PluginProbe
Two Factor Authentication / 1.14.16
Two Factor Authentication v1.14.16
1.12.2 1.13.0 1.14.10 1.14.11 1.14.14 1.14.15 1.14.16 1.14.17 1.14.23 1.14.24 1.14.26 1.14.27 1.14.3 1.14.4 1.14.5 1.14.7 1.14.8 1.15.5 1.16.0 1.2.10 1.2.12 1.2.13 1.2.14 1.2.15 1.2.16 All 98 releases
two-factor-authentication / two-factor-login.php

two-factor-login.php in Two Factor Authentication 1.14.16, at two-factor-login.php

283 lines 11.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /*
3 Plugin Name: Two Factor Authentication
4 Plugin URI: https://www.simbahosting.co.uk/s3/product/two-factor-authentication/
5 Description: Secure your WordPress login forms with two factor authentication - including WooCommerce login forms
6 Author: David Anderson, original plugin by Oskar Hane and enhanced by Dee Nutbourne
7 Author URI: https://www.simbahosting.co.uk
8 Version: 1.14.16
9 Text Domain: two-factor-authentication
10 Domain Path: /languages
11 License: GPLv2 or later
12 */
13
14 register_activation_hook(__FILE__, 'simba_two_factor_authentication_activation');
15
16 if (!function_exists('simba_two_factor_authentication_activation')) {
17 function simba_two_factor_authentication_activation() {
18 if (!empty($GLOBALS['simba_two_factor_authentication'])) {
19 $is_2fa_plugin_active = false;
20 $installed_plugins_slugs = array_keys(get_plugins());
21 foreach ($installed_plugins_slugs as $installed_plugin_slug) {
22 if (is_plugin_active($installed_plugin_slug)) {
23 $temp_split_plugin_slug = explode('/', $installed_plugin_slug);
24 if (isset($temp_split_plugin_slug[1]) && 'two-factor-login.php' == $temp_split_plugin_slug[1]) {
25 $is_2fa_plugin_active = true;
26 break;
27 }
28 }
29 }
30
31 // We should prevent activation if and only if either the 2FA Premium or 2FA Free plugin is active.
32 // We should not prevent activation if either the AIOS plugin is active.
33 if ($is_2fa_plugin_active) {
34 if (file_exists(__DIR__.'/simba-tfa/premium/loader.php')) {
35 wp_die(__('To activate Two Factor Authentication Premium, first de-activate the free version (only one can be active at once).', 'two-factor-authentication'));
36 } else { // If the 2FA Premium plugin is active and tries to activate the 2FA Free Plugin, it throws a fatal error and stops activating the free version.
37 wp_die(__("You can't activate Two Factor Authentication (Free) because Two Factor Authentication Premium is active (only one can be active at once).", 'two-factor-authentication'));
38 }
39 }
40 }
41 }
42 }
43
44 if (!defined('SIMBA_TFA_TEXT_DOMAIN')) define('SIMBA_TFA_TEXT_DOMAIN', 'two-factor-authentication');
45 if (!class_exists('Simba_Two_Factor_Authentication_1')) require dirname(__FILE__).'/simba-tfa/simba-tfa.php';
46
47 if (!class_exists('Simba_Two_Factor_Authentication_Plugin')):
48 /**
49 * This parent-child relationship enables the two to be split without affecting backwards compatibility for developers making direct calls
50 *
51 * This class is for the plugin encapsulation.
