Installer
5 years ago
AdminNotices.php
4 years ago
AjaxHandler.php
4 years ago
Autologin.php
4 years ago
BuddyPressBbPress.php
5 years ago
EditUserProfile.php
4 years ago
ExtensionManager.php
4 years ago
FileUploader.php
4 years ago
FormPreviewHandler.php
5 years ago
FormRepository.php
4 years ago
FormShortcodeDefaults.php
5 years ago
GDPR.php
4 years ago
Geolocation.php
4 years ago
GlobalSiteAccess.php
4 years ago
ImageUploader.php
4 years ago
LoginAuth.php
4 years ago
Miscellaneous.php
4 years ago
ModifyRedirectDefaultLinks.php
4 years ago
PPRESS_Session.php
4 years ago
PROFILEPRESS_sql.php
4 years ago
PasswordReset.php
4 years ago
ProfileUrlRewrite.php
4 years ago
RegistrationAuth.php
4 years ago
SendEmail.php
4 years ago
ShortcodeThemeFactory.php
5 years ago
UserAvatar.php
4 years ago
UserSignupLocationListingPage.php
4 years ago
UsernameEmailRestrictLogin.php
4 years ago
WPProfileFieldParserTrait.php
4 years ago
WelcomeEmailAfterSignup.php
4 years ago
default-email-template.php
4 years ago
index.php
5 years ago
PPRESS_Session.php
219 lines
| 1 | <?php |
| 2 | |
| 3 | namespace ProfilePress\Core\Classes; |
| 4 | |
| 5 | use WP_PPress_Session; |
| 6 | |
| 7 | /** |
| 8 | * This is a wrapper class for WP_PPress_Session / PHP $_SESSION |
| 9 | * |
| 10 | * @copyright Copyright (c) 2015, Pippin Williamson |
| 11 | * @license http://opensource.org/licenses/gpl-2.0.php GNU Public License |
| 12 | */ |
| 13 | class PPRESS_Session |
| 14 | { |
| 15 | /** |
| 16 | * Holds our session data |
| 17 | * |
| 18 | * @var array |
| 19 | * |
| 20 | */ |
| 21 | private $session; |
| 22 | |
| 23 | /** |
| 24 | * Get things started |
| 25 | * |
| 26 | * Defines our WP_PPress_Session constants, includes the necessary libraries and |
| 27 | * retrieves the WP Session instance |
| 28 | */ |
| 29 | public function __construct() |
| 30 | { |
| 31 | if ( ! $this->should_start_session()) { |
| 32 | return; |
| 33 | } |
| 34 | |
| 35 | if ( ! defined('WP_PPRESS_SESSION_COOKIE')) { |
| 36 | define('WP_PPRESS_SESSION_COOKIE', 'ppwp_wp_session'); |
| 37 | } |
| 38 | |
| 39 | if ( ! class_exists('PPRESS_Recursive_ArrayAccess')) { |
| 40 | require_once PROFILEPRESS_SRC . 'lib/wp_session/class-recursive-arrayaccess.php'; |
| 41 | } |
| 42 | |
| 43 | // Include utilities class |
| 44 | if ( ! class_exists('WP_PPress_Session_Utils')) { |
| 45 | require_once PROFILEPRESS_SRC . 'lib/wp_session/class-wp-session-utils.php'; |
| 46 | } |
| 47 | |
| 48 | if ( ! class_exists('WP_PPress_Session')) { |
| 49 | require_once PROFILEPRESS_SRC . 'lib/wp_session/class-wp-session.php'; |
| 50 | require_once PROFILEPRESS_SRC . 'lib/wp_session/wp-session.php'; |
| 51 | } |
| 52 | |
| 53 | $hook = (empty($this->session)) ? 'plugins_loaded' : 'init'; |
| 54 | |
| 55 | add_action($hook, [$this, 'init'], -1); |
| 56 | } |
| 57 | |
| 58 | /** |
| 59 | * Setup the WP_PPress_Session instance |
| 60 | * |
| 61 | * @return mixed |
| 62 | */ |
| 63 | public function init() |
| 64 | { |
| 65 | $this->session = WP_PPress_Session::get_instance(); |
| 66 | |
| 67 | return $this->session; |
| 68 | } |
| 69 | |
| 70 | /** |
| 71 | * Retrieve a session variable |
| 72 | * |
| 73 | * @param string $key Session key |
| 74 | * |
| 75 | * @return mixed Session variable |
| 76 | */ |
| 77 | public function get($key) |
| 78 | { |
| 79 | $key = sanitize_key($key); |
| 80 | $return = false; |
| 81 | |
| 82 | if (isset($this->session[$key]) && ! empty($this->session[$key])) { |
| 83 | |
| 84 | preg_match('/[oO]\s*:\s*\d+\s*:\s*"\s*(?!(?i)(stdClass))/', $this->session[$key], $matches); |
| 85 | if ( ! empty($matches)) { |
| 86 | $this->set($key, null); |
| 87 | |
| 88 | return false; |
| 89 | } |
| 90 | |
| 91 | if (is_numeric($this->session[$key])) { |
