PluginProbe ʕ •ᴥ•ʔ
VikAppointments Services Booking Calendar / 1.2.21
VikAppointments Services Booking Calendar v1.2.21
1.2.21 1.2.20 trunk 1.2.17 1.2.18 1.2.19
vikappointments / libraries / adapter / session / session.php
vikappointments / libraries / adapter / session Last commit date
handler.php 3 days ago session.php 3 days ago
session.php
262 lines
1 <?php
2 /**
3 * @package VikWP - Libraries
4 * @subpackage adapter.session
5 * @author E4J s.r.l.
6 * @copyright Copyright (C) 2023 E4J s.r.l. All Rights Reserved.
7 * @license http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL
8 * @link https://vikwp.com
9 */
10
11 // No direct access
12 defined('ABSPATH') or die('No script kiddies please!');
13
14 /**
15 * Class adapter for managing HTTP sessions using the Joomla standard interface.
16 *
17 * @since 10.0
18 */
19 class JSession
20 {
21 /**
22 * The session adapter instance.
23 *
24 * @var JSession
25 */
26 private static $instance = null;
27
28 /**
29 * Session data pool.
30 *
31 * @var array
32 */
33 private $data;
34
35 /**
36 * Class constructor.
37 */
38 public function __construct()
39 {
40 $this->data = &$_SESSION;
41 }
42
43 /**
44 * Returns the global Session object, only creating it if it doesn't already exist.
45 *
46 * @return self The session object.
47 */
48 public static function getInstance()
49 {
50 if (static::$instance === null)
51 {
52 static::$instance = new JSession();
53 }
54
55 return static::$instance;
56 }
57
58 /**
59 * Gets data from the session store.
60 *
61 * @param string $name Name of a variable.
62 * @param mixed $default Default value of a variable if not set.
63 * @param string $namespace Namespace to use.
64 *
65 * @return mixed Value of a variable.
66 */
67 public function get($name, $default = null, $namespace = 'default')
68 {
69 // add prefix and namespace to avoid collisions
70 $key = '__' . $namespace . '.' . $name;
71
72 // check if the key is contained in the SESSION
73 if (isset($this->data[$key]))
74 {
75 return $this->data[$key];
76 }
77
78 return $default;
79 }
80
81 /**
82 * Sets data into the session store.
83 *
84 * @param string $name Name of a variable.
85 * @param mixed $value Value of a variable.
86 * @param string $namespace Namespace to use.
87 *
88 * @return mixed Old value of a variable.
89 *
90 * @uses get()
91 */
92 public function set($name, $value = null, $namespace = 'default')
93 {
94 $prev = $this->get($name, null, $namespace);
95
96 // add prefix and namespace to avoid collisions
97 $key = '__' . $namespace . '.' . $name;
98
99 // push the value in the session
100 $this->data[$key] = $value;
101
102 return $prev;
103 }
104
105 /**
106 * Checks whether data exists in the session store.
107 *
108 * @param string $name Name of variable.
109 * @param string $namespace Namespace to use.
110 *
111 * @return boolean True if the variable exists.
112 *
113 * @uses get()
114 */
115 public function has($name, $namespace = 'default')
116 {
117 return !is_null($this->get($name, null, $namespace));
118 }
119
120 /**
121 * Unsets data from the session store.
122 *
123 * @param string $name Name of variable.
124 * @param string $namespace Namespace to use.
125 *
126 * @return mixed The value from session or NULL if not set.
127 *
128 * @uses set()
129 */
130 public function clear($name, $namespace = 'default')
131 {
132 return $this->set($name, null, $namespace);
133 }
134
135 /**
136 * Returns our internal nonce identifier.
137 *
138 * @param boolean $forceNew If true, the action will be randomly changed,
139 * instructing WP to use a different token.
140 *
141 * @return string The action name that will be used by WordPress to create
142 * a matching token hash.
143 *
144 * @since 10.1.33
145 */
146 public static function getFormTokenAction($forceNew = false)
147 {
148 // create initial identifier
149 static $id = 1;
150
151 if ($forceNew)
152 {
153 // Refresh identifier when requested.
154 // Use a random ID to prevent predictability.
155 $id = uniqid();
156 }
157
158 // merge method name with our unique identifier
159 $action = __METHOD__ . '.' . $id;
160
161 /**
162 * Plugins can use this hook to change at runtime the action to
163 * use while creating/validating a WordPress nonce.
164 *
165 * @param string $action The action to filter.
166 *
167 * @since 10.1.33
168 */
169 return apply_filters('vik_csrf_token_action', $action);
170 }
171
172 /**
173 * Returns the name that will be used while generating the token input
174 * and during its validation.
175 *
176 * @return string The input name.
177 */
178 public static function getFormTokenName()
179 {
180 /**
181 * Plugins can use this hook to change at runtime the name to
182 * use while creating/validating a WordPress nonce.
183 *
184 * @param string $name The name to filter.
185 *
186 * @since 10.1.33
187 */
188 return apply_filters('vik_csrf_token_name', 'vikwp_nonce');
189 }
190
191 /**
192 * Method to determine a hash for anti-spoofing variable names.
193 *
194 * @param boolean $forceNew If true, force a new token to be created.
195 *
196 * @return string Hashed var name.
197 *
198 * @uses getToken()
199 */
200 public static function getFormToken($forceNew = false)
201 {
202 // create nonce by using our internal action
203 return wp_create_nonce(static::getFormTokenAction($forceNew));
204 }
205
206 /**
207 * Checks for a form token in the request.
208 * Use with JHtml::fetch('form.token') or Session::getFormToken().
209 *
210 * @param string $method The request method in which to look for the token key.
211 *
212 * @return boolean True if found and valid, false otherwise.
213 */
214 public static function checkToken($method = 'post')
215 {
216 /**
217 * Plugins can use this hook to change the default behavior used to validate
218 * the CSRF tokens.
219 *
220 * @param boolean|null $valid True whether the token is valid, false in case
221 * it is invalid, null to let the system uses its
222 * own validation.
223 *
224 * @since 10.1.33
225 */
226 $validated = apply_filters('vik_csrf_token_check', null);
227
228 if (!is_null($validated))
229 {
230 // A plugin validated the token itself.
231 // Even if we cannot trust that validation, we have to return the status
232 // fetched by the attached plugins.
233 return (bool) $validated;
234 }
235
236 $action = static::getFormTokenAction();
237 $app = JFactory::getApplication();
238
239 // check from header first, since AJAX request might specify the
240 // X-CSRF-Token directive within the server headers
241 $nonce = $app->input->server->get('HTTP_X_CSRF_TOKEN', '', 'alnum');
242
243 if ($nonce && wp_verify_nonce($nonce, $action))
244 {
245 return true;
246 }
247
248 // get the name of the data set in request
249 $name = static::getFormTokenName();
250
251 // then fallback to HTTP query
252 $nonce = $app->input->$method->get($name, '', 'alnum');
253
254 if ($nonce && wp_verify_nonce($nonce, $action))
255 {
256 return true;
257 }
258
259 return false;
260 }
261 }
262