| 1 |
<?php |
| 2 |
|
| 3 |
if (!defined('ABSPATH')) die('Access denied.'); |
| 4 |
|
| 5 |
if (!is_admin() || !current_user_can('manage_options')) exit; |
| 6 |
|
| 7 |
global $wp_roles; |
| 8 |
global $simba_two_factor_authentication; |
| 9 |
|
| 10 |
$tfa->setUserHMACTypes(); |
| 11 |
|
| 12 |
?><div class="wrap"> |
| 13 |
|
| 14 |
<div> |
| 15 |
|
| 16 |
<?php screen_icon(); ?> |
| 17 |
<h1><?php echo sprintf(__('Two Factor Authentication (Version: %s) - Admin Settings', SIMBA_TFA_TEXT_DOMAIN), $simba_two_factor_authentication->version); ?> </h1> |
| 18 |
|
| 19 |
<?php |
| 20 |
if (!class_exists('Simba_Two_Factor_Authentication_Premium')) { |
| 21 |
?> |
| 22 |
<a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("Premium version", SIMBA_TFA_TEXT_DOMAIN);?></a> | |
| 23 |
<?php |
| 24 |
} |
| 25 |
?> |
| 26 |
<a href="<?php echo apply_filters('simba_tfa_support_url', 'https://wordpress.org/support/plugin/two-factor-authentication/');?>"><?php _e("Support", SIMBA_TFA_TEXT_DOMAIN);?></a> | |
| 27 |
<a href="https://profiles.wordpress.org/davidanderson#content-plugins"><?php _e('More free plugins', SIMBA_TFA_TEXT_DOMAIN);?></a> | |
| 28 |
<a href="http://updraftplus.com">UpdraftPlus - <?php _e('WordPress backups', SIMBA_TFA_TEXT_DOMAIN); ?></a> | |
| 29 |
<a href="https://www.simbahosting.co.uk/s3/shop/"><?php _e('More premium plugins', SIMBA_TFA_TEXT_DOMAIN);?></a> | |
| 30 |
<a href="https://twitter.com/updraftplus"><?php _e('Twitter', SIMBA_TFA_TEXT_DOMAIN);?></a> | |
| 31 |
|
| 32 |
<a href="http://david.dw-perspective.org.uk"><?php _e("Lead developer's homepage", SIMBA_TFA_TEXT_DOMAIN);?></a> |
| 33 |
<br> |
| 34 |
|
| 35 |
</div> |
| 36 |
|
| 37 |
<?php if (defined('TWO_FACTOR_DISABLE') && TWO_FACTOR_DISABLE) { ?> |
| 38 |
<div class="error"> |
| 39 |
<h3><?php _e('Two Factor Authentication currently disabled', SIMBA_TFA_TEXT_DOMAIN);?></h3> |
| 40 |
<p> |
| 41 |
<?php _e('Two factor authentication is currently disabled via the TWO_FACTOR_DISABLE constant (which is mostly likely to be defined in your wp-config.php)', SIMBA_TFA_TEXT_DOMAIN); ?> |
| 42 |
</p> |
| 43 |
</div> |
| 44 |
<?php } ?> |
| 45 |
|
| 46 |
<div style="max-width:800px;"> |
| 47 |
|
| 48 |
<?php |
| 49 |
if (is_multisite()) { |
| 50 |
global $wpdb; |
| 51 |
if (is_super_admin() && is_object($wpdb) && isset($wpdb->blogid) && 1 == $wpdb->blogid) { |
| 52 |
?> |
| 53 |
<p style="font-size: 120%; font-weight: bold;"> |
| 54 |
<?php _e('N.B. These two-factor settings apply to your entire WordPress network. (i.e. They are not localised to one particular site).', SIMBA_TFA_TEXT_DOMAIN);?> |
| 55 |
</p> |
| 56 |
<?php |
| 57 |
} else { |
| 58 |
// Should not be possible to reach this; but an extra check does not hurt. |
| 59 |
die('Security check'); |
| 60 |
} |
| 61 |
} |
| 62 |
?> |
| 63 |
|
| 64 |
<form method="post" action="options.php" style="margin-top: 12px"> |
| 65 |
<?php |
| 66 |
settings_fields('tfa_user_roles_group'); |
| 67 |
?> |
| 68 |
<h2><?php _e('User roles', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 69 |
<?php _e('Choose which user roles will have two factor authentication available.', SIMBA_TFA_TEXT_DOMAIN); ?> |
| 70 |
<p> |
| 71 |
<?php |
| 72 |
$simba_two_factor_authentication->tfaListUserRolesCheckboxes(); |
| 73 |
?></p> |
| 74 |
<?php submit_button(); ?> |
