PluginProbe
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! / 2.0.2
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! v2.0.2
3.7.5 3.7.4 3.7.3 3.7.2 1-final 3.7.1 3.7.0 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.0.3 3.0.4 3.0.5 3.0.6 3.0.7 3.0.8 3.0.9 3.1.0 3.1.1 3.1.10 All 111 releases
← All changes | includes/API/Login.php +130 -287 3.7.22.0.2 View file →
@@ -6,333 +6,176 @@
6 6 use Templately\Utils\Helper;
7 7 use Templately\Utils\Options;
8 8
9 9 class Login extends API {
10 - public function permission_check( WP_REST_Request $request ) {
10 + public function permission_check( WP_REST_Request $request ) {
11 11 $this->request = $request;
12 - $_route = $request->get_route();
13 - if ( '/templately/v1/login' === $_route ) {
14 - return true;
15 - }
12 + return true;
13 + }
16 14
17 - if ( '/templately/v1/pricing' === $_route ) {
18 - return true;
19 - }
15 + public function register_routes() {
16 + $this->post( 'login', [ $this, 'login' ] );
17 + $this->post( 'logout', [ $this, 'logout' ] );
18 + $this->get( 'is-signed', [ $this, 'is_signed' ] );
19 + }
20 20
21 - if ( '/templately/v1/google-auth-url' === $_route ) {
22 - return true;
23 - }
21 + public function login(){
22 + $errors = [];
23 + $_ip = Helper::get_ip();
24 + $_site_url = home_url( '/' );
24 25
25 - return parent::permission_check( $request );
26 - }
26 + $global_signin = (bool) $this->get_param( 'global_signin', false );
27 + $viaAPI = (bool) $this->get_param( 'viaAPI', false );
28 + $email = $this->get_param( 'email', '', 'sanitize_email' );
29 + $password = $this->get_param( 'password' );
27 30
28 - public function register_routes() {
29 - $this->post( 'login', [$this, 'login'] );
30 - $this->post( 'logout', [$this, 'logout'] );
31 - $this->get( 'is-signed', [$this, 'is_signed'] );
32 - $this->get( 'pricing', [$this, 'pricing'] );
33 - $this->get( 'google-auth-url', [$this, 'google_auth_url'] );
34 - }
31 + $funcArgs = [
32 + 'ip' => $_ip,
33 + 'site_url' => $_site_url,
34 + ];
35 35
36 - public function google_auth_url() {
37 - // Get redirect_to parameter from request if provided
38 - $redirect_to = $this->get_param( 'redirect-to', '' );
36 + if( $viaAPI ) {
37 + $api_key = $this->get_param( 'api_key' );
38 + $funcArgs['api_key'] = $api_key;
39 39
40 - // Use client-provided current_url instead of HTTP_REFERER for reliability
41 - $current_url = $this->get_param( 'current_url', '' );
40 + if ( empty( $api_key ) ) {
41 + $errors['api_key'] = __( 'API Key field cannot be empty.', 'templately' );
42 + }
43 + } else {
44 + $funcArgs['email'] = $email;
45 + $funcArgs['password'] = $password;
42 46
43 - $url = $this->http()->google_auth_url( $redirect_to, $current_url );
44 - return [
45 - 'status' => 'success',
46 - 'url' => $url
47 - ];
48 - }
47 + if ( ! filter_var( $email, FILTER_VALIDATE_EMAIL ) ) {
48 + $errors['email'] = __( 'Make sure you have given a valid email address.', 'templately' );
49 + }
49 50
50 - public function pricing(){
51 - $data = get_transient( "templately_subscriptions" );
51 + if ( empty( $password ) ) {
52 + $errors['password'] = __( 'Password field cannot be empty.', 'templately' );
53 + }
54 + }
52 55
53 - if( is_array( $data ) && ! empty( $data ) ) {
54 - return $data;
56 + if( ! empty( $errors ) ) {
57 + return $this->error( 'login_error', $errors, 'login', 400 );
55 58 }
56 59
57 - $query = 'id, price, name, discounted_price, type, sites, coupon';
58 - $response = $this->http()->query(
59 - 'subscriptionPlans',
60 - $query
60 + $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type } }';
61 +
62 + $response = $this->http()->mutation(
63 + $viaAPI ? 'connectWithApiKey' : 'connect',
64 + $query,
65 + $funcArgs
61 66 )->post();
62 67
63 - set_transient( "templately_subscriptions", $response, WEEK_IN_SECONDS );
68 + if( is_wp_error( $response ) ) {
69 + return $response;
70 + }
64 71
65 - return $response;
66 - }
72 + if ( $global_signin && ! Login::is_globally_signed() ) {
73 + Options::set_global_login();
74 + }
67 75
