....................................../////.===Shadow-Here===./////................................................ > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < > < ------------------------------------------------------------------------------------------------------------------- /////////////////////////////////////////////////////////////////////////////////////////////////////////////////// RIFF¤ WEBPVP8 ˜ ðÑ *ôô>‘HŸK¥¤"§£±¨àð enü¹%½_F‘åè¿2ºQú³íªú`N¿­3ÿƒügµJžaÿ¯ÿ°~¼ÎùnúîÞÖô•òíôÁÉß®Sm¥Ü/ ‡ó˜f£Ùà<˜„xëJ¢Ù€SO3x<ªÔ©4¿+ç¶A`q@Ì“Úñè™ÍÿJÌ´ª-˜ÆtÊÛL]Ïq*‘Ý”ì#ŸÌÏãY]@ê`¿ /ªfkØB4·®£ó z—Üw¥Pxù–ÞLШKÇN¾AkÙTf½è'‰g gÆv›Øuh~ a˜Z— ïj*á¥t d£“uÒ ¨`K˜¹ßþ]b>˜]_ÏÔ6W—è2r4x•íÖ…"ƒÖNîä!¦å Ú}ýxGøÌ —@ ;ÆÚŠ=ɾ1ý8lªË¥ô ^yf®Œ¢u&2©nÙÇ›ñÂñŒ³ aPo['½»øFùà­+4ê“$!lövlüÞ=;N®3ð‚õ›DÉKòÞ>ÄÍ ¥ˆuߤ#ˆ$6ù™¥îЇy’ÍB¼ çxÛ;X"WL£R÷͝*ó-¶Zu}º.s¸sšXqù–DþÿvªhüïwyŸ ¯é³lÀ:KCûÄ£Ëá\…­ ~—ýóî ¼ûûÜTÓüÇy…ŽÆvc»¾×U ñ¸žþоP÷¦ó:Ò¨¨5;Ð#&#ÖúñläÿÁœ GxÉ­/ñ‡áQðìYÉtÒw޼GÔ´zàÒò ð*ëzƒ•4~H]Ø‹f ñÓÈñ`NåWçs'ÆÏW^ø¹!XžµmQ5ÃËoLœÎ: ÞËÍ¥J ù…î èo£ßPÎñ¶ž8.Œ]ʵ~5›ÙË-ù*8ÙÖß±~ ©¹rÓê‚j¶d¸{^Q'˜±Crß ÚH—#¥¥QlÀ×ëã‡DÜ«èî þ&Çæžî;ŽÏºò6ÒLÃXy&ZŒ'j‚¢Ù€IßÚù+–MGi‰*jE€‘JcÜ ÓÌ EÏÚj]o˜ Þr <¾U ûŪæÍ/šÝH¥˜b”¼ ÁñßX GP›ï2›4WŠÏà×£…íÓk†¦H·ÅíMh–*nó÷à]ÁjCº€b7<ب‹¨5車bp2:Á[UªM„QŒçiNMa#<5›áËó¸HýÊ"…×Éw¹¦ì2º–x<›»a±¸3Weü®FÝ⑱ö–î–³|LPÈ~çð~Çå‡|º kD¢µÏàÆAI %1À% ¹Ò – ”ϝS¦‰4&¶£°à Öý”û_Ò Áw°A«Å€?mÇÛgHÉ/8)á¾ÛìáöŽP í¨PŸNÙµº¦‡§Ùš"ÿ«>+ªÕ`Ê÷‡‚ß Õû˜þãÇ-PÍ.¾XV‘€ dÜ"þ4¹ ±Oú‘©t¥¦FªÄÃÄ•b‚znýu½—#cDs˜ÃiÑOˆñ×QO=*IAÊ,¶ŽZƒ;‡wøXè%EÐk:F±Ú” .Ѽ+Áu&Ç`."pÈÉw o&¿dE6‘’EqTuK@Ì¥ã™À(Êk(h‰,H}RÀIXÛš3µ1©_OqÚÒJAñ$ÊÙÜ;D3çŒ[þùœh¬Ã³™ö6ç†NY".