| 75 |
</form> |
| 76 |
|
| 77 |
<hr> |
| 78 |
|
| 79 |
<h2><?php _e('Make two factor authentication compulsory', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 80 |
|
| 81 |
<?php |
| 82 |
|
| 83 |
$output = '<p><a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/">'.__('Requiring users to use two-factor authentication is a feature of the Premium version of this plugin.', SIMBA_TFA_TEXT_DOMAIN).'</a><p>'; |
| 84 |
echo apply_filters('simba_tfa_after_user_roles', $output); |
| 85 |
|
| 86 |
?> |
| 87 |
|
| 88 |
<div> |
| 89 |
<hr> |
| 90 |
<form method="post" action="options.php" style="margin-top: 40px"> |
| 91 |
<?php |
| 92 |
settings_fields('tfa_xmlrpc_status_group'); |
| 93 |
?> |
| 94 |
<h2><?php _e('XMLRPC requests', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 95 |
<?php |
| 96 |
|
| 97 |
echo '<p>'; |
| 98 |
echo __("XMLRPC is a feature within WordPress allowing other computers to talk to your WordPress install. For example, it could be used by an app on your tablet that allows you to blog directly from the app (instead of needing the WordPress dashboard)."); |
| 99 |
|
| 100 |
echo '<p></p>'; |
| 101 |
|
| 102 |
echo __("Unfortunately, XMLRPC also provides a way for attackers to perform actions on your WordPress site, using only a password (i.e. without a two-factor password). More unfortunately, authors of legitimate programmes using XMLRPC have not yet added two-factor support to their code.", SIMBA_TFA_TEXT_DOMAIN); |
| 103 |
|
| 104 |
echo '<p></p>'; |
| 105 |
|
| 106 |
echo __(" i.e. XMLRPC requests coming in to WordPress (whether from a legitimate app, or from an attacker) can only be verified using the password - not with a two-factor code. As a result, there not be an ideal option to pick below. You may have to choose between the convenience of using your apps, or the security of two factor authentication.", SIMBA_TFA_TEXT_DOMAIN); |
| 107 |
|
| 108 |
echo '</p>'; |
| 109 |
?> |
| 110 |
<p> |
| 111 |
<?php |
| 112 |
$simba_two_factor_authentication->tfaListXMLRPCStatusRadios(); |
| 113 |
?></p> |
| 114 |
<?php submit_button(); ?> |
| 115 |
</form> |
| 116 |
</div> |
| 117 |
|
| 118 |
<hr> |
| 119 |
<form method="post" action="options.php" style="margin-top: 40px"> |
| 120 |
<?php |
| 121 |
settings_fields('simba_tfa_default_hmac_group'); |
| 122 |
?> |
| 123 |
<h2><?php _e('Default algorithm', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 124 |
<?php _e('Your users can change this in their own settings if they want.', SIMBA_TFA_TEXT_DOMAIN); ?> |
| 125 |
<p> |
| 126 |
<?php |
| 127 |
$simba_two_factor_authentication->tfaListDefaultHMACRadios(); |
| 128 |
?></p> |
| 129 |
<?php submit_button(); ?> |
| 130 |
</form> |
| 131 |
<hr> |
| 132 |
<br><br> |
| 133 |
<h2><?php _e("Users' settings", SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 134 |
<p> |
| 135 |
|
| 136 |
<?php |
| 137 |
if (!class_exists('Simba_Two_Factor_Authentication_Premium')) { ?> |
| 138 |
|
| 139 |
<a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("The Premium version of this plugin allows you to see and reset the TFA settings of other users.", SIMBA_TFA_TEXT_DOMAIN); ?></a> |
| 140 |
|
| 141 |
<a href="https://wordpress.org/plugins/user-switching/"><?php _e('Another way to do that is by using a user-switching plugin like this one.', SIMBA_TFA_TEXT_DOMAIN); ?></a> |
