PluginProbe
ManageWP Worker / 4.9.25
ManageWP Worker v4.9.25
4.9.38 4.9.37 4.9.36 4.9.35 4.9.34 3.8.7 3.8.8 3.9.0 3.9.1 3.9.10 3.9.11 3.9.12 3.9.13 3.9.14 3.9.15 3.9.16 3.9.17 3.9.18 3.9.19 3.9.2 3.9.20 3.9.21 3.9.22 3.9.23 3.9.24 All 73 releases
worker / src / MWP / Security / HashNonce.php

HashNonce.php in ManageWP Worker 4.9.25, at src/MWP/Security/HashNonce.php

64 lines 1.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /*
3 * This file is part of the ManageWP Worker plugin.
4 *
5 * (c) ManageWP LLC <contact@managewp.com>
6 *
7 * For the full copyright and license information, please view the LICENSE
8 * file that was distributed with this source code.
9 */
10
11 class MWP_Security_HashNonce implements MWP_Security_NonceInterface
12 {
13 /**
14 * How much is this nonce valid for use
15 */
16 const NONCE_LIFETIME = 43200;
17 /**
18 * Blacklist time of nonce. The minimum value is NONCE_LIFETIME +1
19 */
20 const NONCE_BLACKLIST_TIME = 86400;
21 /**
22 * @var string
23 */
24 protected $nonce;
25 /**
26 * @var int
27 */
28 protected $issueAt;
29
30 /**
31 * {@inherits}
32 */
33 public function setValue($value)
34 {
35 $parts = explode("_", $value);
36 if (count($parts) == 2) {
37 list($this->nonce, $this->issueAt) = $parts;
38 }
39 }
40
41 /**
42 * {@inherits}
43 */
44 public function verify()
45 {
46 if (empty($this->nonce) || (int) $this->issueAt == 0) {
47 return false;
48 }
49 if ($this->issueAt + self::NONCE_LIFETIME < time()) {
50 return false;
51 }
52 /** @handled function */
53 $nonceUsed = get_transient('n_'.$this->nonce);
54
55 if ($nonceUsed !== false) {
56 return false;
57 }
58 /** @handled function */
59 set_transient('n_'.$this->nonce, $this->issueAt, self::NONCE_BLACKLIST_TIME); //need shorter name, because of 64 char limit
60
61 return true;
62 }
63 }
64