Ú‰ï[ªŸŒ '²Ð öø_¨ÂÉ9ué¶³ÒŠõTàîMØ#û¯gN‡bÙ놚X„ö …ÉeüÌ^J ‹€.œ$Æ)βÄeæW#óüßĺŸ€ ÀzwV 9oä»f4V*uB «Ë†¹ì¯žR霓æHXa=&“I4K;¯ç‹h×·"UŠ~<•╪Vêª&ÍSÃÆÅ?ÔqÎ*mTM ˜›µwêd#[C¡©§‘D<©àb†–ÁœøvH/,í:¯( ²£|4-„Æövv„Yͼ™^Á$ˆ„¢Û[6yB.åH*V¨æ?$=˜Ñ€•ñ·­(VlŸ‘ nÀt8W÷´Bûba?q9ú¶Xƒl«ÿ\ù¶’þòUÐj/õ¢Ìµ³g$ƒÎR!¸»|Oߍë’BhîÚÑ¢ñåŒJ„®„£2Ð3•ô02Nt…!£Í]Ïc½Qÿ?ˆ<&ÃA¾Ú,JˆijÌ#5yz„‰Î|ÊŽ5QÏ:‹ÐaóVÔxW—CpeÏzÐïíçôÿÅ_[hãsÐ_/ŽTÝ?BîˆííV$<¿i>²F¬_Eß¿ †bÊŒº­ÿ®Z H“C}”¬,Mp ý/Bá£w>˜YV°aƒúh+cŠ- r/[%|üUMHäQ°X»|û/@|°¥Ð !BÔ Ç¢Ä©š+Õì D«7ìN¶ŽðÔ " ƶ’ÖçtA‰Û×}{tþz­¾GÍ›k¹OEJR$ Â׃ «ëÁ"oÉôž$oUK(Ä)Ãz³Ê-‹êN[Ò3Œñbï8P 4ƒ×q¢bo|?<ÛX¬òÄͰL–±›(™ûG?ýË©ÚÄ–ÂDØÐ_Ç¡ô ¾–ÄÏø ×e8Ë©$ÄF¹Å‹ì[©óìl:F¾f´‹‹Xì²ï®\¬ôùƒ ÿat¥óèÒùHß0äe‚;ü×h:ÆWðHž=Ã8骣"kœ'Y?³}Tûè€>?0l›e1Lòñ„aæKÆw…hÖŠùW…ÈÆÄ0ši·›[pcwËþñiêíY/~-Á5˜!¿†A›™Mÿþ(±“t@â“ö2­´TG5yé]çå僳 .·ÍïçÝ7UÚ±Ð/Nè»,_Ï ùdj7\ï Wì4›„»c¸àešg#ÒÊ⥭áØo5‘?ÌdÝô¯ ¹kzsƒ=´#ëÉK›Ø´±-¥eW?‡çßtòTã…$Ý+qÿ±ƒ÷_3Ô¥í÷:æ–ž<·Ö‡‰Å¢ š‡%Ô—utÌÈìðžgÖÀz²À—ï÷Óîäõ{K'´È÷³yaÏÁjƒô}ž§®æÊydÕÈë5¯èˆõvÕ©ã*çD„ “z„Ó‡^^xÂ3M§A´JG‚öï 3W'ˆ.OvXè¡ÊÕª?5º7†˜(˜Ç¶#çê’¶!ÌdZK§æ 0fãaN]òY³RV ™î$®K2R¨`W!1Ôó\;Ý ýB%qæK•&ÓÈe9È0êI±žeŸß -ú@žQr¦ ö4»M¼Áè¹µmw 9 EÆE_°2ó„ŸXKWÁ×Hóì^´²GѝF©óäR†¦‰ç"V»eØ<3ùd3ÿÚ¤Žú“Gi" —‘_ÙËÎ~Üö¯¥½Î»üŸEÚŽåmÞþí ;ÞólËΦMzA"Âf(´òá;Éï(/7½ûñÌ­cïÕçлþÝz¾-ÍvÑ“pH­–ðÓj$¸Äû¤‚‘ãUBË-n“2åPkS5&‹Â|+g^œ®Ì͆d!OïäîU«c;{Û!ÅŽ«ëZ9Ókóˆ]¯ƒ›né `ÇÒ+tÆš (ØKá¾—=3œ®•vuMñg²\ï Ec€ 05±d™‡×iÇ×›UúvÌ¢£Èþ¡ÕØô¶ßÎA"ß±#Ö²ˆÊŸ¦*Ä~ij|àø.-¼'»Ú¥£h ofº¦‡VsR=N½„Î v˜Z*SÌ{=jÑB‹tê…;’HžH¯8–îDù8ñ¢|Q•bÛçš–‹m³“ê¨ åÏ^m¬Žãþ©ïêO‡½6] µÆ„Ooòü ²x}N¦Ë3ïé¿»€›HA˜m%çÞ/¿í7Fø“‹léUk)É°Œµ8Q8›:ÀŠeT*šõ~ôڝG6 ¢}`ùH­–”¡k ‰P1>š†®9z11!X wKfmÁ¦xÑ,N1Q”–æB¶M…ÒÃv6SMˆhU¬ÊPŽï‘öj=·CŒ¯u¹ƒVIЃsx4’ömÛýcå¡¶7ßŠß 57^\wÒÐÆ k§h,Œý î«q^R½3]J¸ÇðN ‚çU¬ôº^Áì} ³f©Õœ§ˆã:FÄÈ‚é(€™?