PluginProbe
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz / 0.0.10
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz v0.0.10
2.12.8 2.12.7 2.12.6 2.12.5 2.12.4 2.12.3 2.12.2 2.12.1 2.12.0 2.11.1 2.11.0 2.10.1 2.10.0 2.9.1 2.9.0 2.8.2 2.8.1 2.7.0 2.7.1 2.8.0 trunk 0.0.10 0.0.11 0.0.12 0.0.13 All 98 releases
sureforms / inc / ai-form-builder / ai-auth.php

ai-auth.php in SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 0.0.10, at inc/ai-form-builder/ai-auth.php

164 lines 4.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * SureForms - AI Auth.
4 *
5 * @package sureforms
6 * @since 0.0.8
7 */
8
9 namespace SRFM\Inc\AI_Form_Builder;
10
11 use SRFM\Inc\Traits\Get_Instance;
12 use SRFM\Inc\Helper;
13
14 // Exit if accessed directly.
15 if ( ! defined( 'ABSPATH' ) ) {
16 exit;
17 }
18
19 /**
20 * SureForms AI Form Builder Class.
21 */
22 class AI_Auth {
23 use Get_Instance;
24
25 /**
26 * The key for encryption and decryption.
27 *
28 * @since 0.0.8
29 * @var string
30 */
31 private $key = '';
32
33 /**
34 * Initiates the auth process.
35 *
36 * @param \WP_REST_Request $request The request object.
37 * @since 0.0.8
38 * @return void
39 */
40 public function get_auth_url( $request ) {
41
42 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
43
44 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
45 wp_send_json_error( 'Nonce verification failed.' );
46 }
47
48 // Generate a random key of 16 characters.
49 $this->key = wp_generate_password( 16, false );
50
51 // Prepare the token data.
52 $token_data = [
53 'redirect-back' => site_url() . '/wp-admin/admin.php?page=add-new-form&method=ai',
54 'key' => $this->key,
55 'site-url' => site_url(),
56 'nonce' => wp_create_nonce( 'ai_auth_nonce' ),
57 ];
58
59 $encoded_token_data = wp_json_encode( $token_data );
60
61 if ( empty( $encoded_token_data ) ) {
62 wp_send_json_error( [ 'message' => 'Failed to encode the token data.' ] );
63 }
64
65 // Send the token data to the frontend for redirection.
66 wp_send_json_success( SRFM_BILLING_PORTAL . 'auth/?token=' . base64_encode( $encoded_token_data ) ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode
67
68 }
69
70 /**
71 * Handles the access key.
72 *
73 * @param \WP_REST_Request $request The request object.
74 * @since 0.0.8
75 * @return void
76 */
77 public function handle_access_key( $request ) {
78
79 $nonce = Helper::get_string_value( $request->get_header( 'X-WP-Nonce' ) );
80
81 if ( ! wp_verify_nonce( sanitize_text_field( $nonce ), 'wp_rest' ) ) {
82 wp_send_json_error( 'Nonce verification failed.' );
83 }
84
85 // get body data.
86 $body = json_decode( $request->get_body(), true );
87
88 if ( empty( $body ) ) {
89 wp_send_json_error( [ 'message' => 'Error processing Access Key.' ] );
90 }
91
92 // get access key.
93 $access_key = is_array( $body ) && ! empty(
94 $body['accessKey']
95 ) ? Helper::get_string_value( $body['accessKey'] ) : '';
96
97 // decrypt the access key.
98 if ( ! empty( $access_key ) ) {
99 $this->decrypt_access_key(
100 $access_key,
101 $this->key
102 );
103 } else {
104 wp_send_json_error( [ 'message' => 'No access key provided.' ] );
105 }
106 }
107
108 /**
109 * Decrypts a string using OpenSSL decryption.
110 *
111 * @param string $data The data to decrypt.
112 * @param string $key The encryption key.
113 * @param string $method The encryption method (e.g., AES-256-CBC).
114 * @since 0.0.8
115 * @return string|false The decrypted string or false on failure.
116 */
117 public function decrypt_access_key( $data, $key, $method = 'AES-256-CBC' ) {
118 // Decode the data and split IV and encrypted data.
119 $decoded_data = base64_decode( $data ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode
120
121 // if the data is not base64 encoded then return false.
122 if ( empty( $decoded_data ) ) {
123 return false;
124 }
125
126 // split the key and encrypted data.
127 list($key, $encrypted) = explode( '::', $decoded_data, 2 );
128
129 // Decrypt the data using the key.
130 $decrypted = openssl_decrypt( $encrypted, $method, $key, 0, $key );
131
132 // if the decryption returns false then send error.
133 if ( empty( $decrypted ) ) {
134 wp_send_json_error( [ 'message' => 'Failed to decrypt the access key.' ] );
135 }
136
137 // json decode the decrypted data.
138 $decrypted_data_array = json_decode( $decrypted, true );
139
140 if ( ! is_array( $decrypted_data_array ) || empty( $decrypted_data_array ) ) {
141 wp_send_json_error( [ 'message' => 'Failed to json decode the decrypted data.' ] );
142 }
143
144 // verify the nonce that comes in $encrypted_email_array.
145 if ( ! empty( $decrypted_data_array['nonce'] ) && ! wp_verify_nonce( $decrypted_data_array['nonce'], 'ai_auth_nonce' ) ) {
146 wp_send_json_error( [ 'message' => 'Nonce verification failed.' ] );
147 }
148
149 // check if the user email is present in the decrypted data.
150 if ( empty( $decrypted_data_array['user_email'] ) ) {
151 wp_send_json_error( [ 'message' => 'No user email found in the decrypted data.' ] );
152 }
153
154 // remove the nonce from the decrypted data before saving it to the options.
155 unset( $decrypted_data_array['nonce'] );
156
157 // save the user email to the options.
158 update_option( 'srfm_ai_auth_user_email', $decrypted_data_array );
159
160 wp_send_json_success();
161 }
162
163 }
164