PluginProbe ʕ •ᴥ•ʔ
WP Job Manager / 2.4.6
WP Job Manager v2.4.6
2.4.6 2.4.5 2.4.4 2.4.3 2.4.2 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.1.0 1.1.1 1.1.2 1.1.3 1.10.0 1.11.0 1.11.1 1.12.0 1.12.1 1.13.0 1.14.0 1.15.0 1.16.0 1.16.1 1.17.0 1.18.0 1.19.0 1.2.0 1.20.0 1.20.1 1.21.0 1.21.1 1.21.2 1.21.3 1.21.4 1.22.0 1.22.1 1.22.2 1.22.3 1.23.0 1.23.1 1.23.10 1.23.11 1.23.12 1.23.13 1.23.2 1.23.3 1.23.4 1.23.5 1.23.6 1.23.7 1.23.8 1.23.9 1.24.0 1.24.0.1 1.25.0 1.25.0.1 1.25.1 1.25.1.1 1.25.2 1.25.2.1 1.25.3 1.25.3.1 1.26.0 1.26.0.1 1.26.1 1.26.1.1 1.26.2 1.26.2.1 1.27.0 1.27.0.1 1.28.0 1.28.0.1 1.29.0 1.29.0.1 1.29.1 1.29.1.1 1.29.2 1.29.2.1 1.29.3 1.29.3.1 1.3.0 1.3.1 1.30.0 1.30.0.1 1.30.1 1.30.1.1 1.30.2 1.30.2.1 1.31.0 1.31.0.1 1.31.1 1.31.1.1 1.31.2 1.31.3 1.32.0 1.32.1 1.32.2 1.32.3 1.33.0 1.33.1 1.33.2 1.33.3 1.33.4 1.33.5 1.34.0 1.34.1 1.34.2 1.34.3 1.34.4 1.34.5 1.35.0 1.35.1 1.35.2 1.35.3 1.36.0 1.36.1 1.36.2 1.37.0 1.38.0 1.38.1 1.39.0 1.4.0 1.40.0 1.40.1 1.40.2 1.41.0 1.42.0 1.5.0 1.5.1 1.5.2 1.6.0 1.7.0 1.7.1 1.7.3 1.8.0 1.8.1 1.8.2 1.9.0 1.9.1 1.9.2 1.9.3 2.0.0 2.1.0 2.1.1 2.2.0 2.2.1 2.2.2 2.3.0 2.4.0 2.4.1
wp-job-manager / includes / class-access-token.php
wp-job-manager / includes Last commit date
3rd-party 2 months ago abstracts 3 months ago admin 2 weeks ago emails 2 weeks ago forms 2 weeks ago helper 3 months ago promoted-jobs 2 weeks ago ui 2 weeks ago widgets 2 weeks ago class-access-token.php 2 years ago class-dev-tools.php 2 years ago class-guest-session.php 2 years ago class-guest-user.php 2 years ago class-job-dashboard-shortcode.php 6 months ago class-job-listing-stats.php 2 years ago class-job-overlay.php 2 years ago class-stats-dashboard.php 2 years ago class-stats-script.php 3 months ago class-stats.php 3 months ago class-wp-job-manager-ajax.php 2 months ago class-wp-job-manager-api.php 6 years ago class-wp-job-manager-blocks.php 2 weeks ago class-wp-job-manager-cache-helper.php 3 months ago class-wp-job-manager-category-walker.php 6 years ago class-wp-job-manager-com-api.php 2 years ago class-wp-job-manager-data-cleaner.php 2 years ago class-wp-job-manager-data-exporter.php 3 months ago class-wp-job-manager-dependency-checker.php 2 years ago class-wp-job-manager-email-notifications.php 2 years ago class-wp-job-manager-forms.php 5 years ago class-wp-job-manager-geocode.php 2 weeks ago class-wp-job-manager-install.php 2 years ago class-wp-job-manager-post-types.php 2 weeks ago class-wp-job-manager-recaptcha.php 6 months ago class-wp-job-manager-rest-api.php 2 months ago class-wp-job-manager-shortcodes.php 2 weeks ago class-wp-job-manager-usage-tracking-data.php 2 years ago class-wp-job-manager-usage-tracking.php 2 years ago class-wp-job-manager-widget.php 2 weeks ago class-wp-job-manager.php 3 months ago trait-singleton.php 2 years ago
class-access-token.php
104 lines
1 <?php
2 /**
3 * File containing the class Access_Token.
4 *
5 * @package wp-job-manager
6 */
7
8 namespace WP_Job_Manager;
9
10 if ( ! defined( 'ABSPATH' ) ) {
11 exit;
12 }
13
14 /**
15 * An access token which can be used to provide access to a resource.
16 */
17 class Access_Token {
18 /**
19 * Token's metadata. They are hashed together with the token.
20 *
21 * @var array
22 */
23 private array $metadata;
24
25 /**
26 * Constructor.
27 *
28 * @param array $metadata Metadata to be hashed together with the token.
29 */
30 public function __construct( array $metadata ) {
31 $this->metadata = $metadata;
32 ksort( $this->metadata );
33 }
34
35 /**
36 * Creates a new token.
37 *
38 * @param int $expiry The expiry timestamp of the token.
39 *
40 * @return string The token.
41 */
42 public function create( int $expiry = 0 ) : string {
43 $metadata_json = wp_json_encode( $this->metadata );
44
45 $hash = substr( wp_hash( $expiry . '|' . $metadata_json, 'nonce' ), -18, 16 );
46
47 return $this->encode( $expiry, $hash );
48 }
49
50 /**
51 * Verifies that a token is correct.
52 *
53 * @param string $token The token to verify.
54 *
55 * @return bool True if the token is correct.
56 */
57 public function verify( string $token ) : bool {
58 $decoded_token = $this->decode( $token );
59
60 if ( false === $decoded_token ) {
61 return false;
62 }
63
64 $expiry = $decoded_token[0];
65
66 if ( '' === $expiry || ( '0' !== $expiry && time() > $expiry ) ) {
67 return false;
68 }
69
70 return hash_equals( $token, $this->create( (int) $expiry ) );
71 }
72
73 /**
74 * Encodes the hash and expiry into a URL-friendly format.
75 *
76 * @param int $expiry The expiry timestamp.
77 * @param string $hash The hash of the metadata.
78 *
79 * @return string
80 */
81 private function encode( int $expiry, string $hash ): string {
82 // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- It encodes known values.
83 return rtrim( strtr( base64_encode( $expiry . ':' . $hash ), '+/', '-_' ), '=' );
84 }
85
86 /**
87 * Decodes a token into the expiry and hash parts.
88 *
89 * @param string $token The token to decode.
90 *
91 * @return false|array A two element array with the expiry and the hash or false on failure.
92 */
93 private function decode( string $token ) {
94 // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode -- Output used for comparisons only.
95 $decoded_str = base64_decode( str_pad( strtr( $token, '-_', '+/' ), strlen( $token ) % 4, '=', STR_PAD_RIGHT ) );
96
97 if ( false === $decoded_str || 1 !== substr_count( $decoded_str, ':' ) ) {
98 return false;
99 }
100
101 return explode( ':', $decoded_str );
102 }
103 }
104