àýÓüè1Gô£¼éj‚OÅñ  #>×—ßtà 0G¥Åa뀐kßhc™À_ÉñÞ#±)GD" YîäË-ÿÙ̪ ¹™a¯´¢E\ÝÒö‚;™„ë]_ p8‰o¡ñ+^÷ 3‘'dT4œŽ ðVë½° :¬víÑ«£tßÚS-3¶“þ2 †üüʨòrš¹M{É_¤`Û¨0ìjœøJ‡:÷ÃáZ˜†@GP&œÑDGÏs¡þ¦þDGú‘1Yá9Ôþ¼ ûø…§÷8&–ÜÑnÄ_m®^üÆ`;ÉVÁJ£?â€-ßê}suÍ2sõA NÌúA磸‘îÿÚ»ƒìö·á¿±tÑÐ"Tÿü˜[@/äj¬€uüªìù¥Ý˜á8Ý´sõj 8@rˆð äþZÇD®ÿUÏ2ùôõrBzÆÏÞž>Ì™xœ“ wiÎ×7_… ¸ \#€MɁV¶¥üÕÿPÔ9Z‡ø§É8#H:ƒ5ÀÝå9ÍIŒ5åKÙŠ÷qÄ>1AÈøžj"µÂд/ªnÀ qªã}"iŸBå˜ÓÛŽ¦…&ݧ;G@—³b¯“•"´4í¨ôM¨åñC‹ïùÉó¯ÓsSH2Ý@ßáM‡ˆKÀªÛUeø/4\gnm¥‹ŸŒ qÄ b9ÞwÒNÏ_4Ég³ú=܆‚´ •â¥õeíþkjz>éÚyU«Íӝ݃6"8/ø{=Ô¢»G¥ äUw°W«,ô—¿ãㆅү¢³xŠUû™yŒ (øSópÐ 9\åTâ»—*oG$/×ÍT†Y¿1¤Þ¢_‡ ¼ „±ÍçèSaÓ 3ÛMÁBkxs‰’R/¡¤ˆÙçª(*õ„üXÌ´ƒ E§´¬EF"Ù”R/ÐNyÆÂ^°?™6¡œïJ·±$§?º>ÖüœcNÌù¯G ‹ñ2ЁBB„^·úìaz¨k:#¨Æ¨8LÎõލ£^§S&cŒÐU€ü(‡F±Š¼&P>8ÙÁ ‰ p5?0ÊÆƒZl¸aô š¼¡}gÿ¶zÆC²¹¬ÎÖG*HB¡O<º2#ñŒAƒ–¡B˜´É$¥›É:FÀÔx¾u?XÜÏÓvN©RS{2ʈãk9rmP¼Qq̳ è¼ÐFׄ^¡Öì fE“F4A…!ì/…¦Lƒ… … $%´¾yã@CI¬ á—3PþBÏNÿ<ý°4Ü ËÃ#ØÍ~âW«rEñw‹eùMMHß²`¬Öó½íf³:‹k˜¯÷}Z!ã¿<¥,\#öµÀ¯aÒNÆIé,Ћ–lŽ#Àæ9ÀÒS·I’½-Ïp Äz¤Š Â* ­íÄ9­< h>׍3ZkËU¹§˜ŒŠ±f­’¤º³Q ÏB?‹#µíÃ¥®@(Gs«†vI¥Mµ‹Á©e~2ú³ÁP4ìÕi‚²Ê^ö@-DþÓàlÜOÍ]n"µã:žpsŽ¢:! Aõ.ç~ÓBûH÷JCÌ]õVƒd «ú´QÙEA–¯¯Œ!.ˆˆëQ±ù œ·Ì!Õâ )ùL„ÅÀlÚè5@B…o´Æ¸XÓ&Û…O«˜”_#‡ƒ„ûÈt!¤ÁÏ›ÎÝŠ?c9 â\>lÓÁVÄÑ™£eØY]:fÝ–—ù+p{™ðè û³”g±OƒÚSù£áÁÊ„ä,ï7š²G ÕÌBk)~ÑiCµ|h#u¤¶îK¨² #²vݯGãeÖ϶ú…¾múÀ¶þÔñ‚Š9'^($¤§ò “š½{éúp÷J›ušS¹áªCÂubÃH9™D™/ZöØÁ‡¦ÝÙŸ·kð*_”.C‹{áXó€‡c¡c€§/šò/&éš÷,àéJþ‰X›fµ“C¨œ®r¬"kL‰Â_q…Z–.ÉL~O µ›zn‚¹À¦Öª7\àHµšÖ %»ÇníV[¥*Õ;ƒ#½¾HK-ÖIÊdÏEÚ#=o÷Óò³´Š: Ç?{¾+9›–‘OEáU·S€˜j"ÄaÜ ŒÛWt› á–c#a»pÔZÞdŽtWê=9éöÊ¢µ~ ë ;Öe‡Œ®:bî3±ýê¢wà¼îpêñ¹¾4 zc¾ðÖÿzdêŒÑÒŝÀ‰s6¤í³ÎÙB¿OZ”+F¤á‡3@Ñëäg©·Ž ˆèª<ù@É{&S„œÕúÀA)‰h:YÀ5^ÂÓŒ°õäU\ ùËÍû#²?Xe¬tu‰^zÒÔãë¼ÛWtEtû …‚g¶Úüâî*moGè¨7%u!]PhÏd™Ý%Îx: VÒ¦ôÊD3ÀŽKÛËãvÆî…N¯ä>Eró–ð`5 Œ%u5XkñÌ*NU%¶áœÊ:Qÿú»“úzyÏ6å-၇¾ ´ ÒÊ]y žO‘w2Äøæ…H’²f±ÎÇ.