PluginProbe ʕ •ᴥ•ʔ
WooCommerce / 11.1.0
WooCommerce v11.1.0
11.1.0 11.1.0-rc.2 11.1.0-rc.1 11.1.0-beta.2 11.1.0-beta.1 11.0.1 11.0.0 11.0.0-rc.3 11.0.0-rc.2 11.0.0-rc.1 11.0.0-beta.2 11.0.0-beta.1 10.9.4 10.9.3 10.9.2 10.9.1 10.9.0 10.9.0-rc.1 10.9.0-beta.2 10.9.0-beta.1 10.8.1 10.8.0 10.8.0-rc.1 10.8.0-beta.2 10.8.0-beta.1 7.8.0-beta.1 7.8.0-beta.2 7.8.0-rc.1 7.8.0-rc.2 7.8.1 7.8.2 7.8.3 7.8.4 7.9.0 7.9.0-beta.1 7.9.0-beta.2 7.9.0-rc.2 7.9.0-rc.3 7.9.1 7.9.2 8.0.0 8.0.0-beta.1 8.0.0-beta.2 8.0.0-rc.1 8.0.0-rc.2 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.1.0 8.1.0-beta.1 8.1.0-rc.1 8.1.0-rc.2 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 8.2.0-beta.1 8.2.0-rc.1 8.2.0-rc.2 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.3.0 8.3.0-beta.1 8.3.0-rc.1 8.3.0-rc.2 8.3.1 8.3.2 8.3.3 8.3.4 8.4.0 8.4.0-beta.1 8.4.0-rc.1 8.4.1 8.4.2 8.4.3 8.5.0 8.5.0-beta.1 8.5.0-rc.1 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.6.0 8.6.0-beta.1 8.6.0-rc.1 8.6.1 8.6.2 8.6.3 8.6.4 8.7.0 8.7.0-beta.1 8.7.0-beta.2 8.7.0-rc.1 8.7.1 8.7.2 8.7.3 8.8.0 8.8.0-beta.1 8.8.0-rc.1 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.8.6 8.8.7 8.9.0 8.9.0-beta.1 8.9.0-rc.1 8.9.1 8.9.2 8.9.3 8.9.4 8.9.5 9.0.0 9.0.0-beta.1 9.0.0-beta.2 9.0.0-rc.1 9.0.1 9.0.2 9.0.3 9.0.4 9.1.0 9.1.0-beta.1 9.1.0-rc.1 9.1.1 9.1.2 9.1.3 9.1.4 9.1.5 9.1.6 9.2.0 9.2.0-beta.1 9.2.0-rc.1 9.2.1 9.2.2 9.2.3 9.2.4 9.2.5 9.3.0 9.3.0-beta.1 9.3.0-rc.1 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.3.6 9.4.0 9.4.0-beta.1 9.4.0-beta.2 9.4.0-rc.1 9.4.0-rc.2 9.4.0-rc.3 9.4.0-rc.4 9.4.1 9.4.2 9.4.3 9.4.4 9.4.5 9.5.0 9.5.0-beta.1 9.5.0-beta.2 9.5.0-rc.1 9.5.1 9.5.2 9.5.3 9.5.4 9.6.0 9.6.0-beta.1 9.6.0-beta.2 9.6.0-rc.1 9.6.1 9.6.2 9.6.3 9.6.4 9.7.0 9.7.0-beta.1 9.7.0-rc.1 9.7.1 9.7.2 9.7.3 9.8.0 9.8.0-beta.1 9.8.0-rc.1 9.8.1 9.8.2 9.8.3 9.8.4 9.8.5 9.8.6 9.8.7 9.9.0 9.9.0-beta.1 9.9.0-rc.1 9.9.1 9.9.2 9.9.3 9.9.4 9.9.5 9.9.6 9.9.7 3.7.3 7.1.2 3.8.0 7.2.0 3.8.0-beta.1 7.2.0-beta.1 3.8.0-rc.1 7.2.0-beta.2 3.8.0-rc.2 7.2.0-rc.1 3.8.1 7.2.0-rc.2 3.8.2 7.2.1 3.8.3 7.2.2 3.9.0 7.2.3 3.9.0-beta.1 7.2.4 3.9.0-beta.2 7.3.0 3.9.0-rc.1 7.3.0-beta.1 3.9.0-rc.2 7.3.0-beta.2 3.9.0-rc.3 7.3.0-rc.1 3.9.0-rc.4 7.3.0-rc.2 3.9.1 7.3.1 3.9.2 7.4.0 3.9.3 7.4.0-beta.1 3.9.4 7.4.0-beta.2 3.9.5 7.4.0-rc.1 4.0.0 7.4.0-rc.2 4.0.0-beta.1 7.4.1 4.0.0-rc.1 7.4.2 4.0.0-rc.2 7.5.0 4.0.1 7.5.0-beta.1 4.0.2 7.5.0-beta.2 