68 - public function login() {
69 - $errors = [];
70 - $_ip = Helper::get_ip();
71 - $_site_url = home_url( '/' );
76 + if ( ! empty( $response['user']['api_key'] ) ) {
77 + $this->utils('options')->set( 'api_key', $response['user']['api_key'] );
78 + unset( $response['user']['api_key'] );
79 + }
72 80
73 - $global_signin = (bool) $this->get_param( 'global_signin', false );
74 - $viaAPI = (bool) $this->get_param( 'viaAPI', false );
75 - $email = $this->get_param( 'email', '', 'sanitize_email' );
76 - $password = $this->get_param( 'password' );
81 + $meta = [
82 + 'is_globally_signed' => Login::is_globally_signed(),
83 + 'signed_as_global' => Login::signed_as_global(),
84 + ];
77 85
78 - $funcArgs = [
79 - 'ip' => $_ip,
80 - 'site_url' => $_site_url
81 - ];
86 + if( ! empty( $response['user']['my_cloud']['last_pushed'] ) ) {
87 + $_cloud_activity = unserialize( $response['user']['my_cloud']['last_pushed'] );
88 + $this->utils('options')->set( 'cloud_activity', $_cloud_activity );
89 + $meta['cloud_activity'] = $_cloud_activity;
90 + unset( $response['user']['my_cloud']['last_pushed'] );
91 + }
82 92
83 - $postArgs = [];
93 + if( ! empty( $response['user']['favourites'] ) ) {
94 + $_favourites = $this->utils('helper')->normalizeFavourites( $response['user']['favourites'] );
95 + $this->utils('options')->set('favourites', $_favourites);
84 96
85 - if ( $viaAPI ) {
86 - $api_key = $this->get_param( 'api_key' );
87 - $funcArgs['api_key'] = $api_key;
97 + unset( $response['user']['favourites'] );
98 + $meta['favourites'] = $_favourites;
99 + }
88 100
89 - if ( empty( $api_key ) ) {
90 - $errors['api_key'] = __( 'API Key field cannot be empty.', 'templately' );
91 - }
92 - } else {
93 - $funcArgs['email'] = $email;
94 - $funcArgs['password'] = addcslashes( $password, '"' );
101 + $this->utils('options')->set('user', $response['user']);
102 + $response['user']['meta'] = $this->user_meta( $meta );
95 103
96 - if ( ! filter_var( $email, FILTER_VALIDATE_EMAIL ) ) {
97 - $errors['email'] = __( 'Make sure you have given a valid email address.', 'templately' );
98 - }
104 + return $response;
105 + }
99 106
100 - if ( empty( $password ) ) {
101 - $errors['password'] = __( 'Password field cannot be empty.', 'templately' );
102 - }
103 - }
107 + public function logout(){
108 + // Remove All Metas
109 + $this->utils('options')
110 + ->remove('user')
111 + ->remove('favourites')
112 + ->remove('cloud_activity')
113 + ->remove('api_key')
114 + ->remove('global_login');
104 115
105 - if ( ! empty( $errors ) ) {
106 - return $this->error( 'login_error', $errors, 'login', 400 );
107 - }
108 -
109 - $query = 'status, message, user{ id, name, first_name, last_name, display_name, email, profile_photo, joined, is_verified, is_company_user, api_key, plan, plan_expire_at, my_cloud{ limit, usages, last_pushed }, favourites{ id, type }, show_notice, reviews{ type, type_id, rating }, subscription { id, name, sites } }';
110 -
111 - $response = $this->http()->mutation(
112 - $viaAPI ? 'connectWithApiKey' : 'connect',
113 - $query,
114 - $funcArgs
115 - )->post($postArgs);
116 -
117 - if ( is_wp_error( $response ) ) {
118 - return $response;
119 - }
120 -
121 - if ( empty( $response['user']['api_key'] ) ) {
122 - return $this->error( 'login_error', $response['message'] ?? __('Invalid API key.', 'templately'), 'login', 400 );
123 - }
124 -
125 - $options = $this->utils( 'options' );
126 - $options->use_current_user( true );
127 -
128 - try {
129 - return $this->store_connection( $response, $global_signin, $_ip, $_site_url );
130 - } finally {
131 - $options->use_current_user( false );
132 - }
133 - }
134 -
135 - /**
136 - * Persist an authenticated connection against the acting user.
137 - *
138 - * @param array $response Cloud response, already validated.
139 - * @param bool $global_signin Whether the user asked to sign in globally.
140 - * @param string $_ip Request IP, echoed back into the profile.
141 - * @param string $_site_url Site URL, echoed back into the profile.