ª|¥'gîV•Ü .̘¯€šòü¤U~Ù†*¢!?ò wý,}´°ÔÞnïoKq5µb!áÓ3"vAßH¡³¡·G(ÐÎ0Îò¼MG!/ài®@—¬04*`…«é8ªøøló“ˆÊ”èù¤…ßÊoÿé'ËuÌÖ5×È¡§ˆˆfŽë9}hìâ_!!¯  B&Ëö¶‰ÀAÙNVŸ Wh›¸®XÑJì¨ú“¿÷3uj²˜¨ÍÎìë±aúŠÝå¯ð*Ó¨ôJ“yºØ)m°WýOè68†ŸÏ2—‰Ïüꪫٚ¥‹l1 ø ÏÄFjêµvÌbü¦èÝx:X±¢H=MÐß—,ˆÉÇ´(9ú¾^ÅÚ4¿m‡$âX‘å%(AlZo@½¨UOÌÕ”1ø¸jÎÀÃÃ_ µ‘Ü.œº¦Ut: Æï’!=¯uwû#,“pþÇúŒø(é@?³ü¥‘Mo §—s@Œ#)§ŒùkL}NOÆêA›¸~r½¼ÙA—HJ«eˆÖ´*¡ÓpÌŸö.m<-"³ûÈ$¬_6­åf£ïÚâj1y§ÕJ½@dÞÁr&Í\Z%D£Íñ·AZ Û³øüd/ªAi†/Й~  ‡âĮҮÏh§°b—›Û«mJžòG'[ÈYýŒ¦9psl ýÁ ®±f¦x,‰½tN ‚Xª9 ÙÖH.«Lo0×?͹m¡å†Ѽ+›2ƒF ±Ê8 7Hցϓ²Æ–m9…òŸï]Â1äN†VLâCˆU .ÿ‰Ts +ÅÎx(%¦u]6AF Š ØF鈄‘ |¢¶c±soŒ/t[a¾–û:s·`i햍ê›ËchÈ…8ßÀUÜewŒðNOƒõD%q#éû\9¤x¹&UE×G¥ Í—™$ð E6-‡¼!ýpãÔM˜ Âsìe¯ñµK¢Ç¡ùôléœ4Ö£”À Š®Ðc ^¨À}ÙËŸ§›ºê{ÊuÉC ×Sr€¤’fÉ*j!úÓ’Gsùìoîßîn%ò· àc Wp÷$¨˜)û»H ×8ŽÒ€Zj¤3ÀÙºY'Ql¦py{-6íÔCeiØp‘‡XÊîÆUߢ܂ž£Xé¼Y8þ©ëgñß}é.ÎógÒ„ÃØËø¯»™§Xýy M%@NŠ À(~áÐvu7&•,Ù˜ó€uP‡^^®=_E„jt’ 403WebShell
403Webshell
Server IP : 51.91.236.193  /  Your IP : 216.73.216.177
Web Server : Apache
System : Linux webm019.cluster128.gra.hosting.ovh.net 6.18.42-ovh-vps-grsec-zfs+ #1 SMP PREEMPT_DYNAMIC Wed Aug 5 15:59:48 CEST 2026 x86_64
User : thillelirn ( 8290)
PHP Version : 8.0.30
Disable Function : _dyuweyrj4,_dyuweyrj4r,dl
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/t/h/i/thillelirn/www/wp-content/plugins/complianz-gdpr/websitescan/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/t/h/i/thillelirn/www/wp-content/plugins/complianz-gdpr/websitescan/class-wsc-auth.php
<?php

