FM

/home/u523506497/domains/mymelon.in/public_html/wp-includes UP

<?php
/**
 * WP_Application_Passwords class
 *
 * @package WordPress
 * @since   5.6.0
 */

/**
 * Class for displaying, modifying, and sanitizing application passwords.
 *
 * @package WordPress
 */
#[AllowDynamicProperties]
class WP_Application_Passwords {

	/**
	 * The application passwords user meta key.
	 *
	 * @since 5.6.0
	 *
	 * @var string
	 */
	const USERMETA_KEY_APPLICATION_PASSWORDS = '_application_passwords';

	/**
	 * The option name used to store whether application passwords are in use.
	 *
	 * @since 5.6.0
	 *
	 * @var string
	 */
	const OPTION_KEY_IN_USE = 'using_application_passwords';

	/**
	 * The generated application password length.
	 *
	 * @since 5.6.0
	 *
	 * @var int
	 */
	const PW_LENGTH = 24;

	/**
	 * Checks if application passwords are being used by the site.
	 *
	 * This returns true if at least one application password has ever been created.
	 *
	 * @since 5.6.0
	 *
	 * @return bool
	 */
	public static function is_in_use() {
		$network_id = get_main_network_id();
		return (bool) get_network_option( $network_id, self::OPTION_KEY_IN_USE );
	}

	/**
	 * Creates a new application password.
	 *
	 * @since 5.6.0
	 * @since 5.7.0 Returns WP_Error if application name already exists.
	 * @since 6.8.0 The hashed password value now uses wp_fast_hash() instead of phpass.
	 *
	 * @param int   $user_id  User ID.
	 * @param array $args     {
	 *     Arguments used to create the application password.
	 *
	 *     @type string $name   The name of the application password.
	 *     @type string $app_id A UUID provided by the application to uniquely identify it.
	 * }
	 * @return array|WP_Error {
	 *     Application password details, or a WP_Error instance if an error occurs.
	 *
	 *     @type string $0 The generated application password in plain text.
	 *     @type array  $1 {
	 *         The details about the created password.
	 *
	 *         @type string $uuid      The unique identifier for the application password.
	 *         @type string $app_id    A UUID provided by the application to uniquely identify it.
	 *         @type string $name      The name of the application password.
	 *         @type string $password  A one-way hash of the password.
	 *         @type int    $created   Unix timestamp of when the password was created.
	 *         @type null   $last_used Null.
	 *         @type null   $last_ip   Null.
	 *     }
	 * }
	 */
	public static function create_new_application_password( $user_id, $args = array() ) {
		if ( ! empty( $args['name'] ) ) {
			$args['name'] = sanitize_text_field( $args['name'] );
		}

		if ( empty( $args['name'] ) ) {
			return new WP_Error( 'application_password_empty_name', __( 'An application name is required to create an application password.' ), array( 'status' => 400 ) );
		}

		$new_password    = wp_generate_password( static::PW_LENGTH, false );
		$hashed_password = self::hash_password( $new_password );

		$new_item = array(
			'uuid'      => wp_generate_uuid4(),
			'app_id'    => empty( $args['app_id'] ) ? '' : $args['app_id'],
			'name'      => $args['name'],
			'password'  => $hashed_password,
			'created'   => time(),
			'last_used' => null,
			'last_ip'   => null,
		);

		$passwords   = static::get_user_application_passwords( $user_id );
		$passwords[] = $new_item;
		$saved       = static::set_user_application_passwords( $user_id, $passwords );

		if ( ! $saved ) {
			return new WP_Error( 'db_error', __( 'Could not save application password.' ) );
		}

		$network_id = get_main_network_id();
		if ( ! get_network_option( $network_id, self::OPTION_KEY_IN_USE ) ) {
			update_network_option( $network_id, self::OPTION_KEY_IN_USE, true );
		}