4.0.3 7.5.0-rc.1 4.0.4 7.5.1 4.1.0 7.5.2 4.1.0-beta.1 7.6.0 4.1.0-beta.2 7.6.0-beta.1 4.1.0-rc.1 7.6.0-beta.2 4.1.0-rc.2 7.6.0-rc.1 4.1.1 7.6.0-rc.2 4.1.2 7.6.0-rc.3 4.1.3 7.6.1 4.1.4 7.6.2 4.2.0 7.7.0 4.2.0-RC.1 7.7.0-beta.1 4.2.0-RC.2 7.7.0-beta.2 4.2.0-beta.1 7.7.0-rc.1 4.2.1 7.7.1 4.2.2 7.7.2 4.2.3 7.7.3 4.2.4 7.8.0 4.2.5 4.3.0 4.3.0-beta.1 4.3.0-rc.1 4.3.0-rc.2 4.3.0-rc.3 4.3.1 4.3.2 4.3.3 4.3.4 4.3.5 4.3.6 4.4.0 4.4.0-beta.1 4.4.0-rc.1 4.4.1 4.4.2 4.4.3 4.4.4 4.5.0 4.5.0-beta.1 4.5.0-rc.1 4.5.0-rc.3 4.5.1 4.5.2 4.5.3 4.5.4 4.5.5 4.6.0 4.6.0-beta.1 4.6.0-rc.1 4.6.1 4.6.2 4.6.3 4.6.4 4.6.5 4.7.0 4.7.0-beta.1 4.7.0-beta.2 4.7.0-rc.1 4.7.1 4.7.1-beta.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.0-beta.1 4.8.0-rc.1 4.8.0-rc.2 4.8.1 4.8.2 4.8.3 4.9.0 4.9.0-beta.1 4.9.0-rc.1 4.9.0-rc.2 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 5.0.0 5.0.0-beta.1 5.0.0-beta.2 5.0.0-rc.1 5.0.0-rc.2 5.0.0-rc.3 5.0.1 5.0.2 5.0.3 5.1.0 5.1.0-beta.1 5.1.0-rc.1 trunk 5.1.1 10.0.0 5.1.2 10.0.0-rc.1 5.1.3 10.0.0-rc.2 5.2.0 10.0.1 5.2.0-beta.1 10.0.2 5.2.0-rc.1 10.0.3 5.2.0-rc.2 10.0.4 5.2.1 10.0.5 5.2.2 10.0.6 5.2.3 10.1.0 5.2.4 10.1.0-rc.1 5.2.5 10.1.0-rc.2 5.3.0 10.1.0-rc.3 5.3.0-beta.1 10.1.0-rc.4 5.3.0-rc.1 10.1.1 5.3.0-rc.2 10.1.2 5.3.1 10.1.3 5.3.2 10.1.4 5.3.3 10.2.0 5.4.0 10.2.0-beta.1 5.4.0-beta.1 10.2.0-beta.2 5.4.0-rc.1 10.2.0-rc.1 5.4.1 10.2.1 5.4.2 10.2.2 5.4.3 10.2.3 5.4.4 10.2.4 5.4.5 10.3.0 5.5.0 10.3.0-beta.1 5.5.0-beta.1 10.3.0-beta.2 5.5.0-rc.1 10.3.0-rc.1 5.5.0-rc.2 10.3.0-rc.2 5.5.1 10.3.1 5.5.2 10.3.2 5.5.3 10.3.3 5.5.4 10.3.4 5.5.5 10.3.5 5.6.0 10.3.6 5.6.0-beta.1 10.3.7 5.6.0-rc.1 10.3.8 5.6.0-rc.2 10.4.0 5.6.1 10.4.0-beta.1 5.6.2 10.4.0-beta.2 5.6.3 10.4.0-rc.1 5.7.0 10.4.1 5.7.0-beta.1 10.4.2 5.7.0-rc.1 10.4.3 5.7.1 10.4.4 5.7.2 10.5.0 5.7.3 10.5.0-beta.1 5.8.0 10.5.0-beta.2 5.8.0-beta.1 10.5.0-rc.1 5.8.0-beta.2 10.5.0-rc.2 5.8.0-rc.1 10.5.0-rc.3 5.8.1 10.5.1 5.8.2 10.5.2 5.9.0 10.5.3 5.9.0-beta.1 10.6.0 5.9.0-rc.1 10.6.0-beta.1 5.9.0-rc.2 10.6.0-beta.2 5.9.1 10.6.0-rc.1 5.9.2 10.6.1 6.0.0 10.6.2 6.0.0-beta.1 10.7.0 6.0.0-rc.1 10.7.0-beta.1 6.0.1 10.7.0-beta.2 6.0.2 10.7.0-rc.1 6.1.0 3.0.0 6.1.0-beta.1 3.0.1 6.1.0-rc.1 3.0.2 6.1.0-rc.2 3.0.3 6.1.1 3.0.4 6.1.2 3.0.5 6.1.3 3.0.6 6.2.0 3.0.7 6.2.0-beta.1 3.0.8 6.2.0-rc.1 3.0.9 6.2.0-rc.2 3.1.0 6.2.1 3.1.1 6.2.2 3.1.2 6.2.3 3.2.0 6.3.0 3.2.1 6.3.0-beta.1 3.2.2 6.3.0-rc.1 3.2.3 