JezK
Edit File: class-rbauthenticator.php
<?php if ( ! defined( 'WPINC' ) || ! defined( 'ABSPATH' ) ) { die; } class RBAuthenticator { private $session_key = ''; private $redirect_to_after_login; private $unauthorized_file; public function __construct( $session_key, $redirect_to_after_login, $unauthorized_file ) { $this->session_key = $session_key; $this->redirect_to_after_login = $redirect_to_after_login; $this->unauthorized_file = $unauthorized_file; } public function run() { if ( isset( $_GET['signature'] ) && isset( $_GET['data'] ) ) { $signature = sanitize_text_field( wp_unslash( $_GET['signature'] ) ); $data = sanitize_text_field( wp_unslash( $_GET['data'] ) ); $request = wp_remote_get( RB_DASHBOARD_BASE_URL . '/dbauth/isvalid' . '?signature=' . rawurlencode( $signature ) . '&data=' . rawurlencode( $data ) . '&source=' . rawurlencode( RB_BOX_NAME ) ); $body = wp_remote_retrieve_body( $request ); if ( $body === '1' ) { session_start(); try { session_regenerate_id( true ); } catch ( \TypeError $e ) { // Broken third-party session handler (e.g. wp-native-php-sessions); // regenerate without destroying the old session — destroy() is then not invoked. session_regenerate_id( false ); } $_SESSION[ $this->session_key ] = '1'; header( sprintf( 'Location: %s', $this->redirect_to_after_login ) ); return; } } else { include $this->unauthorized_file; exit; } session_start(); if ( ! isset( $_SESSION[ $this->session_key ] ) ) { include $this->unauthorized_file; exit; } } }