142 - *
143 - * @return array
144 - */
145 - private function store_connection( $response, $global_signin, $_ip, $_site_url ) {
146 -
147 - if ( $global_signin && ! Login::is_globally_signed() ) {
148 - Options::set_global_login();
149 - }
150 -
151 - if ( ! empty( $response['user']['api_key'] ) ) {
152 - $this->utils( 'options' )->set( 'api_key', $response['user']['api_key'] );
153 - unset( $response['user']['api_key'] );
154 - }
155 -
156 - $meta = [
157 - 'is_globally_signed' => Login::is_globally_signed(),
158 - 'signed_as_global' => Login::signed_as_global()
159 - ];
160 -
161 - if ( ! empty( $response['user']['my_cloud']['last_pushed'] ) ) {
162 - $_cloud_activity = unserialize( $response['user']['my_cloud']['last_pushed'] );
163 - $this->utils( 'options' )->set( 'cloud_activity', $_cloud_activity );
164 - $meta['cloud_activity'] = $_cloud_activity;
165 - unset( $response['user']['my_cloud']['last_pushed'] );
166 - }
167 -
168 - if ( ! empty( $response['user']['favourites'] ) ) {
169 - $_favourites = $this->utils( 'helper' )->normalizeFavourites( $response['user']['favourites'] );
170 - $this->utils( 'options' )->set( 'favourites', $_favourites );
171 -
172 - unset( $response['user']['favourites'] );
173 - $meta['favourites'] = $_favourites;
174 - }
175 -
176 - if ( ! empty( $response['user']['reviews'] ) ) {
177 - $_reviews = $this->utils( 'helper' )->normalizeReviews( $response['user']['reviews'] );
178 - $this->utils( 'options' )->set( 'reviews', $_reviews );
179 -
180 - unset( $response['user']['reviews'] );
181 - $meta['reviews'] = $_reviews;
116 + if( $this->utils('options')->whoami() === 'global' ) {
117 + $this->utils('options')->remove_global_login();
182 118 }
183 119
184 - if(Helper::is_dev_api()){
185 - $response['user']['is_dev_api'] = true;
186 - }
120 + $global_user_id = $this->utils('options')->is_global();
121 + if( $global_user_id !== $this->utils('options')->current_user_id() ) {
122 + $global_user = $this->utils('options')->get( 'user', false, $global_user_id );
187 123
188 - if(! empty( $response['user'] ) && is_array($response['user'])){
189 - $response['user']['ip'] = $_ip;
190 - $response['user']['site_url'] = base64_encode( $_site_url );
191 - }
192 -
193 - $this->utils( 'options' )->set( 'user', $response['user'] );
194 - $response['user']['meta'] = $this->user_meta( $meta );
195 -
196 - return $response;
197 - }
198 -
199 - public function logout() {
200 - // Read the key off the acting user's own record. Options::get() falls back to
201 - // the global-login administrator when no target is given, so $this->api_key
202 - // resolves to the administrator's key for any linked user — disconnecting the
203 - // administrator's account on the cloud as well as locally.
204 - $api_key = $this->utils( 'options' )->get( 'api_key', '', get_current_user_id() );
205 -
206 - if ( empty( $api_key ) ) {
207 - return $this->error(
208 - 'logout_error',
209 - __( 'You are not connected to Templately.', 'templately' ),
210 - 'logout',
211 - 403
212 - );
213 - }
214 -
215 - $response = $this->http()->mutation(
216 - 'disconnect',
217 - 'status, message, data',
218 - [
219 - 'api_key' => $api_key,
220 - "site_url" => home_url( '/' )
221 - ]
222 - )->post();
223 -
224 - if ( is_wp_error( $response ) ) {
225 - return $response;
226 - }
227 -
228 - if ( ! isset( $response['status'] ) || $response['status'] !== 'success' ) {
229 - return $this->error( 'logout_error', $response['message'], 'logout', 404 );
230 - }
231 -
232 - // Remove All Metas
233 - $global_user = $this->delete();
234 -
235 - $response = [
236 - 'status' => 'success',
237 - 'message' => __( 'Logged out.', 'templately' )
238 - ];
239 -
240 - if ( ! empty( $global_user ) ) {
241 - $response['global_user'] = $global_user;
242 - }
243 -
244 - return $response;
245 - }
246 -
247 - public function delete(){
248 - $options = $this->utils( 'options' );
249 -
250 - // Pin the removals to the acting user. Without the pin, Options::user_id()
251 - // resolves a linked user to the global-login administrator and the delete
252 - // path wipes the administrator's connection instead of the caller's.