defined('ABSPATH') or die();

if (!class_exists("cmplz_wsc_auth")) {

	class cmplz_wsc_auth
	{

		const WSC_ENDPOINT = 'aHR0cHM6Ly9hcGkuY29tcGxpYW56Lmlv';
		const WSC_CB_ENDPOINT = 'aHR0cHM6Ly9leHRlcm5hbC1wdWJsaWMtZ2VuZXJhbC5zMy5ldS13ZXN0LTEuYW1hem9uYXdzLmNvbS9zdGF0dXMuanNvbg==';
		const WSC_TERMS_ENDPOINT = 'aHR0cHM6Ly9jb29raWVkYXRhYmFzZS5vcmcvd3AtanNvbi93c2MvdjEvdGVybXM=';
		const NEWSLETTER_TERMS_ENDPOINT = 'aHR0cHM6Ly9jb29raWVkYXRhYmFzZS5vcmcvd3AtanNvbi9uZXdzbGV0dGVyL3YxL3Rlcm1z';
		const NEWSLETTER_SIGNUP_ENDPOINT = 'aHR0cHM6Ly9tYWlsaW5nbGlzdC5jb21wbGlhbnouaW8=';
		const CONS_ENDPOINT = 'aHR0cHM6Ly9jb25zZW50LmNvbXBsaWFuei5pby9wdWJsaWMvY29uc2VudA==';
		const CONS_ENDPOINT_PK = 'qw0Jv5legvI9fQdn5OvNedpG4zibaTNT';
		const WSC_ENDPOINT_AUTH_HEADER = 'QmFzaWMgZEdWaGJXSnNkV1ZmYzNSaFoybHVaenBGYm05bVJHZzRjV0Y2YVhCemFUWkxSM05FVlE9PQ==';
		const PARTNER_ID = 'NjQ1MTc4NjMtM2YzMS00NDA3LWJjMWUtMjc4MjNlOTJhNThl';
		const CONS_IDENTIFIERS = [
			'wsc_consent' => 'terms',
			'newsletter_consent' => 'newsletter',
		];


		public function init_hooks()
		{
			add_action("admin_init", array($this, 'confirm_email_auth'), 10, 3); // Verify the authentication link in the email
			add_action('cmplz_every_day_hook', array($this, 'check_failed_consent_onboarding'));
			add_action('cmplz_every_day_hook', array($this, 'check_failed_newsletter_signup'));
		}


		/**
		 * Sends an authentication email.
		 *
		 * This function sends an authentication email to the specified email address.
		 * It first checks if the user has the capability to manage the plugin.
		 * If the email is not a valid email address, it updates an option to indicate that the email was not sent.
		 * If the email is valid, it makes a POST request to the WSC endpoint to send the email.
		 * If the request is successful, it sets various options to indicate that the email was sent and updates the signup status.
		 * If the request fails, it updates an option to indicate that the email was not sent.
		 *
		 * @param string $email The email address to send the authentication email to.
		 * @return void
		 */
		public static function send_auth_email(string $email): void
		{
			if (!cmplz_user_can_manage() || empty($email)) {
				return;
			}

			if (!is_email($email)) {
				update_option('cmplz_wsc_error_email_not_sent', true, false);
				return;
			}

			$wsc_endpoint = base64_decode(self::WSC_ENDPOINT);
			$wsc_endpoint_auth_header = base64_decode(self::WSC_ENDPOINT_AUTH_HEADER);
			$partner_id = base64_decode(self::PARTNER_ID);

			$request = wp_remote_post(
				$wsc_endpoint . '/api/lite/users',
				array(
					'headers' => array(
						'Content-Type' => 'application/json',
						'Authorization' => $wsc_endpoint_auth_header,
					),
					'timeout' => 15,
					'sslverify' => true,
					'body' => json_encode(array(
						'email' => sanitize_email($email),
						"base_url" => esc_url_raw(admin_url()),
						"partner" => $partner_id
					))
				)
			);