		/**
		 * Fires when an application password is created.
		 *
		 * @since 5.6.0
		 * @since 6.8.0 The hashed password value now uses wp_fast_hash() instead of phpass.
		 *
		 * @param int    $user_id      The user ID.
		 * @param array  $new_item     {
		 *     The details about the created password.
		 *
		 *     @type string $uuid      The unique identifier for the application password.
		 *     @type string $app_id    A UUID provided by the application to uniquely identify it.
		 *     @type string $name      The name of the application password.
		 *     @type string $password  A one-way hash of the password.
		 *     @type int    $created   Unix timestamp of when the password was created.
		 *     @type null   $last_used Null.
		 *     @type null   $last_ip   Null.
		 * }
		 * @param string $new_password The generated application password in plain text.
		 * @param array  $args         {
		 *     Arguments used to create the application password.
		 *
		 *     @type string $name   The name of the application password.
		 *     @type string $app_id A UUID provided by the application to uniquely identify it.
		 * }
		 */
		do_action( 'wp_create_application_password', $user_id, $new_item, $new_password, $args );

		return array( $new_password, $new_item );
	}

	/**
	 * Gets a user's application passwords.
	 *
	 * @since 5.6.0
	 *
	 * @param int $user_id User ID.
	 * @return array {
	 *     The list of application passwords.
	 *
	 *     @type array ...$0 {
	 *         @type string      $uuid      The unique identifier for the application password.
	 *         @type string      $app_id    A UUID provided by the application to uniquely identify it.
	 *         @type string      $name      The name of the application password.
	 *         @type string      $password  A one-way hash of the password.
	 *         @type int         $created   Unix timestamp of when the password was created.
	 *         @type int|null    $last_used The Unix timestamp of the GMT date the application password was last used.
	 *         @type string|null $last_ip   The IP address the application password was last used by.
	 *     }
	 * }
	 */
	public static function get_user_application_passwords( $user_id ) {
		$passwords = get_user_meta( $user_id, static::USERMETA_KEY_APPLICATION_PASSWORDS, true );

		if ( ! is_array( $passwords ) ) {
			return array();
		}

		$save = false;

		foreach ( $passwords as $i => $password ) {
			if ( ! isset( $password['uuid'] ) ) {
				$passwords[ $i ]['uuid'] = wp_generate_uuid4();
				$save                    = true;
			}
		}

		if ( $save ) {
			static::set_user_application_passwords( $user_id, $passwords );
		}

		return $passwords;
	}

	/**
	 * Gets a user's application password with the given UUID.
	 *
	 * @since 5.6.0
	 *
	 * @param int    $user_id User ID.
	 * @param string $uuid    The password's UUID.
	 * @return array|null {
	 *     The application password if found, null otherwise.
	 *
	 *     @type string      $uuid      The unique identifier for the application password.
	 *     @type string      $app_id    A UUID provided by the application to uniquely identify it.
	 *     @type string      $name      The name of the application password.
	 *     @type string      $password  A one-way hash of the password.
	 *     @type int         $created   Unix timestamp of when the password was created.
	 *     @type int|null    $last_used The Unix timestamp of the GMT date the application password was last used.
	 *     @type string|null $last_ip   The IP address the application password was last used by.
	 * }
	 */
	public static function get_user_application_password( $user_id, $uuid ) {
		$passwords = static::get_user_application_passwords( $user_id );

		foreach ( $passwords as $password ) {
			if ( $password['uuid'] === $uuid ) {
				return $password;
			}
		}

		return null;
	}

	/**
	 * Checks if an application password with the given name exists for this user.
	 *
	 * @since 5.7.0
	 *
	 * @param int    $user_id User ID.
	 * @param string $name    Application name.
	 * @return bool Whether the provided application name exists.
	 */
	public static function application_name_exists_for_user( $user_id, $name ) {
		$passwords = static::get_user_application_passwords( $user_id );

		foreach ( $passwords as $password ) {
			if ( strtolower( $password['name'] ) === strtolower( $name ) ) {
				return true;
			}
		}

		return false;
	}

	/**
	 * Updates an application password.
	 *
	 * @since 5.6.0
	 * @since 6.8.0 The actual password should now be hashed using wp_fast_hash().
	 *
	 * @param int    $user_id User ID.
	 * @param string $uuid    The password's UUID.
	 * @param array  $update  {
	 *     Information about the application password to update.
	 *
	 *     @type string      $uuid      The unique identifier for the application password.
	 *     @type string      $app_id    A UUID provided by the application to uniquely identify it.
	 *     @type string      $name      The name of the application password.
	 *     @type string      $password  A one-way hash of the password.
	 *     @type int         $created   Unix timestamp of when the password was created.
	 *     @type int|null    $last_used The Unix timestamp of the GMT date the application password was last used.
	 *     @type string|null $last_ip   The IP address the application password was last used by.
	 * }
	 * @return true|WP_Error True if successful, otherwise a WP_Error instance is returned on error.
	 */
	public static function update_application_password( $user_id, $uuid, $update = array() ) {
		$passwords = static::get_user_application_passwords( $user_id );

