PluginProbe
WP Job Manager / trunk
WP Job Manager vtrunk
2.4.7 2.4.6 2.4.5 2.4.4 2.4.3 2.4.2 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.0.4 1.0.5 1.1.0 1.1.1 1.1.2 1.1.3 1.10.0 1.11.0 1.11.1 1.12.0 1.12.1 1.13.0 1.14.0 1.15.0 All 154 releases
wp-job-manager / includes / class-access-token.php
class-access-token.php
104 lines 2.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /**
3 * File containing the class Access_Token.
4 *
5 * @package wp-job-manager
6 */
7
8 namespace WP_Job_Manager;
9
10 if ( ! defined( 'ABSPATH' ) ) {
11 exit;
12 }
13
14 /**
15 * An access token which can be used to provide access to a resource.
16 */
17 class Access_Token {
18 /**
19 * Token's metadata. They are hashed together with the token.
20 *
21 * @var array
22 */
23 private array $metadata;
24
25 /**
26 * Constructor.
27 *
28 * @param array $metadata Metadata to be hashed together with the token.
29 */
30 public function __construct( array $metadata ) {
31 $this->metadata = $metadata;
32 ksort( $this->metadata );
33 }
34
35 /**
36 * Creates a new token.
37 *
38 * @param int $expiry The expiry timestamp of the token.
39 *
40 * @return string The token.
41 */
42 public function create( int $expiry = 0 ) : string {
43 $metadata_json = wp_json_encode( $this->metadata );
44
45 $hash = substr( wp_hash( $expiry . '|' . $metadata_json, 'nonce' ), -18, 16 );
46
47 return $this->encode( $expiry, $hash );
48 }
49
50 /**
51 * Verifies that a token is correct.
52 *
53 * @param string $token The token to verify.
54 *
55 * @return bool True if the token is correct.
56 */
57 public function verify( string $token ) : bool {
58 $decoded_token = $this->decode( $token );
59
60 if ( false === $decoded_token ) {
61 return false;
62 }
63
64 $expiry = $decoded_token[0];
65
66 if ( '' === $expiry || ( '0' !== $expiry && time() > $expiry ) ) {
67 return false;
68 }
69
70 return hash_equals( $token, $this->create( (int) $expiry ) );
71 }
72
73 /**
74 * Encodes the hash and expiry into a URL-friendly format.
75 *
76 * @param int $expiry The expiry timestamp.
77 * @param string $hash The hash of the metadata.
78 *
79 * @return string
80 */
81 private function encode( int $expiry, string $hash ): string {
82 // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_encode -- It encodes known values.
83 return rtrim( strtr( base64_encode( $expiry . ':' . $hash ), '+/', '-_' ), '=' );
84 }
85
86 /**
87 * Decodes a token into the expiry and hash parts.
88 *
89 * @param string $token The token to decode.
90 *
91 * @return false|array A two element array with the expiry and the hash or false on failure.
92 */
93 private function decode( string $token ) {
94 // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode -- Output used for comparisons only.
95 $decoded_str = base64_decode( str_pad( strtr( $token, '-_', '+/' ), strlen( $token ) % 4, '=', STR_PAD_RIGHT ) );
96
97 if ( false === $decoded_str || 1 !== substr_count( $decoded_str, ':' ) ) {
98 return false;
99 }
100
101 return explode( ':', $decoded_str );
102 }
103 }
104