| 92 | $return = $this->session[$key]; |
| 93 | } else { |
| 94 | |
| 95 | $maybe_json = json_decode($this->session[$key]); |
| 96 | |
| 97 | // Since json_last_error is PHP 5.3+, we have to rely on a `null` value for failing to parse JSON. |
| 98 | if (is_null($maybe_json)) { |
| 99 | $is_serialized = is_serialized($this->session[$key]); |
| 100 | if ($is_serialized) { |
| 101 | $value = @unserialize($this->session[$key]); |
| 102 | $this->set($key, (array)$value); |
| 103 | $return = $value; |
| 104 | } else { |
| 105 | $return = $this->session[$key]; |
| 106 | } |
| 107 | } else { |
| 108 | $return = json_decode($this->session[$key], true); |
| 109 | } |
| 110 | } |
| 111 | } |
| 112 | |
| 113 | return $return; |
| 114 | } |
| 115 | |
| 116 | /** |
| 117 | * Set a session variable |
| 118 | * |
| 119 | * @param string $key Session key |
| 120 | * @param int|string|array $value Session variable |
| 121 | * |
| 122 | * @return mixed Session variable |
| 123 | */ |
| 124 | public function set($key, $value) |
| 125 | { |
| 126 | $key = sanitize_key($key); |
| 127 | |
| 128 | if (is_array($value)) { |
| 129 | $this->session[$key] = wp_json_encode($value); |
| 130 | } else { |
| 131 | $this->session[$key] = esc_attr($value); |
| 132 | } |
| 133 | |
| 134 | return $this->session[$key]; |
| 135 | } |
| 136 | |
| 137 | /** |
| 138 | * Determines if we should start sessions |
| 139 | * |
| 140 | * @return bool |
| 141 | */ |
| 142 | public function should_start_session() |
| 143 | { |
| 144 | $start_session = true; |
| 145 | |
| 146 | if ( ! empty($_SERVER['REQUEST_URI'])) { |
| 147 | |
| 148 | $blacklist = $this->get_blacklist(); |
| 149 | $uri = ltrim($_SERVER['REQUEST_URI'], '/'); |
| 150 | $uri = untrailingslashit($uri); |
| 151 | |
| 152 | if (in_array($uri, $blacklist)) { |
| 153 | $start_session = false; |
| 154 | } |
| 155 | |
| 156 | if (false !== strpos($uri, 'feed=')) { |
| 157 | $start_session = false; |
| 158 | } |
| 159 | |
| 160 | if (is_admin() && false === strpos($uri, 'wp-admin/admin-ajax.php')) { |
| 161 | // We do not want to start sessions in the admin unless we're processing an ajax request |
| 162 | $start_session = false; |
| 163 | } |
| 164 | |
| 165 | if (false !== strpos($uri, 'wp_scrape_key')) { |
| 166 | // Starting sessions while saving the file editor can break the save process, so don't start |
| 167 | $start_session = false; |
| 168 | } |
| 169 | } |
| 170 | |
| 171 | if (defined('DOING_CRON') && DOING_CRON) { |
| 172 | $start_session = false; |
| 173 | } |
| 174 | |
| 175 | return apply_filters('ppress_should_start_session', $start_session); |
| 176 | } |
| 177 | |
| 178 | /** |
| 179 | * Retrieve the URI blacklist |
| 180 | * |
| 181 | * These are the URIs where we never start sessions |
| 182 | * |
| 183 | * @return array |
| 184 | */ |
| 185 | public function get_blacklist() |
| 186 | { |
| 187 | $blacklist = array( |
| 188 | 'feed', |
| 189 | 'feed/rss', |
| 190 | 'feed/rss2', |
| 191 | 'feed/rdf', |
| 192 | 'feed/atom', |
| 193 | 'comments/feed' |
| 194 | ); |
| 195 | |
| 196 | // Look to see if WordPress is in a sub folder or this is a network site that uses sub folders |
| 197 | $folder = str_replace(network_home_url(), '', get_site_url()); |
| 198 | |
| 199 | if ( ! empty($folder)) { |
| 200 | foreach ($blacklist as $path) { |
| 201 | $blacklist[] = $folder . '/' . $path; |
| 202 | } |
| 203 | } |
| 204 | |
| 205 | return $blacklist; |
| 206 | } |
| 207 | |
| 208 | public static function get_instance() |
| 209 | { |
| 210 | static $instance = null; |
| 211 | |
| 212 | if (is_null($instance)) { |
| 213 | $instance = new self(); |
| 214 | } |
| 215 | |
| 216 | return $instance; |
| 217 | } |
| 218 | } |
| 219 |