PluginProbe
Two Factor Authentication / 1.2.6
Two Factor Authentication v1.2.6
1.12.2 1.13.0 1.14.10 1.14.11 1.14.14 1.14.15 1.14.16 1.14.17 1.14.23 1.14.24 1.14.26 1.14.27 1.14.3 1.14.4 1.14.5 1.14.7 1.14.8 1.15.5 1.16.0 1.2.10 1.2.12 1.2.13 1.2.14 1.2.15 1.2.16 All 98 releases
← All changes | includes/admin_settings.php +102 -82 1.12.21.2.6 View file →
@@ -1,28 +1,36 @@
1 1 <?php
2 2
3 3 if (!defined('ABSPATH')) die('Access denied.');
4 4
5 +if (!is_admin() || !current_user_can('manage_options')) exit;
6 +
7 +global $wp_roles;
8 +global $simba_two_factor_authentication;
9 +
10 +$tfa->setUserHMACTypes();
11 +
5 12 ?><div class="wrap">
6 13
7 14 <div>
8 15
9 - <h1><?php echo sprintf(__('Two Factor Authentication (Version: %s) - Admin Settings', 'two-factor-authentication'), $simba_two_factor_authentication->version); ?> </h1>
16 + <?php screen_icon(); ?>
17 + <h1><?php echo sprintf(__('Two Factor Authentication (Version: %s) - Admin Settings', SIMBA_TFA_TEXT_DOMAIN), $simba_two_factor_authentication->version); ?> </h1>
10 18
11 19 <?php
12 20 if (!class_exists('Simba_Two_Factor_Authentication_Premium')) {
13 21 ?>
14 - <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("Premium version", 'two-factor-authentication');?></a> |
22 + <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("Premium version", SIMBA_TFA_TEXT_DOMAIN);?></a> |
15 23 <?php
16 24 }
17 25 ?>
18 - <a href="<?php echo apply_filters('simba_tfa_support_url', 'https://wordpress.org/support/plugin/two-factor-authentication/');?>"><?php _e("Support", 'two-factor-authentication');?></a> |
19 - <a href="https://profiles.wordpress.org/davidanderson#content-plugins"><?php _e('More free plugins', 'two-factor-authentication');?></a> |
20 - <a href="http://updraftplus.com">UpdraftPlus - <?php _e('WordPress backups', 'two-factor-authentication'); ?></a> |
21 - <a href="https://www.simbahosting.co.uk/s3/shop/"><?php _e('More premium plugins', 'two-factor-authentication');?></a> |
22 - <a href="https://twitter.com/updraftplus"><?php _e('Twitter', 'two-factor-authentication');?></a> |
26 + <a href="<?php echo apply_filters('simba_tfa_support_url', 'https://wordpress.org/support/plugin/two-factor-authentication/');?>"><?php _e("Support", SIMBA_TFA_TEXT_DOMAIN);?></a> |
27 + <a href="https://profiles.wordpress.org/davidanderson#content-plugins"><?php _e('More free plugins', SIMBA_TFA_TEXT_DOMAIN);?></a> |
28 + <a href="http://updraftplus.com">UpdraftPlus - <?php _e('WordPress backups', SIMBA_TFA_TEXT_DOMAIN); ?></a> |
29 + <a href="https://www.simbahosting.co.uk/s3/shop/"><?php _e('More premium plugins', SIMBA_TFA_TEXT_DOMAIN);?></a> |
30 + <a href="https://twitter.com/updraftplus"><?php _e('Twitter', SIMBA_TFA_TEXT_DOMAIN);?></a> |
23 31
24 - <a href="http://david.dw-perspective.org.uk"><?php _e("Lead developer's homepage", 'two-factor-authentication');?></a>
32 + <a href="http://david.dw-perspective.org.uk"><?php _e("Lead developer's homepage", SIMBA_TFA_TEXT_DOMAIN);?></a>
25 33 <br>
26 34
27 35 </div>
28 36
@@ -27,11 +35,11 @@
27 35 </div>
28 36
29 37 <?php if (defined('TWO_FACTOR_DISABLE') && TWO_FACTOR_DISABLE) { ?>
30 38 <div class="error">
31 - <h3><?php _e('Two Factor Authentication currently disabled', 'two-factor-authentication');?></h3>
39 + <h3><?php _e('Two Factor Authentication currently disabled', SIMBA_TFA_TEXT_DOMAIN);?></h3>
32 40 <p>
33 - <?php _e('Two factor authentication is currently disabled via the TWO_FACTOR_DISABLE constant (which is mostly likely to be defined in your wp-config.php)', 'two-factor-authentication'); ?>
