PluginProbe
ManageWP Worker / 4.9.29
ManageWP Worker v4.9.29
4.9.38 4.9.37 4.9.36 4.9.35 4.9.34 3.8.7 3.8.8 3.9.0 3.9.1 3.9.10 3.9.11 3.9.12 3.9.13 3.9.14 3.9.15 3.9.16 3.9.17 3.9.18 3.9.19 3.9.2 3.9.20 3.9.21 3.9.22 3.9.23 3.9.24 All 73 releases
worker / src / MWP / Security / NonceManager.php

NonceManager.php in ManageWP Worker 4.9.29, at src/MWP/Security/NonceManager.php

73 lines 2.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /*
3 * This file is part of the ManageWP Worker plugin.
4 *
5 * (c) ManageWP LLC <contact@managewp.com>
6 *
7 * For the full copyright and license information, please view the LICENSE
8 * file that was distributed with this source code.
9 */
10
11 class MWP_Security_NonceManager
12 {
13
14 private $context;
15
16 private $nonceValidFor;
17
18 private $nonceBlacklistedFor;
19
20 /**
21 * @param MWP_WordPress_Context $context
22 * @param int $nonceValidFor How long (in seconds) is the nonce valid since its issue time.
23 * @param int $nonceBlacklistedFor How long (in seconds) to keep used nonce in storage.
24 */
25 public function __construct(MWP_WordPress_Context $context, $nonceValidFor = 43200, $nonceBlacklistedFor = 86400)
26 {
27 if ($nonceBlacklistedFor < $nonceValidFor) {
28 throw new LogicException('Nonce blacklist time must be higher than nonce lifetime.');
29 }
30
31 $this->context = $context;
32 $this->nonceValidFor = $nonceValidFor;
33 $this->nonceBlacklistedFor = $nonceBlacklistedFor;
34 }
35
36 /**
37 * @param string $nonce
38 *
39 * @throws MWP_Security_Exception_NonceFormatInvalid
40 * @throws MWP_Security_Exception_NonceExpired
41 * @throws MWP_Security_Exception_NonceAlreadyUsed
42 */
43 public function useNonce($nonce)
44 {
45 $parts = explode('_', $nonce);
46
47 if (count($parts) !== 2) {
48 throw new MWP_Security_Exception_NonceFormatInvalid();
49 }
50
51 list($nonceValue, $issuedAt) = $parts;
52 $issuedAt = (int) $issuedAt;
53
54 if (!$nonceValue || !$issuedAt) {
55 throw new MWP_Security_Exception_NonceFormatInvalid();
56 }
57
58 if ($issuedAt + $this->nonceValidFor < time()) {
59 throw new MWP_Security_Exception_NonceExpired();
60 }
61
62 // There was a bug where the generated nonce was 42 characters long.
63 $transientKey = substr('n_'.$nonceValue, 0, 40);
64 $nonceUsed = $this->context->transientGet($transientKey);
65
66 if ($nonceUsed !== false) {
67 throw new MWP_Security_Exception_NonceAlreadyUsed();
68 }
69
70 $this->context->transientSet($transientKey, $issuedAt, $this->nonceBlacklistedFor);
71 }
72 }
73