52 */
53 class Simba_Two_Factor_Authentication_Plugin extends Simba_Two_Factor_Authentication_1 {
54
55 public $version = '1.14.16';
56
57 const PHP_REQUIRED = '5.6';
58
59 /**
60 * Constructor, run upon plugin initiation
61 *
62 * @uses __FILE__
63 */
64 public function __construct() {
65
66 add_action('plugins_loaded', array($this, 'plugins_loaded_load_textdomain'));
67
68 if (version_compare(PHP_VERSION, self::PHP_REQUIRED, '<' )) {
69 add_action('all_admin_notices', array($this, 'admin_notice_insufficient_php'));
70 $abort = true;
71 }
72
73 if (!function_exists('mcrypt_get_iv_size') && !function_exists('openssl_cipher_iv_length')) {
74 add_action('all_admin_notices', array($this, 'admin_notice_missing_mcrypt_and_openssl'));
75 $abort = true;
76 }
77
78 $encryption_enabled = $this->get_option('tfa_encrypt_secrets');
79 if ($encryption_enabled && (!defined('SIMBA_TFA_DB_ENCRYPTION_KEY') || '' === SIMBA_TFA_DB_ENCRYPTION_KEY)) {
80 add_action('all_admin_notices', array($this, 'admin_notice_missing_db_encryption_key'));
81 }
82
83 if (!empty($abort)) return;
84
85 // Menu entries
86 add_action('admin_menu', array($this, 'menu_entry_for_admin'));
87 add_action('admin_menu', array($this, 'menu_entry_for_user'));
88 add_action('network_admin_menu', array($this, 'menu_entry_for_user'));
89
90 // Add settings link in plugin list
91 $plugin = plugin_basename(__FILE__);
92 add_filter("plugin_action_links_$plugin", array($this, 'add_plugin_settings_link'));
93 add_filter("network_admin_plugin_action_links_$plugin", array($this, 'add_plugin_settings_link'));
94
95 $this->set_user_settings_page_slug('two-factor-auth-user');
96
97 $this->set_plugin_translate_url('https://translate.wordpress.org/projects/wp-plugins/two-factor-authentication/');
98
99 if (is_multisite() && function_exists('switch_to_blog')) {
100 $main_site_id = function_exists('get_main_site_id') ? get_main_site_id() : 1;
101 switch_to_blog($main_site_id);
102 }
103 $this->set_site_wide_administration_url(admin_url('options-general.php?page=two-factor-auth'));
104 if (is_multisite() && function_exists('restore_current_blog')) restore_current_blog();
105
106 $this->set_premium_version_url('https://www.simbahosting.co.uk/s3/product/two-factor-authentication/');
107 $this->set_faq_url('https://wordpress.org/plugins/two-factor-authentication/#faq');
108 parent::__construct();
109
110 }
111
112 /**
113 * Runs upon the WP filters plugin_action_links_(plugin) and network_plugin_action_links_(plugin)
114 *
115 * @param Array $links
116 *
117 * @return Array
118 */
119 public function add_plugin_settings_link($links) {
120 if (is_multisite()) {
121 $main_site_id = function_exists('get_main_site_id') ? get_main_site_id() : 1;
122 switch_to_blog($main_site_id);
123 $link = $this->get_settings_link();
124 restore_current_blog();
125 array_unshift($links, $link);
126 } else {
127 $link = $this->get_settings_link();
128 array_unshift($links, $link);
129 }
130
131 $link2 = '<a href="admin.php?page=two-factor-auth-user">'.__('User settings', 'two-factor-authentication').'</a>';
132 array_unshift($links, $link2);
133
134 return $links;
135 }
136
137 /**
138 * Get 2FA settings anchor tag link.
139 *
140 * @return string 2FA settings anchor tag link.
141 */
142 private function get_settings_link() {
143 return '<a href="'.admin_url('options-general.php').'?page=two-factor-auth">'.__('Plugin settings', 'two-factor-authentication').'</a>';
144 }
145
146 /**
147 * Runs upon the WP actions admin_menu and network_admin_menu
148 */
149 public function menu_entry_for_user() {
150
151 global $current_user;
152 if ($this->is_activated_for_user($current_user->ID)) {
153 add_menu_page(__('Two Factor Authentication', 'two-factor-authentication'), __('Two Factor Auth', 'two-factor-authentication'), 'read', 'two-factor-auth-user', array($this, 'show_dashboard_user_settings_page'), $this->includes_url().'/tfa_admin_icon_16x16.png', 72);
154 }
155 }
156
157 /**
158 * Runs upon the WP action admin_menu
159 */
160 public function menu_entry_for_admin() {
161
162 $skip_adding_options_menu_entry = (is_multisite() && (!is_super_admin() || !is_main_site()));
163
164 $skip_adding_options_menu_entry = apply_filters('simba_tfa_skip_adding_options_menu_entry', $skip_adding_options_menu_entry);
165
166 if ($skip_adding_options_menu_entry) return;
167
168 add_options_page(
169 __('Two Factor Authentication', 'two-factor-authentication'),
170 __('Two Factor Authentication', 'two-factor-authentication'),
171 $this->get_management_capability(),
172 'two-factor-auth',
173 array($this, 'show_admin_settings_page')
174 );
175 }
176
177 /**
178 * Include the admin settings page code
179 */
180 public function show_admin_settings_page() {
181
182 if (!is_admin() || !current_user_can($this->get_management_capability())) return;
183
184 $admin_settings_links = array();
185 if (!class_exists('Simba_Two_Factor_Authentication_Premium')) {