41 + <?php _e('Two factor authentication is currently disabled via the TWO_FACTOR_DISABLE constant (which is mostly likely to be defined in your wp-config.php)', SIMBA_TFA_TEXT_DOMAIN); ?>
34 42 </p>
35 43 </div>
36 44 <?php } ?>
37 45
@@ -38,12 +46,13 @@
38 46 <div style="max-width:800px;">
39 47
40 48 <?php
41 49 if (is_multisite()) {
42 - if (is_super_admin()) {
50 + global $wpdb;
51 + if (is_super_admin() && is_object($wpdb) && isset($wpdb->blogid) && 1 == $wpdb->blogid) {
43 52 ?>
44 53 <p style="font-size: 120%; font-weight: bold;">
45 - <?php _e('N.B. These two-factor settings apply to your entire WordPress network. (i.e. They are not localised to one particular site).', 'two-factor-authentication');?>
54 + <?php _e('N.B. These two-factor settings apply to your entire WordPress network. (i.e. They are not localised to one particular site).', SIMBA_TFA_TEXT_DOMAIN);?>
46 55 </p>
47 56 <?php
48 57 } else {
49 58 // Should not be possible to reach this; but an extra check does not hurt.
@@ -52,42 +61,31 @@
52 61 }
53 62 ?>
54 63
55 64 <form method="post" action="options.php" style="margin-top: 12px">
56 - <?php settings_fields('tfa_user_roles_group'); ?>
57 - <h2><?php _e('User roles', 'two-factor-authentication'); ?></h2>
58 - <?php _e('Choose which user roles will have two factor authentication available.', 'two-factor-authentication'); ?>
65 + <?php
66 + settings_fields('tfa_user_roles_group');
67 + ?>
68 + <h2><?php _e('User roles', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
69 + <?php _e('Choose which user roles will have two factor authentication available.', SIMBA_TFA_TEXT_DOMAIN); ?>
59 70 <p>
60 - <?php $simba_two_factor_authentication->list_user_roles_checkboxes(); ?>
61 - </p>
62 - <?php submit_button(); ?>
71 + <?php
72 + $simba_two_factor_authentication->tfaListUserRolesCheckboxes();
73 + ?></p>
74 + <?php submit_button(); ?>
63 75 </form>
64 76
65 77 <hr>
66 78
67 - <h2><?php _e('Make two factor authentication compulsory', 'two-factor-authentication'); ?></h2>
79 + <h2><?php _e('Make two factor authentication compulsory', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
68 80
69 81 <?php
70 82
71 - $output = '<p><a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/">'.__('Requiring users to use two-factor authentication is a feature of the Premium version of this plugin.', 'two-factor-authentication').'</a><p>';
83 + $output = '<p><a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/">'.__('Requiring users to use two-factor authentication is a feature of the Premium version of this plugin.', SIMBA_TFA_TEXT_DOMAIN).'</a><p>';
72 84 echo apply_filters('simba_tfa_after_user_roles', $output);
73 85
74 86 ?>
75 87
76 - <hr>
77 - <h2><?php _e('Trusted devices', 'two-factor-authentication'); ?></h2>
78 -
79 - <form method="post" action="options.php" style="margin-top: 12px">
80 - <?php settings_fields('tfa_user_roles_trusted_group'); ?>
81 - <?php _e('Choose which user roles are permitted to mark devices they login on as trusted. This feature requires browser cookies and an https (i.e. SSL) connection to the website to work.', 'two-factor-authentication'); ?>
82 -
83 - <?php
84 - $output = '<p><a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/">'.__('Allowing users to mark a device as trusted so that a two-factor code is only needed once in a specified number of days (instead of every login) is a feature of the Premium version of this plugin.', 'two-factor-authentication').'</a><p>';
85 - echo apply_filters('simba_tfa_trusted_devices_config', $output);
86 - ?>
87 -
88 - </form>
89 -
90 88 <div>
91 89 <hr>
92 90 <form method="post" action="options.php" style="margin-top: 40px">
93 91 <?php
@@ -92,40 +90,27 @@