			if (is_wp_error($request)) {
				$error_message = $request->get_error_message();
				if (WP_DEBUG) {
					error_log('COMPLIANZ: cannot send email, request failed');
					if ($error_message) {
						error_log('COMPLIANZ: ' . $error_message);
					}
				}
				update_option('cmplz_wsc_error_email_not_sent', true, false);
			} else {
				$response_code = wp_remote_retrieve_response_code($request);
				if ($response_code === 200) {
					cmplz_update_option_no_hooks(cmplz_wsc::WSC_EMAIL_OPTION_KEY, $email);
					update_option('cmplz_wsc_signup_status', 'pending', false);
					update_option('cmplz_wsc_status', 'pending', false);
					update_option('cmplz_wsc_signup_date', time(), false);
					delete_option('cmplz_wsc_error_email_not_sent');
					delete_option('cmplz_wsc_onboarding_start');
				} else {
					$response_message = wp_remote_retrieve_response_message($request);
					if (WP_DEBUG) {
						error_log('COMPLIANZ: cannot send email, request failed');
						if ($response_message) {
							error_log('COMPLIANZ: ' . $response_message);
						}
					}
					update_option('cmplz_wsc_error_email_not_sent', true, false);
				}
			}
		}


		/**
		 * Handles the confirmation of email authentication for the Website Scan Feature.
		 *
		 * This function is responsible for confirming the email authentication for the Complianz plugin.
		 * It checks if the user has the necessary permissions, if the page is the Complianz page,
		 * and if the lite-user-confirmation parameter is set. It then verifies the email and token,
		 * makes a request to the WSC endpoint, and updates the necessary options accordingly.
		 * Finally, it redirects the user to the Complianz settings page.
		 *
		 * @return void
		 */
		public function confirm_email_auth(): void
		{
			if (!cmplz_user_can_manage()) {
				return;
			}

			if (!isset($_GET['page']) || $_GET['page'] !== 'complianz') {
				return;
			}

			if (!isset($_GET['lite-user-confirmation'])) {
				return;
			}

			$stored_email = cmplz_get_option(cmplz_wsc::WSC_EMAIL_OPTION_KEY);

			if (!isset($_GET['email']) || $_GET['email'] !== $stored_email) {
				update_option('cmplz_wsc_error_email_mismatch', true, false);
				if (WP_DEBUG) {
					error_log('COMPLIANZ: email does not match the stored email');
				}
				return;
			}
			if (!isset($_GET['token'])) {
				update_option('cmplz_wsc_error_missing_token', true, false);
				if (WP_DEBUG) {
					error_log('COMPLIANZ: token not found in the authentication url');
				}
				return;
			}

			$token = sanitize_text_field($_GET['token']);
			$wsc_endpoint = base64_decode(self::WSC_ENDPOINT);
			$wsc_endpoint_auth_header = base64_decode(self::WSC_ENDPOINT_AUTH_HEADER);

			$request = wp_remote_post($wsc_endpoint . '/api/lite/oauth_applications', array(
				'headers' => array(
					'Content-Type' => 'application/json',
					'Authorization' => $wsc_endpoint_auth_header,
				),
				'timeout' => 15,
				'sslverify' => true,
				'body' => json_encode(
					array(
						'email' => sanitize_title($stored_email),
						'token' => $token,
					)
				),
			));

			if (is_wp_error($request)) {
				$error_message = $request->get_error_message();
				if (WP_DEBUG) {
					error_log('COMPLIANZ: cannot confirm email, request failed');
					if ($error_message) {
						error_log('COMPLIANZ: ' . $error_message);
					}
				}
				update_option('cmplz_wsc_error_email_auth_failed', true, false);
			} else {
				$response_code = wp_remote_retrieve_response_code($request);
				if ($response_code === 201) {
					$response_body = json_decode(wp_remote_retrieve_body($request));
					if (isset($response_body->client_id) && isset($response_body->client_secret)) {
						cmplz_update_option_no_hooks(cmplz_wsc::WSC_CLIENT_ID_OPTION_KEY, $response_body->client_id);
						cmplz_update_option_no_hooks(cmplz_wsc::WSC_CLIENT_SECRET_OPTION_KEY, $response_body->client_secret);
						update_option('cmplz_wsc_signup_status', 'enabled', false);
						update_option('cmplz_wsc_status', 'enabled', false);
						update_option('cmplz_wsc_auth_completed', true, false);
						cmplz_wsc_onboarding::update_onboarding_status('terms', true);
						delete_option('cmplz_wsc_error_email_auth_failed');
						delete_option('cmplz_wsc_error_email_mismatch');
						delete_option('cmplz_wsc_error_missing_token');
						// reset the processed pages
						delete_transient('cmplz_processed_pages_list');
					} else {
						if (WP_DEBUG) {
							error_log('COMPLIANZ: cannot confirm email, client id or secret not found in response');
						}
						update_option('cmplz_wsc_error_email_auth_failed', true, false);
					}
				} else {
					if (WP_DEBUG) {
						error_log('COMPLIANZ: cannot confirm email, request failed');
					}
					update_option('cmplz_wsc_error_email_auth_failed', true, false);
				}
			}

