Installer
5 years ago
AdminNotices.php
4 years ago
AjaxHandler.php
4 years ago
Autologin.php
4 years ago
BuddyPressBbPress.php
5 years ago
EditUserProfile.php
4 years ago
ExtensionManager.php
5 years ago
FileUploader.php
4 years ago
FormPreviewHandler.php
5 years ago
FormRepository.php
4 years ago
FormShortcodeDefaults.php
5 years ago
GDPR.php
5 years ago
GlobalSiteAccess.php
4 years ago
ImageUploader.php
4 years ago
LoginAuth.php
4 years ago
Miscellaneous.php
5 years ago
ModifyRedirectDefaultLinks.php
5 years ago
PPRESS_Session.php
4 years ago
PROFILEPRESS_sql.php
5 years ago
PasswordReset.php
5 years ago
ProfileUrlRewrite.php
4 years ago
RegistrationAuth.php
4 years ago
SendEmail.php
5 years ago
ShortcodeThemeFactory.php
5 years ago
UserAvatar.php
4 years ago
UserSignupLocationListingPage.php
5 years ago
UsernameEmailRestrictLogin.php
5 years ago
WelcomeEmailAfterSignup.php
5 years ago
default-email-template.php
5 years ago
index.php
5 years ago
PPRESS_Session.php
212 lines
| 1 | <?php |
| 2 | |
| 3 | namespace ProfilePress\Core\Classes; |
| 4 | |
| 5 | use WP_Session; |
| 6 | |
| 7 | /** |
| 8 | * This is a wrapper class for WP_Session / PHP $_SESSION |
| 9 | * |
| 10 | * @copyright Copyright (c) 2015, Pippin Williamson |
| 11 | * @license http://opensource.org/licenses/gpl-2.0.php GNU Public License |
| 12 | */ |
| 13 | class PPRESS_Session |
| 14 | { |
| 15 | /** |
| 16 | * Holds our session data |
| 17 | * |
| 18 | * @var array |
| 19 | * |
| 20 | */ |
| 21 | private $session; |
| 22 | |
| 23 | /** |
| 24 | * Get things started |
| 25 | * |
| 26 | * Defines our WP_Session constants, includes the necessary libraries and |
| 27 | * retrieves the WP Session instance |
| 28 | */ |
| 29 | public function __construct() |
| 30 | { |
| 31 | if ( ! $this->should_start_session()) { |
| 32 | return; |
| 33 | } |
| 34 | |
| 35 | // Use WP_Session (default) |
| 36 | |
| 37 | if ( ! defined('WP_SESSION_COOKIE')) { |
| 38 | define('WP_SESSION_COOKIE', 'ppwp_wp_session'); |
| 39 | } |
| 40 | |
| 41 | if ( ! class_exists('Recursive_ArrayAccess')) { |
| 42 | require_once PROFILEPRESS_SRC . 'lib/wp_session/class-recursive-arrayaccess.php'; |
| 43 | } |
| 44 | |
| 45 | if ( ! class_exists('WP_Session')) { |
| 46 | require_once PROFILEPRESS_SRC . 'lib/wp_session/class-wp-session.php'; |
| 47 | require_once PROFILEPRESS_SRC . 'lib/wp_session/wp-session.php'; |
| 48 | } |
| 49 | |
| 50 | $hook = (empty($this->session)) ? 'plugins_loaded' : 'init'; |
| 51 | |
| 52 | add_action($hook, [$this, 'init'], -1); |
| 53 | } |
| 54 | |
| 55 | /** |
| 56 | * Setup the WP_Session instance |
| 57 | * |
| 58 | * @return mixed |
| 59 | */ |
| 60 | public function init() |
| 61 | { |
| 62 | $this->session = WP_Session::get_instance(); |
| 63 | |
| 64 | return $this->session; |
| 65 | } |
| 66 | |
| 67 | /** |
| 68 | * Retrieve a session variable |
| 69 | * |
| 70 | * @param string $key Session key |
| 71 | * |
| 72 | * @return mixed Session variable |
| 73 | */ |
| 74 | public function get($key) |
| 75 | { |
| 76 | $key = sanitize_key($key); |
| 77 | $return = false; |
| 78 | |
| 79 | if (isset($this->session[$key]) && ! empty($this->session[$key])) { |
| 80 | |
| 81 | preg_match('/[oO]\s*:\s*\d+\s*:\s*"\s*(?!(?i)(stdClass))/', $this->session[$key], $matches); |
| 82 | if ( ! empty($matches)) { |
| 83 | $this->set($key, null); |
| 84 | |
| 85 | return false; |
| 86 | } |
| 87 | |
| 88 | if (is_numeric($this->session[$key])) { |
| 89 | $return = $this->session[$key]; |
| 90 | } else { |
| 91 | |