92 90 <form method="post" action="options.php" style="margin-top: 40px">
93 91 <?php
94 92 settings_fields('tfa_xmlrpc_status_group');
95 93 ?>
96 - <h2><?php _e('XMLRPC requests', 'two-factor-authentication'); ?></h2>
94 + <h2><?php _e('XMLRPC requests', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
97 95 <?php
98 96
99 97 echo '<p>';
100 - echo __("XMLRPC is a feature within WordPress allowing other computers to talk to your WordPress install. For example, it could be used by an app on your tablet that allows you to blog directly from the app (instead of needing the WordPress dashboard).", 'two-factor-authentication');
101 - echo '</p><p>';
98 + echo __("XMLRPC is a feature within WordPress allowing other computers to talk to your WordPress install. For example, it could be used by an app on your tablet that allows you to blog directly from the app (instead of needing the WordPress dashboard).");
102 99
103 - echo __("Unfortunately, XMLRPC also provides a way for attackers to perform actions on your WordPress site, using only a password (i.e. without a two-factor password). More unfortunately, authors of legitimate programmes using XMLRPC have not yet added two-factor support to their code.", 'two-factor-authentication');
104 - echo '</p><p>';
100 + echo '<p></p>';
105 101
106 - echo __("i.e. XMLRPC requests coming in to WordPress (whether from a legitimate app, or from an attacker) can only be verified using the password - not with a two-factor code. As a result, there not be an ideal option to pick below. You may have to choose between the convenience of using your apps, or the security of two factor authentication.", 'two-factor-authentication');
102 + echo __("Unfortunately, XMLRPC also provides a way for attackers to perform actions on your WordPress site, using only a password (i.e. without a two-factor password). More unfortunately, authors of legitimate programmes using XMLRPC have not yet added two-factor support to their code.", SIMBA_TFA_TEXT_DOMAIN);
103 +
104 + echo '<p></p>';
105 +
106 + echo __(" i.e. XMLRPC requests coming in to WordPress (whether from a legitimate app, or from an attacker) can only be verified using the password - not with a two-factor code. As a result, there not be an ideal option to pick below. You may have to choose between the convenience of using your apps, or the security of two factor authentication.", SIMBA_TFA_TEXT_DOMAIN);
107 +
107 108 echo '</p>';
108 -
109 109 ?>
110 110 <p>
111 - <?php $simba_two_factor_authentication->tfa_list_xmlrpc_status_radios(); ?>
112 - </p>
113 - <?php submit_button(); ?>
114 - </form>
115 - </div>
116 -
117 - <div id="simba-tfa-admin-settings-algorithm">
118 - <hr>
119 - <form method="post" action="options.php" style="margin-top: 40px">
120 - <?php
121 - settings_fields('simba_tfa_default_hmac_group');
122 - ?>
123 - <h2><?php _e('Default algorithm', 'two-factor-authentication'); ?></h2>
124 - <?php _e('Your users can change this in their own settings if they want.', 'two-factor-authentication'); ?>
125 - <p>
126 111 <?php
127 - $totp_controller->print_default_hmac_radios();
112 + $simba_two_factor_authentication->tfaListXMLRPCStatusRadios();
128 113 ?></p>
129 114 <?php submit_button(); ?>
130 115 </form>
131 116 </div>
@@ -130,59 +115,94 @@
130 115 </form>
131 116 </div>
132 117
133 118 <hr>
134 -
119 + <form method="post" action="options.php" style="margin-top: 40px">
135 120 <?php
136 - if (function_exists('WC')) {
137 -
138 - ?>
139 - <br><br>
140 - <h2><?php _e("WooCommerce integration", 'two-factor-authentication'); ?></h2>
121 + settings_fields('simba_tfa_default_hmac_group');