			wp_redirect(cmplz_admin_url('#settings/settings-cd'));

			exit;
		}


		/**
		 * Retrieves the access token for the Website Scan feature.
		 *
		 * This function checks the WSC signup status and retrieves the access token
		 * if it is available. If the token is not found, it tries to retrieve a fresh one
		 * using the provided email, client ID, and client secret.
		 *
		 * @param bool $new Whether to retrieve a new token.
		 * @param bool $no_store Whether to store the token.
		 * @param array|false $client_credentials The client credentials.
		 *
		 * @return string|bool The access token if available, 'pending' if the WSC signup status is pending,
		 *                     false if the email, client ID, or client secret is not found, or false if there
		 *                     was an error retrieving the token.
		 *
		 */
		public static function get_token($new = false, $no_store = false, $client_credentials = false)
		{
			// emulating the union type  array|false $client_credentials
			if (!is_bool($new)) {
				throw new InvalidArgumentException('$new needs to be of type bool');
			}
			if (!is_bool($no_store)) {
				throw new InvalidArgumentException('$no_store needs to be of type bool');
			}
			if ($client_credentials !== false && !is_array($client_credentials)) {
				throw new InvalidArgumentException('$client_credentials must be an array or false');
			}

			// clear stored token
			if ($new) cmplz_delete_transient('cmplz_wsc_access_token');

			$token = cmplz_get_transient('cmplz_wsc_access_token');
			if ($token) {
				return $token;
			}

			//if no token found, try retrieving a fresh one
			$email = (string)cmplz_get_option(cmplz_wsc::WSC_EMAIL_OPTION_KEY);
			$client_id = (string)cmplz_get_option(cmplz_wsc::WSC_CLIENT_ID_OPTION_KEY);
			$client_secret = (string)cmplz_get_option(cmplz_wsc::WSC_CLIENT_SECRET_OPTION_KEY);

			// if client credentials are provided, use them
			if ($client_credentials) {
				$client_id = $client_credentials['client_id'];
				$client_secret = $client_credentials['client_secret'];
			} else {
				if ($email === '' || $client_id === '' || $client_secret === '') {
					// if (WP_DEBUG) {
					// 	error_log('COMPLIANZ: cannot retrieve token, email or client id or secret not found');
					// }
					return false;
				}
			}

			$wsc_endpoint = base64_decode(self::WSC_ENDPOINT);
			$wsc_endpoint_auth_header = base64_decode(self::WSC_ENDPOINT_AUTH_HEADER);

			$request = wp_remote_post(
				$wsc_endpoint . '/oauth/token',
				array(
					'headers' => array(
						'Content-Type' => 'application/json',
						'Authorization' => $wsc_endpoint_auth_header,
					),
					'timeout' => 15,
					'sslverify' => true,
					'body' => json_encode(
						array(
							'grant_type' => "client_credentials",
							"client_id" => $client_id,
							"client_secret" => $client_secret,
							"scope" => "write"
						)
					)
				)
			);

			if (!is_wp_error($request)) { // request success true

				$request = json_decode(wp_remote_retrieve_body($request));

				if (isset($request->access_token)) { // if there's an access token
					if ($no_store) return $request->access_token;

					delete_option('cmplz_wsc_error_token_api');
					update_option('cmplz_wsc_connection_updated', time(), false);

					$token = $request->access_token;
					$expires = $request->expires_in ?? 7200;
					cmplz_set_transient('cmplz_wsc_access_token', $token, $expires - 10);

					return $token;
				} else {
					if ($no_store) return false;

					update_option('cmplz_wsc_error_token_api', true, false);
					if (WP_DEBUG && $request->error) {
						error_log('COMPLIANZ: cannot retrieve token, token not found in response');
					}
					return false;
				}
			} else {
				if (!$no_store) update_option('cmplz_wsc_error_token_api', true, false);
				$error_message = $request->get_error_message();
				if (WP_DEBUG) {
					error_log('COMPLIANZ: cannot retrieve token, request failed');
					if ($error_message) {
						error_log('COMPLIANZ: ' . $error_message);
					}
				}
				return false;
			}
		}


		/**
		 * Store the consent when user signs up for the WSC Feature
		 * or when the user signs up for the newsletter
		 *
		 * The method is triggered once using the cron job during the onboarding process
		 * or using check_failed_consent_onboarding() method ($retry = true)
		 *
		 * @param string $type || Could be wsc terms, wsc newsletter 'wsc_consent' // 'newsletter_consent'
		 * @param array $posted_data
		 * @param bool $retry
		 * @param string $consent_data
		 * @return void
		 */
		public static function store_onboarding_consent(string $type, array $posted_data, bool $retry = false, string $consent_data = ''): void
		{
			// Check if the given type exists in the cons_identifiers array.
			if (!array_key_exists($type, self::CONS_IDENTIFIERS)) {
				return;
			}
			// Check if the posted_data array is empty.
			if (empty($posted_data)) {
				return;
			}

