JezK
Edit File: block-user-enumeration.php
<?php if ( ! defined( 'WPINC' ) || ! defined( 'ABSPATH' ) ) { die; } require_once ABSPATH . 'wp-includes/pluggable.php'; class RBBlockUserEnumerationPlugin { private static $instance = null; private function __construct() { } public static function get_instance() { if ( self::$instance === null ) { self::$instance = new self(); } return self::$instance; } /** * Helper function * Get the users display_name */ public function get_user_nicename( $nicename ) { global $wpdb; if ( ! $user = $wpdb->get_row( $wpdb->prepare( "SELECT `ID` FROM $wpdb->users WHERE `user_nicename` = %s", $nicename ) ) ) { return false; } return get_user_by( 'id', $user->ID ); } /** * Helper function * Get the current logged in user */ public function get_logged_in_user( $login ) { return get_user_by( 'login', $login ); } /** * Helper function * Create a string from an array_key if the value of the key matches the searched input */ public function string_from( $array, $key ) { if ( array_key_exists( $key, $array ) ) { $value = $array[ $key ]; if ( is_string( $value ) ) { return $value; } } return ''; } /** * Check if the user is an admin, and if so, hide it's user_login on posts and archives and comments * (will be hooked in later in this class) * and replace it with it's display_name (hopefully not the same as the users login). * If it has no nickname, return an empty string. */ public function raidboxes_hide_admin_username( $display_name ) { $user = self::get_logged_in_user( $display_name ); if ( user_can( $user, 'administrator' ) ) { if ( strcasecmp( $user->display_name, $display_name ) !== 0 ) { return $user->display_name; } else { return ''; } } else { return $display_name; } } /** * Check if the user is an admin, and if so, hide it's user_url on posts and archives * (will be hooked in later in this class). */ public function raidboxes_hide_admin_url( $link ) { $nicename = ltrim( strrchr( rtrim( $link, '/' ), '/' ), '/' ); $user = self::get_user_nicename( $nicename ); if ( user_can( $user, 'administrator' ) ) { return ''; } else { return $link; } } /** * Remove author IDs from classes in comments * (will be hooked in later in this class). */ public function raidboxes_remove_comment_user_id_in_classes( $classes ) { $removed = false; reset( $classes ); while ( ( $k = key( $classes ) ) !== null ) { if ( strpos( $classes[ $k ], 'comment-author-' ) === 0 ) { unset( $classes[ $k ] ); $removed = true; } next( $classes ); } if ( $removed ) { $classes = array_values( $classes ); } return $classes; } /** * Remove the comment_reply_link indicator of admin comments */ public function raidboxes_remove_comment_reply_link( $link, $args, $comment, $post ) { $link = preg_replace( '/aria-label=\'.+\'/', 'aria-label=\'\'', $link ); return $link; } /** * Hide the username and urls from WordPress posts, comments and archives */ public function from_posts() { add_filter( 'the_author', array( $this, 'raidboxes_hide_admin_username' ), 10, 1 ); add_filter( 'get_comment_author', array( $this, 'raidboxes_hide_admin_username' ), 10, 1 ); add_filter( 'author_link', array( $this, 'raidboxes_hide_admin_url' ), 10, 1 ); add_filter( 'comment_class', array( $this, 'raidboxes_remove_comment_user_id_in_classes' ), 10, 1 ); add_filter( 'comment_reply_link', array( $this, 'raidboxes_remove_comment_reply_link' ), 10, 4 ); } /** * Discourage the WordPress-REST-API from displaying * user names and give back a 403 header */ public function from_rest_api() { $header_error_403 = 'HTTP/1.1 403 Forbidden'; $header_content_type_json = 'Content-Type: application/json; charset=UTF-8'; $regex_api = '@/wp/v2/users\b@'; $request_uri = $this->string_from( $_SERVER, 'REQUEST_URI' ); $rest_route = $this->string_from( $_REQUEST, 'rest_route' ); $call_rest_api = preg_match( $regex_api, $request_uri ) || preg_match( $regex_api, $rest_route ); if ( $call_rest_api ) { header( $header_error_403 ); header( $header_content_type_json ); die( '{"code":"rest_user_cannot_view","message":"Sorry, you are not allowed to list users.","data":{"status":403}}' ); } } public static function init() { $block_user_enumeration = self::get_instance(); $block_user_enumeration->from_posts(); $block_user_enumeration->from_rest_api(); } } RBBlockUserEnumerationPlugin::init();