		foreach ( $passwords as &$item ) {
			if ( $item['uuid'] !== $uuid ) {
				continue;
			}

			if ( ! empty( $update['name'] ) ) {
				$update['name'] = sanitize_text_field( $update['name'] );
			}

			$save = false;

			if ( ! empty( $update['name'] ) && $item['name'] !== $update['name'] ) {
				$item['name'] = $update['name'];
				$save         = true;
			}

			if ( $save ) {
				$saved = static::set_user_application_passwords( $user_id, $passwords );

				if ( ! $saved ) {
					return new WP_Error( 'db_error', __( 'Could not save application password.' ) );
				}
			}

			/**
			 * Fires when an application password is updated.
			 *
			 * @since 5.6.0
			 * @since 6.8.0 The password is now hashed using wp_fast_hash() instead of phpass.
			 *              Existing passwords may still be hashed using phpass.
			 *
			 * @param int   $user_id The user ID.
			 * @param array $item    {
			 *     The updated application password details.
			 *
			 *     @type string      $uuid      The unique identifier for the application password.
			 *     @type string      $app_id    A UUID provided by the application to uniquely identify it.
			 *     @type string      $name      The name of the application password.
			 *     @type string      $password  A one-way hash of the password.
			 *     @type int         $created   Unix timestamp of when the password was created.
			 *     @type int|null    $last_used The Unix timestamp of the GMT date the application password was last used.
			 *     @type string|null $last_ip   The IP address the application password was last used by.
			 * }
			 * @param array $update  The information to update.
			 */
			do_action( 'wp_update_application_password', $user_id, $item, $update );

			return true;
		}

		return new WP_Error( 'application_password_not_found', __( 'Could not find an application password with that id.' ) );
	}

	/**
	 * Records that an application password has been used.
	 *
	 * @since 5.6.0
	 *
	 * @param int    $user_id User ID.
	 * @param string $uuid    The password's UUID.
	 * @return true|WP_Error True if the usage was recorded, a WP_Error if an error occurs.
	 */
	public static function record_application_password_usage( $user_id, $uuid ) {
		$passwords = static::get_user_application_passwords( $user_id );

		foreach ( $passwords as &$password ) {
			if ( $password['uuid'] !== $uuid ) {
				continue;
			}

			// Only record activity once a day.
			if ( $password['last_used'] + DAY_IN_SECONDS > time() ) {
				return true;
			}

			$password['last_used'] = time();
			$password['last_ip']   = $_SERVER['REMOTE_ADDR'];

			$saved = static::set_user_application_passwords( $user_id, $passwords );

			if ( ! $saved ) {
				return new WP_Error( 'db_error', __( 'Could not save application password.' ) );
			}

			return true;
		}

		// Specified application password not found!
		return new WP_Error( 'application_password_not_found', __( 'Could not find an application password with that id.' ) );
	}

	/**
	 * Deletes an application password.
	 *
	 * @since 5.6.0
	 *
	 * @param int    $user_id User ID.
	 * @param string $uuid    The password's UUID.
	 * @return true|WP_Error Whether the password was successfully found and deleted, a WP_Error otherwise.
	 */
	public static function delete_application_password( $user_id, $uuid ) {
		$passwords = static::get_user_application_passwords( $user_id );

		foreach ( $passwords as $key => $item ) {
			if ( $item['uuid'] === $uuid ) {
				unset( $passwords[ $key ] );
				$saved = static::set_user_application_passwords( $user_id, $passwords );

				if ( ! $saved ) {
					return new WP_Error( 'db_error', __( 'Could not delete application password.' ) );
				}

				/**
				 * Fires when an application password is deleted.
				 *
				 * @since 5.6.0
				 *
				 * @param int   $user_id The user ID.
				 * @param array $item    The data about the application password.
				 */
				do_action( 'wp_delete_application_password', $user_id, $item );

				return true;
			}
		}

		return new WP_Error( 'application_password_not_found', __( 'Could not find an application password with that id.' ) );
	}