122 + ?>
123 + <h2><?php _e('Default algorithm', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
124 + <?php _e('Your users can change this in their own settings if they want.', SIMBA_TFA_TEXT_DOMAIN); ?>
141 125 <p>
142 - <?php echo apply_filters('simba_tfa_settings_woocommerce', '<a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/">'.__('The Premium version of this plugin allows you to add a configuration tab for users in the WooCommerce "My account" area.', 'two-factor-authentication').'</a>'); ?>
143 - </p>
144 - <hr>
145 - <?php } ?>
146 -
126 + <?php
127 + $simba_two_factor_authentication->tfaListDefaultHMACRadios();
128 + ?></p>
129 + <?php submit_button(); ?>
130 + </form>
131 + <hr>
147 132 <br><br>
148 - <h2><?php _e("Users' settings", 'two-factor-authentication'); ?></h2>
133 + <h2><?php _e("Users' settings", SIMBA_TFA_TEXT_DOMAIN); ?></h2>
149 134 <p>
150 135
151 136 <?php
152 137 if (!class_exists('Simba_Two_Factor_Authentication_Premium')) { ?>
153 138
154 - <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("The Premium version of this plugin allows you to see and reset the TFA settings of other users.", 'two-factor-authentication'); ?></a>
139 + <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("The Premium version of this plugin allows you to see and reset the TFA settings of other users.", SIMBA_TFA_TEXT_DOMAIN); ?></a>
155 140
156 - <a href="https://wordpress.org/plugins/user-switching/"><?php _e('Another way to do that is by using a user-switching plugin like this one.', 'two-factor-authentication'); ?></a>
141 + <a href="https://wordpress.org/plugins/user-switching/"><?php _e('Another way to do that is by using a user-switching plugin like this one.', SIMBA_TFA_TEXT_DOMAIN); ?></a>
157 142
158 143 <?php } ?>
159 144
160 145 <?php do_action('simba_tfa_users_settings'); ?>
161 146
147 + <?php
148 +
149 + // Disabled
150 + if (1==0) {
151 + //List users and type of tfa
152 + foreach($wp_roles->role_names as $id => $name)
153 + {
154 + $setting = $simba_two_factor_authentication->get_option('tfa_'.$id);
155 + $setting = $setting === false || $setting ? 1 : 0;
156 + if(!$setting)
157 + continue;
158 +
159 + $users_q = new WP_User_Query( array(
160 + 'role' => $name
161 + ));
162 + $users = $users_q->get_results();
163 +
164 + if(!$users)
165 + continue;
166 +
167 + print '<h3>'.$name.'s</h3>';
168 +
169 + foreach( $users as $user )
170 + {
171 + $userdata = get_userdata( $user->ID );
172 + $tfa_type = get_user_meta($user->ID, 'simbatfa_delivery_type', true);
173 + print '<span style="font-size: 1.2em">'.esc_attr( $userdata->user_nicename ).'</span>';
174 + if(!$tfa_type)
175 + print ' - '.__('Default', SIMBA_TFA_TEXT_DOMAIN);
176 + else
177 + print ' - <a class="button" href="'.esc_url(add_query_arg(array('tfa_change_to_email' => 1, 'tfa_user_id' => $user->ID))).'">'.__('Change to email', SIMBA_TFA_TEXT_DOMAIN).'</a>';
178 + print '<br>';
179 + }
180 + }
181 + }
182 +
183 + ?>
162 184 <hr>
163 185 <?php if (!class_exists('Simba_Two_Factor_Authentication_Premium')) { ?>
164 - <h2><?php _e('Premium version', 'two-factor-authentication'); ?></h2>
186 + <h2><?php _e('Premium version', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
165 187 <p>
166 - <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("If you want to say 'thank you' or help this plugin's development, or get extra features, then please take a look at the premium version of this plugin.", 'two-factor-authentication'); ?></a> <?php _e('It comes with these extra features:', 'two-factor-authentication');?><br>
