← All changes
|
vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php
+24
-2
1.0.61
→
1.0.64
View file →
| @@ -12,16 +12,38 @@ | ||
| 12 | 12 | return $string; |
| 13 | 13 | } |
| 14 | 14 | |
| 15 | 15 | /** |
| 16 | + * Build the private nonce action for a plugin using this SDK. | |
| 17 | + * | |
| 18 | + * The public 'wp_rest' action must not be used on its own: WordPress hands | |
| 19 | + * the same 'wp_rest' nonce to every logged out visitor, and plugins print | |
| 20 | + * it on public pages, so it proves nothing about who is calling. | |
| 21 | + * | |
| 22 | + * @since 1.0.0 | |
| 23 | + * | |
| 24 | + * @param string $identifier | |
| 25 | + * | |
| 26 | + * @return string | |
| 27 | + */ | |
| 28 | + public static function get_nonce_action( $identifier ) { | |
| 29 | + return 'ens_' . $identifier . '_flow'; | |
| 30 | + } | |
| 31 | + | |
| 32 | + /** | |
| 16 | 33 | * will verify nonce |
| 17 | 34 | * |
| 18 | 35 | * @return array |
| 19 | 36 | */ |
| 20 | 37 | public static function ens_verify_nonce( $nonce, $identifier ) { |
| 21 | - $is_local = isset( $_SERVER['REMOTE_ADDR'] ) && in_array( $_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1'] ); | |
| 38 | + if ( ! empty( $nonce ) && wp_verify_nonce( $nonce, self::get_nonce_action( $identifier ) ) ) { | |
| 39 | + return true; | |
| 40 | + } | |
| 22 | 41 | |
| 23 | - if ( ( isset( $nonce ) && wp_verify_nonce( $nonce, 'wp_rest' ) ) || $is_local ) { | |
| 42 | + // Backward compatibility: plugins bundling an older SDK still send a | |
| 43 | + // 'wp_rest' nonce. This is only a CSRF check; authorization is enforced | |
| 44 | + // by the capability check in each route's permission_callback. | |
| 45 | + if ( ! empty( $nonce ) && wp_verify_nonce( $nonce, 'wp_rest' ) ) { | |
| 24 | 46 | return true; |
| 25 | 47 | } |
| 26 | 48 | |
| 27 | 49 | $response = [ |