6.3.0-rc.2 3.2.4 6.3.1 3.2.5 6.3.2 3.2.6 6.4.0 3.3.0 6.4.0-beta.1 3.3.1 6.4.0-rc.1 3.3.2 6.4.1 3.3.2-rc.1 6.4.2 3.3.3 6.5.0 3.3.4 6.5.0-beta.1 3.3.5 6.5.0-rc.1 3.3.6 6.5.0-rc.2 3.4.0 6.5.1 3.4.0-beta.1 6.5.2 3.4.0-rc.2 6.6.0 3.4.1 6.6.0-beta.1 3.4.2 6.6.0-rc.1 3.4.3 6.6.0-rc.2 3.4.4 6.6.1 3.4.5 6.6.2 3.4.6 6.7.0 3.4.7 6.7.0-beta.1 3.4.8 6.7.0-beta.2 3.5.0 6.7.0-rc.1 3.5.0-beta.1 6.7.1 3.5.0-rc.1 6.8.0 3.5.0-rc.2 6.8.0-beta.1 3.5.1 6.8.0-beta.2 3.5.10 6.8.0-rc.1 3.5.2 6.8.1 3.5.3 6.8.2 3.5.4 6.8.3 3.5.5 6.9.0 3.5.6 6.9.0-beta.1 3.5.7 6.9.0-beta.2 3.5.8 6.9.0-rc.1 3.5.9 6.9.1 3.6.0 6.9.2 3.6.0-beta.1 6.9.3 3.6.0-rc.1 6.9.4 3.6.0-rc.2 6.9.5 3.6.0-rc.3 7.0.0 3.6.1 7.0.0-beta.1 3.6.2 7.0.0-beta.2 3.6.3 7.0.0-beta.3 3.6.4 7.0.0-rc.1 3.6.5 7.0.0-rc.2 3.6.6 7.0.1 3.6.7 7.0.2 3.7.0 7.1.0 3.7.0-beta.1 7.1.0-beta.1 3.7.0-rc.1 7.1.0-beta.2 3.7.0-rc.2 7.1.0-rc.1 3.7.1 7.1.0-rc.2 3.7.2 7.1.1
woocommerce / src / StoreApi / SessionHandler.php
woocommerce / src / StoreApi Last commit date
Exceptions 2 weeks ago Formatters 1 month ago Payments 6 months ago Routes 2 weeks ago Schemas 2 weeks ago Utilities 2 weeks ago Authentication.php 3 weeks ago Formatters.php 2 years ago Legacy.php 1 year ago RoutesController.php 2 months ago SchemaController.php 2 months ago SessionHandler.php 3 weeks ago StoreApi.php 6 months ago deprecated.php 2 years ago functions.php 2 years ago
SessionHandler.php
210 lines
1 <?php
2 declare(strict_types=1);
3
4 namespace Automattic\WooCommerce\StoreApi;
5
6 use Automattic\Jetpack\Constants;
7 use Automattic\WooCommerce\StoreApi\Utilities\CartTokenUtils;
8 use WC_Session;
9 defined( 'ABSPATH' ) || exit;
10
11 /**
12 * SessionHandler class
13 *
14 * Token-based session handler for the Store API. Unlike WC_Session_Handler which
15 * uses browser cookies, this handler uses an HTTP_CART_TOKEN header (JWT-like) to
16 * identify sessions. It shares the same database table but has no cookie, cron,
17 * or cache layer.
18 *
19 * @since 10.7.0
20 */
21 final class SessionHandler extends WC_Session {
22 /**
23 * Token from HTTP headers.
24 *
25 * @var string
26 */
27 protected $token = '';
28
29 /**
30 * Table name for session data.
31 *
32 * @var string Custom session table name
33 */
34 protected $table = '';
35
36 /**
37 * Expiration timestamp.
38 *
39 * @var int
40 */
41 protected $session_expiration = 0;
42
43 /**
44 * Constructor for the session class.