| 142 |
|
| 143 |
<?php } ?> |
| 144 |
|
| 145 |
<?php do_action('simba_tfa_users_settings'); ?> |
| 146 |
|
| 147 |
<?php |
| 148 |
|
| 149 |
// Disabled |
| 150 |
if (1==0) { |
| 151 |
//List users and type of tfa |
| 152 |
foreach($wp_roles->role_names as $id => $name) |
| 153 |
{ |
| 154 |
$setting = $simba_two_factor_authentication->get_option('tfa_'.$id); |
| 155 |
$setting = $setting === false || $setting ? 1 : 0; |
| 156 |
if(!$setting) |
| 157 |
continue; |
| 158 |
|
| 159 |
$users_q = new WP_User_Query( array( |
| 160 |
'role' => $name |
| 161 |
)); |
| 162 |
$users = $users_q->get_results(); |
| 163 |
|
| 164 |
if(!$users) |
| 165 |
continue; |
| 166 |
|
| 167 |
print '<h3>'.$name.'s</h3>'; |
| 168 |
|
| 169 |
foreach( $users as $user ) |
| 170 |
{ |
| 171 |
$userdata = get_userdata( $user->ID ); |
| 172 |
$tfa_type = get_user_meta($user->ID, 'simbatfa_delivery_type', true); |
| 173 |
print '<span style="font-size: 1.2em">'.esc_attr( $userdata->user_nicename ).'</span>'; |
| 174 |
if(!$tfa_type) |
| 175 |
print ' - '.__('Default', SIMBA_TFA_TEXT_DOMAIN); |
| 176 |
else |
| 177 |
print ' - <a class="button" href="'.esc_url(add_query_arg(array('tfa_change_to_email' => 1, 'tfa_user_id' => $user->ID))).'">'.__('Change to email', SIMBA_TFA_TEXT_DOMAIN).'</a>'; |
| 178 |
print '<br>'; |
| 179 |
} |
| 180 |
} |
| 181 |
} |
| 182 |
|
| 183 |
?> |
| 184 |
<hr> |
| 185 |
<?php if (!class_exists('Simba_Two_Factor_Authentication_Premium')) { ?> |
| 186 |
<h2><?php _e('Premium version', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 187 |
<p> |
| 188 |
<a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("If you want to say 'thank you' or help this plugin's development, or get extra features, then please take a look at the premium version of this plugin.", SIMBA_TFA_TEXT_DOMAIN); ?></a> <?php _e('It comes with these extra features:', SIMBA_TFA_TEXT_DOMAIN);?><br> |
| 189 |
</p> |
| 190 |
<p> |
| 191 |
<ul style="list-style: disc inside;"> |
| 192 |
<li><strong><?php _e('Emergency codes', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('provide your users with one-time codes to use in case they lose their device.', SIMBA_TFA_TEXT_DOMAIN);?></li> |
| 193 |
<li><strong><?php _e('Manage all users centrally', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('enable, disable or see TFA codes for all your users from one central location.', SIMBA_TFA_TEXT_DOMAIN);?></li> |
| 194 |
<li><strong><?php _e('More shortcodes', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('flexible shortcodes allowing you to design your front-end settings page for your users exactly as you wish.', SIMBA_TFA_TEXT_DOMAIN);?></li> |
| 195 |
<li><strong><?php _e('Personal support', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('access to our personal support desk for 12 months.', SIMBA_TFA_TEXT_DOMAIN);?></li> |
| 196 |
</ul> |
| 197 |
</p> |
| 198 |
<hr> |
| 199 |
<?php } ?> |
| 200 |
|
| 201 |
<h2><?php _e('Translations', SIMBA_TFA_TEXT_DOMAIN); ?></h2> |
| 202 |
<p> |
| 203 |
<?php _e("If you translate this plugin, please send the translations .po-file to us so we can include it in future releases - paste a link in the plugin's support forum.", SIMBA_TFA_TEXT_DOMAIN); ?> |
| 204 |
<br> |
| 205 |
</p> |
| 206 |
|
| 207 |
</div> |
| 208 |
</div> |