<?php
/**
* Error Protection API: WP_Recovery_Mode_Key_Service class
*
* @package WordPress
* @since 5.2.0
*/
/**
* Core class used to generate and validate keys used to enter Recovery Mode.
*
* @since 5.2.0
*/
#[AllowDynamicProperties]
final class WP_Recovery_Mode_Key_Service {
/**
* The option name used to store the keys.
*
* @since 5.2.0
* @var string
*/
private $option_name = 'recovery_keys';
/**
* Creates a recovery mode token.
*
* @since 5.2.0
*
* @return string A random string to identify its associated key in storage.
*/
public function generate_recovery_mode_token() {
return wp_generate_password( 22, false );
}
/**
* Creates a recovery mode key.
*
* @since 5.2.0
*
* @global PasswordHash $wp_hasher Portable PHP password hashing framework instance.
*
* @param string $token A token generated by {@see generate_recovery_mode_token()}.
* @return string Recovery mode key.
*/
public function generate_and_store_recovery_mode_key( $token ) {
global $wp_hasher;
$key = wp_generate_password( 22, false );
if ( empty( $wp_hasher ) ) {
require_once ABSPATH . WPINC . '/class-phpass.php';
$wp_hasher = new PasswordHash( 8, true );
}
$hashed = $wp_hasher->HashPassword( $key );
$records = $this->get_keys();
$records[ $token ] = array(
'hashed_key' => $hashed,
'created_at' => time(),
);
$this->update_keys( $records );
/**
* Fires when a recovery mode key is generated.
*
* @since 5.2.0
*
* @param string $token The recovery data token.
* @param string $key The recovery mode key.
*/
do_action( 'generate_recovery_mode_key', $token, $key );
return $key;
}
/**
* Verifies if the recovery mode key is correct.
*
* Recovery mode keys can only be used once; the key will be consumed in the process.
*
* @since 5.2.0
*
* @global PasswordHash $wp_hasher Portable PHP password hashing framework instance.
*
* @param string $token The token used when generating the given key.
* @param string $key The unhashed key.
* @param int $ttl Time in seconds for the key to be valid for.
* @return true|WP_Error True on success, error object on failure.
*/
public function validate_recovery_mode_key( $token, $key, $ttl ) {
global $wp_hasher;
$records = $this->get_keys();
if ( ! isset( $records[ $token ] ) ) {
return new WP_Error( 'token_not_found', __( 'Recovery Mode not initialized.' ) );
}
$record = $records[ $token ];
$this->remove_key( $token );
if ( ! is_array( $record ) || ! isset( $record['hashed_key'], $record['created_at'] ) ) {
return new WP_Error( 'invalid_recovery_key_format', __( 'Invalid recovery key format.' ) );
}
if ( empty( $wp_hasher ) ) {
require_once ABSPATH . WPINC . '/class-phpass.php';
$wp_hasher = new PasswordHash( 8, true );
}
if ( ! $wp_hasher->CheckPassword( $key, $record['hashed_key'] ) ) {
return new WP_Error( 'hash_mismatch', __( 'Invalid recovery key.' ) );
}
if ( time() > $record['created_at'] + $ttl ) {
return new WP_Error( 'key_expired', __( 'Recovery key expired.' ) );
}
return true;
}
/**
* Removes expired recovery mode keys.
*
* @since 5.2.0
*
* @param int $ttl Time in seconds for the keys to be valid for.
*/
public function clean_expired_keys( $ttl ) {
$records = $this->get_keys();
foreach ( $records as $key => $record ) {
if ( ! isset( $record['created_at'] ) || time() > $record['created_at'] + $ttl ) {
unset( $records[ $key ] );
}
}
$this->update_keys( $records );
}
/**
* Removes a used recovery key.
*
* @since 5.2.0
*
* @param string $token The token used when generating a recovery mode key.
