PluginProbe
User Access Manager / 2.2.23
User Access Manager v2.2.23
2.3.20 2.3.19 2.3.18 2.3.17 2.3.16 2.3.15 2.3.14 2.3.13 trunk 0.6 0.6.1 0.6.2 0.7 0.7 Beta 0.7.0.1 0.8 0.8.0.1 0.8.0.2 0.9 0.9.1 0.9.1.1 0.9.1.2 0.9.1.3 0.9.1.4 1.0 All 136 releases
← All changes | src/Controller/Frontend/RedirectController.php +182 -84 2.3.162.2.23 View file →
@@ -1,11 +1,23 @@
1 1 <?php
2 +/**
3 + * FrontendRedirectController.php
4 + *
5 + * The FrontendRedirectController class file.
6 + *
7 + * PHP versions 5
8 + *
9 + * @author Alexander Schneider <alexanderschneider85@gmail.com>
10 + * @copyright 2008-2017 Alexander Schneider
11 + * @license http://www.gnu.org/licenses/gpl-2.0.html GNU General Public License, version 2
12 + * @version SVN: $id$
13 + * @link http://wordpress.org/extend/plugins/user-access-manager/
14 + */
2 15
3 16 declare(strict_types=1);
4 17
5 18 namespace UserAccessManager\Controller\Frontend;
6 19
7 -use JetBrains\PhpStorm\NoReturn;
8 20 use UserAccessManager\Access\AccessHandler;
9 21 use UserAccessManager\Cache\Cache;
10 22 use UserAccessManager\Config\MainConfig;
11 23 use UserAccessManager\Config\WordpressConfig;
@@ -19,36 +31,110 @@
19 31 use UserAccessManager\Util\Util;
20 32 use UserAccessManager\Wrapper\Php;
21 33 use UserAccessManager\Wrapper\Wordpress;
22 34
35 +/**
36 + * Class FrontendRedirectController
37 + *
38 + * @package UserAccessManager\Controller
39 + */
23 40 class RedirectController extends Controller
24 41 {
25 42 use LoginControllerTrait;
26 43
27 - public const POST_URL_CACHE_KEY = 'PostUrls';
28 - public const REDIRECT_TO_PARAMETER = 'redirect_to';
44 + const POST_URL_CACHE_KEY = 'PostUrls';
29 45
46 + /**
47 + * @var MainConfig
48 + */
49 + private $mainConfig;
50 +
51 + /**
52 + * @var Database
53 + */
54 + private $database;
55 +
56 + /**
57 + * @var Cache
58 + */
59 + private $cache;
60 +
61 + /**
62 + * @var Util
63 + */
64 + private $util;
65 +
66 + /**
67 + * @var ObjectHandler
68 + */
69 + private $objectHandler;
70 +
71 + /**
72 + * @var AccessHandler
73 + */
74 + private $accessHandler;
75 +
76 + /**
77 + * @var FileHandler
78 + */
79 + private $fileHandler;
80 +
81 + /**
82 + * @var FileObjectFactory
83 + */
84 + private $fileObjectFactory;
85 +
86 + /**
87 + * RedirectController constructor.
88 + * @param Php $php
89 + * @param Wordpress $wordpress
90 + * @param WordpressConfig $wordpressConfig
91 + * @param MainConfig $mainConfig
92 + * @param Database $database
93 + * @param Util $util
94 + * @param Cache $cache
95 + * @param ObjectHandler $objectHandler
96 + * @param AccessHandler $accessHandler
97 + * @param FileHandler $fileHandler
98 + * @param FileObjectFactory $fileObjectFactory
99 + */
30 100 public function __construct(
31 101 Php $php,
32 102 Wordpress $wordpress,
33 103 WordpressConfig $wordpressConfig,
34 - private MainConfig $mainConfig,
35 - private Database $database,
36 - private Util $util,
37 - private Cache $cache,
38 - private ObjectHandler $objectHandler,
39 - private AccessHandler $accessHandler,
40 - private FileHandler $fileHandler,
41 - private FileObjectFactory $fileObjectFactory
104 + MainConfig $mainConfig,
105 + Database $database,
106 + Util $util,
107 + Cache $cache,
108 + ObjectHandler $objectHandler,
109 + AccessHandler $accessHandler,
110 + FileHandler $fileHandler,
111 + FileObjectFactory $fileObjectFactory
42 112 ) {
43 113 parent::__construct($php, $wordpress, $wordpressConfig);
114 + $this->mainConfig = $mainConfig;
115 + $this->database = $database;
116 + $this->util = $util;
117 + $this->cache = $cache;
118 + $this->objectHandler = $objectHandler;
119 + $this->accessHandler = $accessHandler;
120 + $this->fileHandler = $fileHandler;
121 + $this->fileObjectFactory = $fileObjectFactory;
44 122 }
45 123
124 + /**
125 + * @return Wordpress
126 + */
46 127 protected function getWordpress(): Wordpress
47 128 {
48 129 return $this->wordpress;
49 130 }
50 131
132 + /**
133 + * Returns the post by the given url.