253 - $options->use_current_user( true );
254 -
255 - try {
256 - $options
257 - ->remove( 'user' )
258 - ->remove( 'favourites' )
259 - ->remove( 'reviews' )
260 - ->remove( 'cloud_activity' )
261 - ->remove( 'api_key' )
262 - ->remove( 'global_login' )
263 - ->remove( 'total_download_counts' )
264 - ->remove( 'templates_in_clouds' );
265 -
266 - if ( $options->who_am_i() === 'global' ) {
267 - $options->remove_global_login();
124 + if( ! empty( $global_user ) ) {
125 + $global_user['meta'] = $this->user_meta();
268 126 }
269 - } finally {
270 - $options->use_current_user( false );
271 127 }
272 128
273 - $global_user_id = $this->utils( 'options' )->is_global();
274 - $global_user = null;
129 + $response = [
130 + 'status' => 'success',
131 + 'message' => __( 'Logged out.', 'templately' ),
132 + ];
275 133
276 - if ( $global_user_id !== $this->utils( 'options' )->current_user_id() ) {
277 - $global_user = $this->utils( 'options' )->get( 'user', false, $global_user_id );
134 + if( ! empty( $global_user ) ) {
135 + $response['global_user'] = $global_user;
136 + }
278 137
279 - if ( ! empty( $global_user ) ) {
280 - if ( is_array( $global_user ) ) {
281 - unset( $global_user['api_key'] );
282 - }
283 -
284 - $global_user['meta'] = $this->user_meta();
285 - }
286 - }
287 -
288 - return $global_user;
138 + return $response;
289 139 }
290 140
291 - public static function is_signed(): array {
292 - $_response = [
293 - 'status' => 'success'
294 - ];
141 + public static function is_signed(){
142 + $_response = [
143 + 'status' => 'success'
144 + ];
295 145
296 - $_user = ( new static )->utils( 'options' )->get( 'user', null );
146 + $_user = (new static)->utils( 'options' )->get('user', null);
297 147
298 - if ( ! is_null( $_user ) ) {
299 - // Profiles stored before 3.7.1 may still carry the cloud API key.
300 - if ( is_array( $_user ) ) {
301 - unset( $_user['api_key'] );
302 - }
148 + if( ! is_null( $_user ) ) {
149 + $_user['meta'] = self::get_instance()->user_meta();
150 + }
303 151
304 - $_user['meta'] = self::get_instance()->user_meta();
305 - }
152 + if( empty( $_user ) ) {
153 + $_response['status'] = 'error';
154 + }
306 155
307 - if ( empty( $_user ) ) {
308 - $_response['status'] = 'error';
309 - }
156 + $_response['user'] = $_user;
310 157
311 - $_response['user'] = $_user;
158 + return $_response;
159 + }
312 160
313 - return $_response;
314 - }
161 + public function user_meta( $meta = [] ){
162 + $_meta = [
163 + 'link_account' => self::utils( 'options' )->link_account(),
164 + 'unlink_account' => self::utils( 'options' )->unlink_account(),
165 + 'is_globally_signed' => Login::is_globally_signed(),
166 + 'signed_as_global' => Login::signed_as_global(),
167 + 'starred' => self::utils('options')->get('favourites'),
168 + 'cloud_activity' => self::utils( 'options' )->get('cloud_activity'),
169 + 'has_api' => rest_sanitize_boolean( self::utils( 'options' )->get('api_key' ) ),
170 + ];
315 171
316 - public function user_meta( $meta = [] ): array {
317 - $_meta = [
318 - 'link_account' => self::utils( 'options' )->link_account(),
319 - 'unlink_account' => self::utils( 'options' )->unlink_account(),
320 - 'is_globally_signed' => Login::is_globally_signed(),
321 - 'signed_as_global' => Login::signed_as_global(),
322 - 'starred' => self::utils( 'options' )->get( 'favourites' ),
323 - 'reviews' => self::utils( 'options' )->get( 'reviews' ),
324 - 'cloud_activity' => self::utils( 'options' )->get( 'cloud_activity' ),
325 - 'has_api' => rest_sanitize_boolean( self::utils( 'options' )->get( 'api_key' ) )
326 - ];
172 + return array_merge( $_meta, $meta );
173 + }
327 174
328 - return array_merge( $_meta, $meta );
329 - }
330 -
331 - public static function is_globally_signed(): bool {
332 - return rest_sanitize_boolean( ( new static )->utils( 'options' )->is_globally_signed() );
333 - }
334 -
335 - public static function signed_as_global(): bool {
336 - return rest_sanitize_boolean( ( new static )->utils( 'options' )->signed_as_global() );
337 - }
338 -}
175 + public static function is_globally_signed(){
176 + return rest_sanitize_boolean( ( new static )->utils('options')->is_globally_signed() );
177 + }
178 + public static function signed_as_global(){
179 + return rest_sanitize_boolean( ( new static )->utils('options')->signed_as_global() );
180 + }
181 +}