	/**
	 * Deletes all application passwords for the given user.
	 *
	 * @since 5.6.0
	 *
	 * @param int $user_id User ID.
	 * @return int|WP_Error The number of passwords that were deleted or a WP_Error on failure.
	 */
	public static function delete_all_application_passwords( $user_id ) {
		$passwords = static::get_user_application_passwords( $user_id );

		if ( $passwords ) {
			$saved = static::set_user_application_passwords( $user_id, array() );

			if ( ! $saved ) {
				return new WP_Error( 'db_error', __( 'Could not delete application passwords.' ) );
			}

			foreach ( $passwords as $item ) {
				/** This action is documented in wp-includes/class-wp-application-passwords.php */
				do_action( 'wp_delete_application_password', $user_id, $item );
			}

			return count( $passwords );
		}

		return 0;
	}

	/**
	 * Sets a user's application passwords.
	 *
	 * @since 5.6.0
	 *
	 * @param int   $user_id   User ID.
	 * @param array $passwords {
	 *     The list of application passwords.
	 *
	 *     @type array ...$0 {
	 *         @type string      $uuid      The unique identifier for the application password.
	 *         @type string      $app_id    A UUID provided by the application to uniquely identify it.
	 *         @type string      $name      The name of the application password.
	 *         @type string      $password  A one-way hash of the password.
	 *         @type int         $created   Unix timestamp of when the password was created.
	 *         @type int|null    $last_used The Unix timestamp of the GMT date the application password was last used.
	 *         @type string|null $last_ip   The IP address the application password was last used by.
	 *     }
	 * }
	 * @return int|bool User meta ID if the key didn't exist (ie. this is the first time that an application password
	 *                  has been saved for the user), true on successful update, false on failure or if the value passed
	 *                  is the same as the one that is already in the database.
	 */
	protected static function set_user_application_passwords( $user_id, $passwords ) {
		return update_user_meta( $user_id, static::USERMETA_KEY_APPLICATION_PASSWORDS, $passwords );
	}

	/**
	 * Sanitizes and then splits a password into smaller chunks.
	 *
	 * @since 5.6.0
	 *
	 * @param string $raw_password The raw application password.
	 * @return string The chunked password.
	 */
	public static function chunk_password(
		#[\SensitiveParameter]
		$raw_password
	) {
		$raw_password = preg_replace( '/[^a-z\d]/i', '', $raw_password );

		return trim( chunk_split( $raw_password, 4, ' ' ) );
	}

	/**
	 * Hashes a plaintext application password.
	 *
	 * @since 6.8.0
	 *
	 * @param string $password Plaintext password.
	 * @return string Hashed password.
	 */
	public static function hash_password(
		#[\SensitiveParameter]
		string $password
	): string {
		return wp_fast_hash( $password );
	}

	/**
	 * Checks a plaintext application password against a hashed password.
	 *
	 * @since 6.8.0
	 *
	 * @param string $password Plaintext password.
	 * @param string $hash     Hash of the password to check against.
	 * @return bool Whether the password matches the hashed password.
	 */
	public static function check_password(
		#[\SensitiveParameter]
		string $password,
		string $hash
	): bool {
		if ( ! str_starts_with( $hash, '$generic$' ) ) {
			/*
			 * If the hash doesn't start with `$generic$`, it is a hash created with `wp_hash_password()`.
			 * This is the case for application passwords created before 6.8.0.
			 */
			return wp_check_password( $password, $hash );
		}