134 + * @param string $url The url of the post(attachment).
135 + * @return int
136 + */
51 137 public function getPostIdByUrl(string $url): int
52 138 {
53 139 $postUrls = (array)$this->cache->getFromRuntimeCache(self::POST_URL_CACHE_KEY);
54 140
@@ -73,78 +159,61 @@
73 159
74 160 return $postUrls[$url];
75 161 }
76 162
77 - private function normalizeAttachmentUrl(array $uploadDirs, string $objectUrl): string
163 + /**
164 + * Returns the file object by the given type and url.
165 + * @param string $objectType The type of the requested file.
166 + * @param string $objectUrl The file url.
167 + * @return null|FileObject
168 + */
169 + private function getFileSettingsByType(string $objectType, string $objectUrl): ?FileObject
78 170 {
79 - $uploadDir = str_replace(ABSPATH, '/', $uploadDirs['basedir']);
80 - $regex = '/.*' . str_replace('/', '\/', $uploadDir) . '\//i';
81 - $cleanObjectUrl = preg_replace($regex, '', $objectUrl);
82 - $uploadUrl = str_replace('/files', $uploadDir, $uploadDirs['baseurl']);
171 + $fileObject = null;
83 172
84 - return rtrim($uploadUrl, '/') . '/' . ltrim($cleanObjectUrl, '/');
85 - }
173 + if ($objectType === ObjectHandler::ATTACHMENT_OBJECT_TYPE) {
174 + $uploadDirs = $this->wordpress->getUploadDir();
175 + $uploadDir = str_replace(ABSPATH, '/', $uploadDirs['basedir']);
176 + $regex = '/.*' . str_replace('/', '\/', $uploadDir) . '\//i';
177 + $cleanObjectUrl = preg_replace($regex, '', $objectUrl);
178 + $uploadUrl = str_replace('/files', $uploadDir, $uploadDirs['baseurl']);
179 + $objectUrl = rtrim($uploadUrl, '/') . '/' . ltrim($cleanObjectUrl, '/');
86 180
87 - private function getAttachmentFileObject(string $objectUrl): ?FileObject
88 - {
89 - $uploadDirs = $this->wordpress->getUploadDir();
90 - $postId = $this->getPostIdByUrl($this->normalizeAttachmentUrl($uploadDirs, $objectUrl));
181 + $post = $this->objectHandler->getPost($this->getPostIdByUrl($objectUrl));
182 + $postType = $post->post_type ?? '';
91 183
92 - if ($postId < 1) {
93 - return null;
94 - }
184 + if ($postType === ObjectHandler::ATTACHMENT_OBJECT_TYPE) {
185 + $multiPath = str_replace('/files', $uploadDir, $uploadDirs['baseurl']);
95 186
96 - $post = $this->objectHandler->getPost($postId);
187 + $fileObject = $this->fileObjectFactory->createFileObject(
188 + $post->ID,
189 + $objectType,
190 + $uploadDirs['basedir'] . str_replace($multiPath, '', $objectUrl),
191 + $this->wordpress->attachmentIsImage($post->ID)
192 + );
193 + }
194 + } else {
195 + $extraParameter = $this->getRequestParameter('uamextra');
97 196
98 - if (($post->post_type ?? '') !== ObjectHandler::ATTACHMENT_OBJECT_TYPE) {
99 - return null;
197 + $fileObject = $this->wordpress->applyFilters(
198 + 'uam_get_file_settings_by_type',
199 + $fileObject,
200 + $objectType,
201 + $objectUrl,
202 + $extraParameter
203 + );
100 204 }
101 205
102 - $file = $this->wordpress->getAttachedFile($post->ID);
103 -
104 - if ($file === false || $this->isInsideUploadDirectory($file, $uploadDirs['basedir']) === false) {
105 - return null;
106 - }
107 -
108 - return $this->fileObjectFactory->createFileObject(
109 - $post->ID,
110 - ObjectHandler::ATTACHMENT_OBJECT_TYPE,
111 - $file,
112 - $this->wordpress->attachmentIsImage($post->ID)
113 - );
206 + return $fileObject;
114 207 }
115 208
116 - private function isInsideUploadDirectory(string $file, string $uploadBaseDir): bool
117 - {