186 $admin_settings_links[] = array(
187 'url' => 'https://www.simbahosting.co.uk/s3/product/two-factor-authentication/',
188 'title' => __('Premium version', 'two-factor-authentication'),
189 );
190 }
191 $simba_tfa_support_url = apply_filters('simba_tfa_support_url', 'https://wordpress.org/support/plugin/two-factor-authentication/');
192
193 $admin_settings_links[] = array(
194 'url' => $simba_tfa_support_url,
195 'title' => __('Support', 'two-factor-authentication'),
196 );
197
198 $admin_settings_links[] = array(
199 'url' => 'https://profiles.wordpress.org/davidanderson#content-plugins',
200 'title' => __('More free plugins', 'two-factor-authentication'),
201 );
202
203 $admin_settings_links[] = array(
204 'url' => 'http://updraftplus.com',
205 'title' => 'UpdraftPlus - '.__('WordPress backups', 'two-factor-authentication'),
206 );
207
208 $admin_settings_links[] = array(
209 'url' => 'https://www.simbahosting.co.uk/s3/shop/',
210 'title' => __('More premium plugins', 'two-factor-authentication'),
211 );
212
213 $admin_settings_links[] = array(
214 'url' => 'https://twitter.com/updraftplus',
215 'title' => __('Twitter', 'two-factor-authentication'),
216 );
217
218 $admin_settings_links[] = array(
219 'url' => 'https://david.dw-perspective.org.uk',
220 'title' => __("Lead developer's homepage", 'two-factor-authentication'),
221 );
222
223 $admin_settings_links = apply_filters('simba_tfa_admin_settings_links', $admin_settings_links);
224
225 $this->include_template('admin-settings.php', array(
226 'settings_page_heading' => $this->get_settings_page_heading(),
227 'admin_settings_links' => $admin_settings_links,
228 ));
229 }
230
231 /**
232 * Runs conditionally on the WP action all_admin_notices
233 */
234 public function admin_notice_insufficient_php() {
235 $this->show_admin_warning('<strong>'.__('Higher PHP version required', 'two-factor-authentication').'</strong><br> '.sprintf(__('The Two Factor Authentication plugin requires PHP version %s or higher - your current version is only %s.', 'two-factor-authentication'), self::PHP_REQUIRED, PHP_VERSION), 'error');
236 }
237
238 /**
239 * Runs conditionally on the WP action all_admin_notices
240 */
241 public function admin_notice_missing_mcrypt_and_openssl() {
242 $this->show_admin_warning('<strong>'.__('PHP OpenSSL or mcrypt module required', 'two-factor-authentication').'</strong><br> '.__('The Two Factor Authentication plugin requires either the PHP openssl (preferred) or mcrypt module to be installed. Please ask your web hosting company to install one of them.', 'two-factor-authentication'), 'error');
243 }
244
245 /**
246 * Runs conditionally on the WP action all_admin_notices
247 */
248 public function admin_notice_missing_db_encryption_key() {
249 $this->show_admin_warning('<strong>'.__('Two Factor Authentication encryption key not found', 'two-factor-authentication').'</strong><br> '.htmlspecialchars(__('The "encrypt secrets" feature is currently enabled, but no encryption key has been found (set via the SIMBA_TFA_DB_ENCRYPTION_KEY constant).', SIMBA_TFA_TEXT_DOMAIN).' '.__('This indicates that either setup failed, or your WordPress installation has been corrupted.', SIMBA_TFA_TEXT_DOMAIN)) . ' <a href="' . esc_url($this->get_faq_url()) . '">'. __('Go here for the FAQs, which explain how a website owner can de-activate the plugin without needing to login.', SIMBA_TFA_TEXT_DOMAIN) .'</a>', 'error');
250 }
251
252 /**
253 * Run upon the WP plugins_loaded action. This method is called even if main loading aborts - so don't put anything else in it (use a separate method).
254 */
255 public function plugins_loaded_load_textdomain() {
256 load_plugin_textdomain(
257 'two-factor-authentication',
258 false,
259 dirname(plugin_basename(__FILE__)).'/languages/'
260 );
261
262 $this->set_settings_page_heading(sprintf(__('Two Factor Authentication (Version: %s) - Admin Settings', 'two-factor-authentication'), $this->version));
263
264 }
265 }
266 endif;
267
268 $GLOBALS['simba_two_factor_authentication'] = new Simba_Two_Factor_Authentication_Plugin();
269
270 if (file_exists(__DIR__.'/simba-tfa/premium/loader.php') && empty($GLOBALS['simba_two_factor_authentication_premium'])) {
271 if (!class_exists('Simba_Two_Factor_Authentication_Premium')) include_once(__DIR__.'/simba-tfa/premium/loader.php');
272
273 $GLOBALS['simba_two_factor_authentication_premium'] = new Simba_Two_Factor_Authentication_Premium($GLOBALS['simba_two_factor_authentication']);
274
275 if (!class_exists('Updraft_Manager_Updater_1_8')) require_once(plugin_dir_path(__FILE__).'vendor/davidanderson684/simba-plugin-manager-updater/class-udm-updater.php');
276
277 try {
278 new Updraft_Manager_Updater_1_8('https://www.simbahosting.co.uk/s3', 1, 'two-factor-authentication-premium/two-factor-login.php', array('require_login' => false));
279 } catch (Exception $e) {
280 error_log($e->getMessage());
281 }
282 }
283