		return wp_verify_fast_hash( $password, $hash );
	}
}
ID3-
IXR-
PHPMailer-
Requests-
SimplePie-
Text-
abilities-api-
abilities-api.php32800V
abilities.php11797V
admin-bar.php40067V
ai-client-
ai-client.php2549V
assets-
atomlib.php12181V
author-template.php19844V
block-bindings-
block-bindings.php7632V
block-editor.php28724V
block-i18n.json316V
block-patterns-
block-patterns.php15606V
block-supports-
block-template-utils.php63477V
block-template.php18257V
blocks-
blocks.php124205V
bookmark-template.php12768V
bookmark.php15427V
build-
cache-compat.php11021V
cache.php13486V
canonical.php34786V
capabilities.php43584V
category-template.php56990V
category.php12834V
certificates-
class-IXR.php2609V
class-avif-info.php30008V
class-feed.php539V
class-http.php367V
class-json.php171V
class-oembed.php401V
class-phpass.php6771V
class-phpmailer.php664V
class-pop3.php171V
class-requests.php2237V
class-simplepie.php453V
class-smtp.php457V
class-snoopy.php37715V
class-spl.php171V
class-walker-category-dropdown.php2469V
class-walker-category.php8477V
class-walker-comment.php14221V
class-walker-nav-menu.php12044V
class-walker-page-dropdown.php2710V
class-walker-page.php7612V
class-wp-admin-bar.php18002V
class-wp-ajax-response.php5288V
class-wp-application-passwords.php17099V
class-wp-block-bindings-registry.php8263V
class-wp-block-bindings-source.php2992V
class-wp-block-editor-context.php1350V
class-wp-block-list.php4713V
class-wp-block-metadata-registry.php11846V
class-wp-block-parser-block.php2555V
class-wp-block-parser-frame.php1994V
class-wp-block-parser.php11525V
class-wp-block-pattern-categories-registry.php4383V
class-wp-block-patterns-registry.php10265V
class-wp-block-processor.php69914V
class-wp-block-styles-registry.php6419V
class-wp-block-supports.php7578V
class-wp-block-template.php2111V
class-wp-block-templates-registry.php7080V
class-wp-block-type-registry.php5305V
class-wp-block-type.php17222V
class-wp-block.php28236V
class-wp-classic-to-block-menu-converter.php4026V
class-wp-comment-query.php49040V
class-wp-comment.php17249V
class-wp-connector-registry.php15181V
class-wp-customize-control.php26112V
class-wp-customize-manager.php202908V
class-wp-customize-nav-menus.php58034V
class-wp-customize-panel.php10703V
class-wp-customize-section.php11209V
class-wp-customize-setting.php29956V
class-wp-customize-widgets.php72596V
class-wp-date-query.php35970V
class-wp-dependencies.php17089V
class-wp-dependency.php2653V
class-wp-duotone.php40836V
class-wp-editor.php72228V
class-wp-embed.php15908V
class-wp-error.php7514V
class-wp-exception.php253V
class-wp-fatal-error-handler.php8150V
class-wp-feed-cache-transient.php3304V
class-wp-feed-cache.php969V
class-wp-filter-sentinel.php760V
class-wp-hook.php17584V
class-wp-http-cookie.php7269V
class-wp-http-curl.php13261V
class-wp-http-encoding.php6689V
class-wp-http-ixr-client.php3516V
class-wp-http-proxy.php5980V
class-wp-http-requests-hooks.php2022V
class-wp-http-requests-response.php4243V
class-wp-http-response.php2977V
class-wp-http-streams.php16764V
class-wp-http.php41641V
class-wp-icon-collections-registry.php5805V
class-wp-icons-registry.php9903V
class-wp-image-editor-gd.php20741V
class-wp-image-editor-imagick.php43454V
class-wp-image-editor.php17456V
class-wp-list-util.php7443V
class-wp-locale-switcher.php6776V
class-wp-locale.php16848V
class-wp-matchesmapregex.php1828V
class-wp-meta-query.php30507V
class-wp-metadata-lazyloader.php6833V
class-wp-navigation-fallback.php9193V
class-wp-network-query.php19989V
class-wp-network.php12411V
class-wp-object-cache.php17524V
class-wp-oembed-controller.php6905V
class-wp-oembed.php34372V
class-wp-paused-extensions-storage.php5067V
class-wp-phpmailer.php4348V
class-wp-plugin-dependencies.php25209V
class-wp-post-type-variable.php0V
class-wp-post-type.php30672V
class-wp-post.php8806V
class-wp-query.php164148V