118 - $realFile = $this->php->realpath($file);
119 - $realUploadBaseDir = $this->php->realpath($uploadBaseDir);
120 -
121 - return $realFile !== false
122 - && $realUploadBaseDir !== false
123 - && str_starts_with($realFile, $realUploadBaseDir . DIRECTORY_SEPARATOR);
124 - }
125 -
126 - private function getFileSettingsByType(string $objectType, string $objectUrl): ?FileObject
127 - {
128 - if ($objectType === ObjectHandler::ATTACHMENT_OBJECT_TYPE) {
129 - return $this->getAttachmentFileObject($objectUrl);
130 - }
131 -
132 - $extraParameter = $this->getRequestParameter('uamextra');
133 -
134 - return $this->wordpress->applyFilters(
135 - 'uam_get_file_settings_by_type',
136 - null,
137 - $objectType,
138 - $objectUrl,
139 - $extraParameter
140 - );
141 - }
142 -
143 209 /**
210 + * Delivers the content of the requested file.
211 + * @param string $objectType The type of the requested file.
212 + * @param string $objectUrl The file url.
144 213 * @throws UserGroupTypeException
145 214 */
146 - public function getFile(string $objectType, string $objectUrl): void
215 + public function getFile(string $objectType, string $objectUrl)
147 216 {
148 217 $fileObject = $this->getFileSettingsByType($objectType, $objectUrl);
149 218
150 219 if ($fileObject === null) {
@@ -167,8 +236,13 @@
167 236
168 237 $this->fileHandler->getFile($file, $fileObject->isImage());
169 238 }
170 239
240 + /**
241 + * Returns the redirect url and the permalink of the post if exists.
242 + * @param null|string $permalink
243 + * @return null|string
244 + */
171 245 private function getRedirectUrlAndPermalink(?string &$permalink): ?string
172 246 {
173 247 $permalink = null;
174 248 $redirect = $this->mainConfig->getRedirect();
@@ -185,11 +259,8 @@
185 259 } elseif ($redirect === 'custom_url') {
186 260 $url = $this->mainConfig->getRedirectCustomUrl();
187 261 } elseif ($redirect === 'login') {
188 262 $url = $this->getLoginUrl();
189 - } elseif ($redirect === 'origin') {
190 - $referer = $this->wordpress->getReferer();
191 - $url = $referer !== false ? $referer : $this->wordpress->getHomeUrl('/');
192 263 } else {
193 264 $url = $this->wordpress->getHomeUrl('/');
194 265 }
195 266
@@ -196,14 +267,16 @@
196 267 return $url;
197 268 }
198 269
199 270 /**
271 + * Redirects the user to his destination.
272 + * @param bool $checkPosts
200 273 * @throws UserGroupTypeException
201 274 */
202 - public function redirectUser(bool $checkPosts = true): void
275 + public function redirectUser($checkPosts = true)
203 276 {
204 277 if ($checkPosts === true) {
205 - $posts = $this->wordpress->getWpQuery()->get_posts();
278 + $posts = (array)$this->wordpress->getWpQuery()->get_posts();
206 279
207 280 foreach ($posts as $post) {
208 281 if ($this->accessHandler->checkObjectAccess($post->post_type, $post->ID)) {
209 282 return;
@@ -214,17 +287,18 @@
214 287 $url = $this->getRedirectUrlAndPermalink($permalink);
215 288 $currentUrl = $this->util->getCurrentUrl();
216 289
217 290 if ($url !== null && $url !== $currentUrl && $permalink !== $currentUrl) {
218 - if ($this->mainConfig->appendRedirectToParameter() === true) {
219 - $url = $this->wordpress->addQueryArg([self::REDIRECT_TO_PARAMETER => $currentUrl], $url);
220 - }
221 -
222 291 $this->wordpress->wpRedirect($url);
223 292 $this->php->callExit();
224 293 }
225 294 }
226 295
296 + /**
297 + * Returns the post id by the post name.