45 */
46 public function __construct() {
47 $this->token = CartTokenUtils::get_request_cart_token();
48 $this->table = $GLOBALS['wpdb']->prefix . 'woocommerce_sessions';
49 }
50
51 /**
52 * Init hooks and session data.
53 */
54 public function init() {
55 $this->init_session_from_token();
56 add_action( 'shutdown', array( $this, 'save_data' ), 20 );
57 }
58
59 /**
60 * Process the token header to load the correct session.
61 *
62 * Verifies the signature here rather than trusting the caller that selected this handler.
63 */
64 protected function init_session_from_token() {
65 if ( ! CartTokenUtils::validate_cart_token( $this->token ) ) {
66 $this->_customer_id = $this->generate_customer_id();
67 $this->session_expiration = CartTokenUtils::get_cart_token_expiration();
68 $this->_data = array();
69 return;
70 }
71
72 $payload = CartTokenUtils::get_cart_token_payload( $this->token );
73
74 $this->_customer_id = $payload['user_id'];
75 $this->session_expiration = $payload['exp'];
76 $this->_data = (array) $this->get_session( $this->get_customer_id(), array() );
77 }
78
79 /**
80 * Return true if the current user has an active session.
81 *
82 * @return bool
83 */
84 public function has_session() {
85 return ! empty( $this->_customer_id );
86 }
87
88 /**
89 * Generate a unique customer ID for guests, or return user ID if logged in.
90 *
91 * @return string
92 */
93 public function generate_customer_id() {
94 return is_user_logged_in() ? (string) get_current_user_id() : wc_rand_hash( 't_', 30 );
95 }
96
97 /**
98 * Get session unique ID for requests if session is initialized or user ID if logged in.
99 *
100 * @return string
101 */
102 public function get_customer_unique_id() {
103 if ( $this->has_session() && $this->get_customer_id() ) {
104 return $this->get_customer_id();
105 }
106 return is_user_logged_in() ? (string) get_current_user_id() : '';
107 }
108
109 /**
110 * Get session data fresh from storage.
111 *
112 * This re-reads session data from the database rather than returning
113 * in-memory data, ensuring the latest persisted state is returned.
114 *
115 * @return array
116 */
117 public function get_session_data() {
118 return $this->has_session() ? (array) $this->get_session( $this->get_customer_id(), array() ) : array();
119 }
120
121 /**
122 * Returns the session.
123 *
124 * @param string $customer_id Customer ID.
125 * @param mixed $default_value Default session value.
126 *
127 * @return mixed Returns either the session data or the default value. Returns false if WP setup is in progress.
128 */
129 public function get_session( $customer_id, $default_value = false ) {
130 global $wpdb;
131
132 // This mimics behaviour from default WC_Session_Handler class. There will be no sessions retrieved while WP setup is due.
133 if ( Constants::is_defined( 'WP_SETUP_CONFIG' ) ) {
134 return $default_value;
135 }
136
137 $value = $wpdb->get_var(
138 $wpdb->prepare(
139 'SELECT session_value FROM %i WHERE session_key = %s',
140 $this->table,
141 $customer_id
142 )
143 );
144
145 if ( is_null( $value ) ) {
146 $value = $default_value;
147 }
148
149 return maybe_unserialize( $value );
150 }
151
152 /**
153 * Destroy all session data.
154 *
155 * @return void
156 */
157 public function destroy_session() {
158 $this->delete_session( $this->get_customer_id() );
159 $this->forget_session();
160 }
161
162 /**
163 * Forget all session data without destroying persisted storage.
164 *
165 * @return void
166 */
167 public function forget_session() {
168 $this->_data = array();
169 $this->_dirty = false;
170 $this->_customer_id = null;
171 }
172
173 /**
174 * Delete the session from the database.
175 *
176 * @param string $customer_id Customer session ID.
177 * @return void
178 */
179 public function delete_session( $customer_id ) {
180 if ( ! $customer_id ) {
181 return;
182 }
183 $GLOBALS['wpdb']->delete( $this->table, array( 'session_key' => $customer_id ) );
184 }
185
186 /**
187 * Save data and delete user session.
188 *
189 * @return void
190 */
191 public function save_data() {
192 // Dirty if something changed - prevents saving nothing new.
193 if ( $this->_dirty ) {
194 global $wpdb;
195
196 $wpdb->query(
197 $wpdb->prepare(
198 'INSERT INTO %i (`session_key`, `session_value`, `session_expiry`) VALUES (%s, %s, %d) ON DUPLICATE KEY UPDATE `session_value` = VALUES(`session_value`), `session_expiry` = VALUES(`session_expiry`)',
199 $this->table,
200 $this->get_customer_id(),
201 maybe_serialize( $this->_data ),
202 $this->session_expiration
203 )
204 );
205
206 $this->_dirty = false;
207 }
208 }
209 }
210