class-wp-recovery-mode-cookie-service.php6877V
class-wp-recovery-mode-email-service.php11162V
class-wp-recovery-mode-key-service.php4914V
class-wp-recovery-mode-link-service.php3523V
class-wp-recovery-mode.php11460V
class-wp-rewrite.php63693V
class-wp-role.php2523V
class-wp-roles.php9326V
class-wp-script-modules.php40743V
class-wp-scripts.php36754V
class-wp-session-tokens.php7319V
class-wp-simplepie-file.php3552V
class-wp-simplepie-sanitize-kses.php1903V
class-wp-site-query.php31482V
class-wp-site.php7836V
class-wp-speculation-rules.php7884V
class-wp-styles.php13316V
class-wp-tax-query.php19577V
class-wp-taxonomy.php18559V
class-wp-term-query.php40751V
class-wp-term.php5263V
class-wp-text-diff-renderer-inline.php979V
class-wp-text-diff-renderer-table.php18925V
class-wp-textdomain-registry.php10481V
class-wp-theme-json-data.php1805V
class-wp-theme-json-resolver.php35692V
class-wp-theme-json-schema.php7367V
class-wp-theme-json.php222059V
class-wp-theme.php65811V
class-wp-token-map.php29032V
class-wp-url-pattern-prefixer.php4802V
class-wp-user-meta-session-tokens.php2954V
class-wp-user-query.php44102V
class-wp-user-request.php2342V
class-wp-user.php23189V
class-wp-view-config-data.php29427V
class-wp-walker.php13292V
class-wp-widget-factory.php4113V
class-wp-widget.php18452V
class-wp-xmlrpc-server.php217288V
class-wp.php26520V
class-wpdb.php121437V
class.wp-dependencies.php373V
class.wp-scripts.php343V
class.wp-styles.php338V
comment-template.php103211V
comment.php150630V
compat-utf8.php19386V
compat.php22479V
connectors.php32922V
cron.php46266V
css-
customize-
date.php400V
default-constants.php11365V
default-filters.php39500V
default-widgets.php2288V
deprecated.php193977V
embed-template.php338V
embed.php39215V
error-protection.php4092V
feed-atom-comments.php5504V
feed-atom.php3114V
feed-rdf.php2668V
feed-rss-core.php146V
feed-rss.php1189V
feed-rss2-comments.php4136V
feed-rss2.php3799V
feed.php25189V
fonts-
fonts.php9789V
formatting.php357678V
functions.php295481V
functions.wp-scripts.php20492V
functions.wp-styles.php8654V
general-template-get.php146V
general-template.php184198V
global-styles-and-settings.php20780V
html-api-
http.php28961V
https-detection.php5857V
https-migration.php4741V
icons.php6334V
images-
interactivity-api-
js-
json-schema.php7802V
kses.php88497V
l10n-
l10n.php71415V
link-template.php160143V
load.php56475V
locale.php162V
media-template.php65759V
media.php236804V
meta.php66739V
ms-blogs.php26324V
ms-default-constants.php4921V
ms-default-filters.php6636V
ms-deprecated.php21787V
ms-files.php2857V
ms-functions.php92530V
ms-load.php20055V
ms-network.php3782V
ms-settings.php4197V
ms-site.php41729V
nav-menu-template.php25983V
nav-menu.php44269V
option.php105246V
php-ai-client-
php-compat-
pluggable-deprecated.php6324V
pluggable.php127919V
plugin.php37123V
pomo-
post-formats.php7070V
post-template.php69129V
post-thumbnail-template.php10879V
post.php305215V
query.php37554V
registration-functions.php200V
registration.php200V
rest-api-
rest-api.php102951V
revision.php31241V
rewrite.php19567V
robots-template.php5185V
rss-functions.php277V
rss.php23203V
script-loader.php163550V
script-modules.php12311V
session.php258V
shortcodes-set.php0V
shortcodes.php24034V
sitemaps-
sitemaps.php3238V
sodium_compat-
speculative-loading.php11880V
spl-autoload-compat.php441V
style-engine-
style-engine.php8045V
taxonomy.php178307V
template-canvas.php544V
template-loader.php4267V
template.php38826V
theme-compat-
theme-i18n.json1892V
theme-previews.php2887V
theme-templates.php4060V
theme.json9480V
theme.php134913V
update.php38269V
user.php180301V
utf8.php6977V
vars.php6600V
version.php1103V
view-config.php19087V
view-transitions.php602V
widgets-
widgets.php70866V
wp-db.php445V
wp-diff.php792V
Blog - Page 3 of 508 - My Melon - Digital Marketing & Creative Agency
Skip to content Skip to footer