298 + * @param string $name
299 + * @return int
300 + */
227 301 private function getPostIdByName(string $name): int
228 302 {
229 303 $postableTypes = implode('\',\'', $this->objectHandler->getPostTypes());
230 304
@@ -231,9 +305,9 @@
231 305 $query = $this->database->prepare(
232 306 "SELECT ID
233 307 FROM {$this->database->getPostsTable()}
234 308 WHERE post_name = %s
235 - AND post_type IN ('$postableTypes')",
309 + AND post_type IN ('{$postableTypes}')",
236 310 $name
237 311 );
238 312
239 313 return (int) $this->database->getVariable($query);
@@ -238,9 +312,15 @@
238 312
239 313 return (int) $this->database->getVariable($query);
240 314 }
241 315
242 - private function extractObjectTypeAndId(mixed $pageParams, ?string &$objectType, int|string|null &$objectId): void
316 + /**
317 + * Extracts the object type and id.
318 + * @param mixed $pageParams
319 + * @param null|string $objectType
320 + * @param null|int|string $objectId
321 + */
322 + private function extractObjectTypeAndId($pageParams, ?string &$objectType, ?string &$objectId)
243 323 {
244 324 $objectType = null;
245 325 $objectId = null;
246 326
@@ -270,11 +350,15 @@
270 350 }
271 351 }
272 352
273 353 /**
354 + * Redirects to a page or to content.
355 + * @param array|null $headers The headers which are given from wordpress.
356 + * @param mixed $pageParams The params of the current page.
357 + * @return array|null
274 358 * @throws UserGroupTypeException
275 359 */
276 - public function redirect(?array $headers, mixed $pageParams): ?array
360 + public function redirect(?array $headers, $pageParams): ?array
277 361 {
278 362 $fileUrl = $this->getRequestParameter('uamgetfile');
279 363 $fileType = $this->getRequestParameter('uamfiletype');
280 364
@@ -292,9 +376,15 @@
292 376
293 377 return $headers;
294 378 }
295 379
296 - public function getFileUrl(string $url, int|string|null $id): string
380 + /**
381 + * Returns the url for a locked file.
382 + * @param string $url The base url.
383 + * @param int|string $id The id of the file.
384 + * @return string
385 + */
386 + public function getFileUrl(string $url, $id): string
297 387 {
298 388 // Nginx always supports real urls so we need the new urls only
299 389 // if we don't use nginx and mod_rewrite is disabled
300 390 if ($this->mainConfig->lockFile() === true
@@ -302,9 +392,9 @@
302 392 && $this->wordpress->gotModRewrite() === false
303 393 ) {
304 394 $post = $this->objectHandler->getPost($id);
305 395
306 - if ($post !== false) {
396 + if ($post !== null) {
307 397 $type = explode('/', $post->post_mime_type);
308 398 $type = $type[1] ?? $type[0];
309 399
310 400 $lockedFileTypes = $this->mainConfig->getLockedFiles();
@@ -318,8 +408,14 @@
318 408
319 409 return $url;
320 410 }
321 411
412 + /**
413 + * Caches the urls for the post for a later lookup.
414 + * @param string $url The url of the post.
415 + * @param object $post The post object.
416 + * @return string
417 + */
322 418 public function cachePostLinks(string $url, object $post): string
323 419 {
324 420 $postUrls = (array) $this->cache->getFromRuntimeCache(self::POST_URL_CACHE_KEY);
325 421 $postUrls[$url] = $post->ID;
@@ -326,10 +422,12 @@
326 422 $this->cache->addToRuntimeCache(self::POST_URL_CACHE_KEY, $postUrls);
327 423 return $url;
328 424 }
329 425
330 - #[NoReturn]
331 - public function testXSendFile(): void
426 + /**
427 + * Tries to load the file via x send file
428 + */
429 + public function testXSendFile()
332 430 {
333 431 $this->fileHandler->deliverXSendFileTestFile();
334 432 }
335 433 }