PluginProbe
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance / 3.2.3
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance v3.2.3
4.7.0 4.6.1 4.6.0 4.5.5 4.5.4 4.5.3 4.5.2 3.2.20 3.2.21 3.2.22 3.2.3 3.2.5 3.2.6 3.2.7 3.2.9 3.3.0 3.3.1 3.3.2 3.4.0 3.4.1 3.4.2 3.5.0 3.6.0 3.7.0 3.7.1 All 111 releases
wp-optimize / vendor / rosell-dk / webp-convert-cloud-service / src / AccessCheck.php

AccessCheck.php in WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance 3.2.3, at vendor/rosell-dk/webp-convert-cloud-service/src/AccessCheck.php

100 lines 3.6 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace WebPConvertCloudService;
4
5 use \WebPConvertCloudService\WebPConvertCloudService;
6
7 class AccessCheck
8 {
9
10 private static function accessDenied($msg)
11 {
12 WebPConvertCloudService::exitWithError(WebPConvertCloudService::ERROR_ACCESS_DENIED, $msg);
13 }
14
15 /**
16 * Test an IP (ie "212.67.80.1") against a pattern (ie "212.*")
17 */
18 private static function testIpPattern($ip, $pattern)
19 {
20 $regEx = '/^' . str_replace('*', '.*', $pattern) . '$/';
21
22 if (preg_match($regEx, $ip)) {
23 return true;
24 }
25 return false;
26 }
27
28 public static function runAccessChecks($options)
29 {
30 $accessOptions = $options['access'];
31
32 $onWhitelist = false;
33 if (isset($accessOptions['whitelist']) && count($accessOptions['whitelist']) > 0) {
34 foreach ($accessOptions['whitelist'] as $whitelistItem) {
35 if (isset($whitelistItem['ip'])) {
36 if (!self::testIpPattern($_SERVER['REMOTE_ADDR'], $whitelistItem['ip'])) {
37 continue;
38 }
39 }
40 $onWhitelist = true;
41
42 if (!isset($whitelistItem['api-key']) || $whitelistItem['api-key'] == '') {
43 // This item requires no api key
44 // Access granted!
45 return;
46 }
47
48 if (isset($_POST['salt']) && isset($_POST['api-key-crypted'])) {
49 if (CRYPT_BLOWFISH == 1) {
50 // Strip off the first 28 characters (the first 6 are always "$2y$10$". The next 22 is the salt)
51 $cryptedKey = substr(crypt($whitelistItem['api-key'], '$2y$10$' . $_POST['salt'] . '$'), 28);
52 if ($_POST['api-key-crypted'] == $cryptedKey) {
53 // Access granted!
54 return;
55 }
56 } else {
57 // trouble...
58 }
59 } else {
60 $hashingRequired = (
61 isset($whitelistItem['require-api-key-to-be-crypted-in-transfer']) &&
62 $whitelistItem['require-api-key-to-be-crypted-in-transfer']
63 );
64 if (!$hashingRequired && isset($_POST['api-key'])) {
65 if ($_POST['api-key'] == $whitelistItem['api-key']) {
66 // Access granted!
67 return;
68 }
69 }
70 }
71 }
72 }
73
74
75 if ($onWhitelist) {
76 if (isset($_POST['salt']) && isset($_POST['api-key-crypted'])) {
77 self::accessDenied('Invalid api key');
78 } else {
79 if (isset($_POST['api-key'])) {
80 self::accessDenied('Either api key is invalid, or you must crypt the api key');
81 } else {
82 if (isset($_POST['salt']) && isset($_POST['api-key-crypted'])) {
83 self::accessDenied('You need to supply a valid api key');
84 } else {
85 if (!isset($_POST['api-key-crypted'])) {
86 self::accessDenied('You need to supply an api key');
87 } else {
88 if (!isset($_POST['salt'])) {
89 self::accessDenied('You must supply salt to go with you encripted api key');
90 }
91 }
92 }
93 }
94 }
95 } else {
96 self::accessDenied('Access denied');
97 }
98 }
99 }
100