*/
private function remove_key( $token ) {
$records = $this->get_keys();
if ( ! isset( $records[ $token ] ) ) {
return;
}
unset( $records[ $token ] );
$this->update_keys( $records );
}
/**
* Gets the recovery key records.
*
* @since 5.2.0
*
* @return array Associative array of $token => $data pairs, where $data has keys 'hashed_key'
* and 'created_at'.
*/
private function get_keys() {
return (array) get_option( $this->option_name, array() );
}
/**
* Updates the recovery key records.
*
* @since 5.2.0
*
* @param array $keys Associative array of $token => $data pairs, where $data has keys 'hashed_key'
* and 'created_at'.
* @return bool True on success, false on failure.
*/
private function update_keys( array $keys ) {
return update_option( $this->option_name, $keys );
}
}
Directory Contents
Dirs: 28 × Files: 237
!"#$%&'(()*+,-./00123456789 t\
wIDATx ]ys 47Y ƒ - " Rv < f{Ɛ $k l L > L ~h^ 1 [ r G t&h
l F z3O Y ! p A(_g̷ E8 )S 8 c Kb"z ~ 5 J xAL WU < *
5 m;W a pB h ~P J
2 3 6 ҙ .Ƹ P i 4g
F R L P ΪK/D M v (a3
k J
Œ4N5* SH ` SdJ z O J Xՠ V>u ߱ BE&L b2 ?2` tX+ c CB A$ i b C ĀMB E : / # Dx &l =q Ty 0 \p I ( L Ǎ { e
4k ;`u^ヲ eP!( d { )T A 8 O;Ě n >;s6 ! :Nx `[S D HU ~ qJ F}
a g*D 49 / pn k h (t 8NxƐF _!r չ7
ZR R q/5") Ӎ NY 0 x sZ! o
fu , K"$ ? pg 㕣= 1» {h " fh7
y } +7 $ y
" X ą - G P u 4 m >J 5 L =V ' ^@I p ?MS xЌ XV P ! h "C NS9B8̢ ]!K e zA , ӏkbY !< XQ ٿyS| *" f { w 4@[S <
# 0 ! js [m =,~ o
"ݎ DHf Wo $ g ! Vԅ t mB /y Wf V4 c+@x? B ~u " xUN e 0 BĂ)
~J pz!
7y6]l Ԥ@ P a< O /DHC `≻ N m"$ 0ObB }{ x AO FCG DR ^ "B { WDH UR l@ T
# +"d T ; 0 i D}. 7 ` ' ] w rE &S i ƕiTD EL P _ u h $ Ա FG wVD G L R Zf ' .!] J /ZR oGЍs Mr Ĥ ʬ 3 Q [3 cL `^ p +
( F;# B 5 ' 2Y f [ ϶R0e } E 7
6M aۮ H <& n % L] E}Up x紉, Uw' Q Ǯշo k ވۙ 0N94 VX5 xEDE l D #֤ } C o )W : ^ s 9 bRf iX5u ཱི 4 :[ T 1. | [E 2ؽ Iy\ : o x K G 5
ylP ' uK E
ftb/i[3 .g _ [3M n
G, #NwQ5~
ؚ) | n =Ц"x qg gB ` 듘 ~ x w ?
?
R~ _ u. &VQ K˻ H C ( TN˄+ `C dA nB D 3"Z G ê ^k H_ /- ~ " R_ .8 Z_ 6@ o xg uP ? 3լ @7AM! E7^
- =V L x g-D0 CtmW 7 O G _ WD0 g C w1 r
d w : a | \ *" f nֳ ^ H# f L ` Z ۽hV }S F r0Ù Bć5r] @! NL iQ]{s^=4 d WD " " M;
t" 8 5 e dL| "-*st" ) SWD ?R[S e ooF 20.D ? bo =) A i o d ģ ZҰaO
@E =) i D a &ܟa CϞ y6 ,<%{^x%{f8? `iw^ ?/
M
* IEND B`