188 + <a href="https://www.simbahosting.co.uk/s3/product/two-factor-authentication/"><?php _e("If you want to say 'thank you' or help this plugin's development, or get extra features, then please take a look at the premium version of this plugin.", SIMBA_TFA_TEXT_DOMAIN); ?></a> <?php _e('It comes with these extra features:', SIMBA_TFA_TEXT_DOMAIN);?><br>
167 189 </p>
168 190 <p>
169 191 <ul style="list-style: disc inside;">
170 - <li><strong><?php _e('Emergency codes', 'two-factor-authentication');?></strong> - <?php _e('provide your users with one-time codes to use in case they lose their device.', 'two-factor-authentication');?></li>
171 - <li><strong><?php _e('Make TFA compulsory', 'two-factor-authentication');?></strong> - <?php _e('require your users to set up TFA to be able to log in, after an optional grace period.', 'two-factor-authentication');?></li>
172 - <li><strong><?php _e('Trusted devices', 'two-factor-authentication');?></strong> - <?php _e('allow privileged (or all) users to mark a device as trusted and thereby only needing to supply a TFA code upon login every so-many days (e.g. every 30 days) instead of on each login.', 'two-factor-authentication');?></li>
173 - <li><strong><?php _e('Manage all users centrally', 'two-factor-authentication');?></strong> - <?php _e('enable, disable or see TFA codes for all your users from one central location.', 'two-factor-authentication');?></li>
174 - <li><strong><?php _e('More shortcodes', 'two-factor-authentication');?></strong> - <?php _e('flexible shortcodes allowing you to design your front-end settings page for your users exactly as you wish.', 'two-factor-authentication');?></li>
175 - <li><strong><?php _e('Personal support', 'two-factor-authentication');?></strong> - <?php _e('access to our personal support desk for 12 months.', 'two-factor-authentication');?></li>
192 + <li><strong><?php _e('Emergency codes', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('provide your users with one-time codes to use in case they lose their device.', SIMBA_TFA_TEXT_DOMAIN);?></li>
193 + <li><strong><?php _e('Manage all users centrally', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('enable, disable or see TFA codes for all your users from one central location.', SIMBA_TFA_TEXT_DOMAIN);?></li>
194 + <li><strong><?php _e('More shortcodes', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('flexible shortcodes allowing you to design your front-end settings page for your users exactly as you wish.', SIMBA_TFA_TEXT_DOMAIN);?></li>
195 + <li><strong><?php _e('Personal support', SIMBA_TFA_TEXT_DOMAIN);?></strong> - <?php _e('access to our personal support desk for 12 months.', SIMBA_TFA_TEXT_DOMAIN);?></li>
176 196 </ul>
177 197 </p>
178 198 <hr>
179 199 <?php } ?>
180 200
181 - <h2><?php _e('Translations', 'two-factor-authentication'); ?></h2>
201 + <h2><?php _e('Translations', SIMBA_TFA_TEXT_DOMAIN); ?></h2>
182 202 <p>
183 - <?php echo sprintf(__("If you want to translate this plugin, please go to %s", 'two-factor-authentication'), '<a href="https://translate.wordpress.org/projects/wp-plugins/two-factor-authentication/">'.__('the wordpress.org translation website.', 'two-factor-authentication').'</a>').' '.__("Don't send us the translation file directly - plugin authors do not have access to the wordpress.org translation system (local language teams do).", 'two-factor-authentication'); ?>
203 + <?php _e("If you translate this plugin, please send the translations .po-file to us so we can include it in future releases - paste a link in the plugin's support forum.", SIMBA_TFA_TEXT_DOMAIN); ?>
184 204 <br>
185 205 </p>
186 206
187 207 </div>
188 -</div>
208 +</div>