| 92 | $maybe_json = json_decode($this->session[$key]); |
| 93 | |
| 94 | // Since json_last_error is PHP 5.3+, we have to rely on a `null` value for failing to parse JSON. |
| 95 | if (is_null($maybe_json)) { |
| 96 | $is_serialized = is_serialized($this->session[$key]); |
| 97 | if ($is_serialized) { |
| 98 | $value = @unserialize($this->session[$key]); |
| 99 | $this->set($key, (array)$value); |
| 100 | $return = $value; |
| 101 | } else { |
| 102 | $return = $this->session[$key]; |
| 103 | } |
| 104 | } else { |
| 105 | $return = json_decode($this->session[$key], true); |
| 106 | } |
| 107 | } |
| 108 | } |
| 109 | |
| 110 | return $return; |
| 111 | } |
| 112 | |
| 113 | /** |
| 114 | * Set a session variable |
| 115 | * |
| 116 | * @param string $key Session key |
| 117 | * @param int|string|array $value Session variable |
| 118 | * |
| 119 | * @return mixed Session variable |
| 120 | */ |
| 121 | public function set($key, $value) |
| 122 | { |
| 123 | $key = sanitize_key($key); |
| 124 | |
| 125 | if (is_array($value)) { |
| 126 | $this->session[$key] = wp_json_encode($value); |
| 127 | } else { |
| 128 | $this->session[$key] = esc_attr($value); |
| 129 | } |
| 130 | |
| 131 | return $this->session[$key]; |
| 132 | } |
| 133 | |
| 134 | /** |
| 135 | * Determines if we should start sessions |
| 136 | * |
| 137 | * @return bool |
| 138 | */ |
| 139 | public function should_start_session() |
| 140 | { |
| 141 | $start_session = true; |
| 142 | |
| 143 | if ( ! empty($_SERVER['REQUEST_URI'])) { |
| 144 | |
| 145 | $blacklist = $this->get_blacklist(); |
| 146 | $uri = ltrim($_SERVER['REQUEST_URI'], '/'); |
| 147 | $uri = untrailingslashit($uri); |
| 148 | |
| 149 | if (in_array($uri, $blacklist)) { |
| 150 | $start_session = false; |
| 151 | } |
| 152 | |
| 153 | if (false !== strpos($uri, 'feed=')) { |
| 154 | $start_session = false; |
| 155 | } |
| 156 | |
| 157 | if (is_admin() && false === strpos($uri, 'wp-admin/admin-ajax.php')) { |
| 158 | // We do not want to start sessions in the admin unless we're processing an ajax request |
| 159 | $start_session = false; |
| 160 | } |
| 161 | |
| 162 | if (false !== strpos($uri, 'wp_scrape_key')) { |
| 163 | // Starting sessions while saving the file editor can break the save process, so don't start |
| 164 | $start_session = false; |
| 165 | } |
| 166 | } |
| 167 | |
| 168 | return apply_filters('ppress_should_start_session', $start_session); |
| 169 | } |
| 170 | |
| 171 | /** |
| 172 | * Retrieve the URI blacklist |
| 173 | * |
| 174 | * These are the URIs where we never start sessions |
| 175 | * |
| 176 | * @return array |
| 177 | */ |
| 178 | public function get_blacklist() |
| 179 | { |
| 180 | $blacklist = array( |
| 181 | 'feed', |
| 182 | 'feed/rss', |
| 183 | 'feed/rss2', |
| 184 | 'feed/rdf', |
| 185 | 'feed/atom', |
| 186 | 'comments/feed' |
| 187 | ); |
| 188 | |
| 189 | // Look to see if WordPress is in a sub folder or this is a network site that uses sub folders |
| 190 | $folder = str_replace(network_home_url(), '', get_site_url()); |
| 191 | |
| 192 | if ( ! empty($folder)) { |
| 193 | foreach ($blacklist as $path) { |
| 194 | $blacklist[] = $folder . '/' . $path; |
| 195 | } |
| 196 | } |
| 197 | |
| 198 | return $blacklist; |
| 199 | } |
| 200 | |
| 201 | public static function get_instance() |
| 202 | { |
| 203 | static $instance = null; |
| 204 | |
| 205 | if (is_null($instance)) { |
| 206 | $instance = new self(); |
| 207 | } |
| 208 | |
| 209 | return $instance; |
| 210 | } |
| 211 | } |
| 212 |