PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php +24 -2 1.0.61 → 1.0.64 View file →
@@ -12,16 +12,38 @@
12 12 return $string;
13 13 }
14 14
15 15 /**
16 + * Build the private nonce action for a plugin using this SDK.
17 + *
18 + * The public 'wp_rest' action must not be used on its own: WordPress hands
19 + * the same 'wp_rest' nonce to every logged out visitor, and plugins print
20 + * it on public pages, so it proves nothing about who is calling.
21 + *
22 + * @since 1.0.0
23 + *
24 + * @param string $identifier
25 + *
26 + * @return string
27 + */
28 + public static function get_nonce_action( $identifier ) {
29 + return 'ens_' . $identifier . '_flow';
30 + }
31 +
32 + /**
16 33 * will verify nonce
17 34 *
18 35 * @return array
19 36 */
20 37 public static function ens_verify_nonce( $nonce, $identifier ) {
21 - $is_local = isset( $_SERVER['REMOTE_ADDR'] ) && in_array( $_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1'] );
38 + if ( ! empty( $nonce ) && wp_verify_nonce( $nonce, self::get_nonce_action( $identifier ) ) ) {
39 + return true;
40 + }
22 41
23 - if ( ( isset( $nonce ) && wp_verify_nonce( $nonce, 'wp_rest' ) ) || $is_local ) {
42 + // Backward compatibility: plugins bundling an older SDK still send a
43 + // 'wp_rest' nonce. This is only a CSRF check; authorization is enforced
44 + // by the capability check in each route's permission_callback.
45 + if ( ! empty( $nonce ) && wp_verify_nonce( $nonce, 'wp_rest' ) ) {
24 46 return true;
25 47 }
26 48
27 49 $response = [