			// if it's a retry because there's an old failed store attempts
			// set the old consent
			if ($retry) {
				$consent = $consent_data;
			} else {
				// else let's create a new consent data
				// check posted data
				$email = sanitize_email($posted_data['email']);
				if (!is_email($email)) {
					return;
				}

				// Create a subject id
				$site_url = site_url();
				$encodedSiteUrl = base64_encode($site_url);
				$encodedEmail = base64_encode($email);
				$consent_subject_id = sprintf('cmplz-%s#%s', $encodedSiteUrl, $encodedEmail);

				// Check for timestamp and url
				$timestamp = isset($posted_data['timestamp']) // check if timestamp is set
					? (int)$posted_data['timestamp'] / (strlen($posted_data['timestamp']) > 10 ? 1000 : 1) // if timestamp is in milliseconds, convert to seconds
					: time(); // if $posted_data['timestamp'] is not set, use the current time

				$url = esc_url_raw($posted_data['url']) ?? site_url();

				// Generate the consent
				$consent = json_encode([
					'timestamp' => date('c', $timestamp),
					'subject' => [
						'id' => $consent_subject_id,
						'email' => $email,
					],
					'preferences' => [
						$type => true
					],
					'legal_notices' => [
						[
							'identifier' => self::CONS_IDENTIFIERS[$type] // terms or newsletter
						]
					],
					'proofs' => [
						[
							// pass all $posted_data as content
							'content' => json_encode([
								'email' => $email,
								'timestamp' => $timestamp,
								'url' => $url,
							]),
							'form' => 'complianz-onboarding__' . $type, // complianz onboarding form ??
						]
					],
				]);
			}

			// safe store the consent locally
			update_option('cmplz_' . $type . '_consentdata', $consent, false);

			$cons_endpoint = base64_decode(self::CONS_ENDPOINT);
			// Send the request
			$request = wp_remote_post(
				$cons_endpoint,
				array(
					'headers' => array(
						'Content-Type' => 'application/json',
						'ApiKey' => self::CONS_ENDPOINT_PK,
					),
					'timeout' => 15,
					'sslverify' => true,
					'body' => $consent
				)
			);

			if (is_wp_error($request)) {
				$error_message = $request->get_error_message();
				if (WP_DEBUG) {
					error_log('COMPLIANZ: cannot store consent, request failed for identifier: ' . $type);
					if ($error_message) {
						error_log('COMPLIANZ: ' . $error_message);
					}
				}
				// 	// define an error into the options
				update_option('cmplz_consent_error_timestamp_' . $type, time());
				// store the consent for the time we can resend the request
				update_option('cmplz_consent_error_consentdata_' . $type, $consent);
			} else {
				$response_code = wp_remote_retrieve_response_code($request);
				if ($response_code == 200) {
					delete_option('cmplz_consent_' . $type);
					// delete possible consent errors
					delete_option('cmplz_consent_error_timestamp_' . $type);
					delete_option('cmplz_consent_error_consentdata_' . $type);

					$body = json_decode(wp_remote_retrieve_body($request));
					// store the consent locally
					update_option('cmplz_consent_' . $type, $body);
				} else {
					$response_message = wp_remote_retrieve_response_message($request);
					if (WP_DEBUG) {
						error_log('COMPLIANZ: cannot store consent, request failed for identifier: ' . $type);
						if ($response_message) {
							error_log('COMPLIANZ: ' . $response_message);
						}
					}
					// 	// define an error into the options
					update_option('cmplz_consent_error_timestamp_' . $type, time());
					// store the consent for the time we can resend the rquest
					update_option('cmplz_consent_error_consentdata_' . $type, $consent);
				}
			}
		}


		/**
		 * Subscribes a user to the newsletter.
		 *
		 * @param string $email The email address of the user.
		 * @param bool $retry Whether to retry the subscription if it fails.
		 * @return void
		 */
		public static function newsletter_sign_up(string $email, bool $retry = false): void
		{
			$license_key = '';

			if (defined('rsssl_pro_version')) {
				$license_key = COMPLIANZ::$license->license_key();
				$license_key = COMPLIANZ::$license->maybe_decode($license_key);
			}

			$api_params = array(
				'has_premium' => defined('cmplz_premium'), // not required
				'license' => $license_key, // not required
				'email' => sanitize_email($email),
				'domain' => esc_url_raw(site_url()),
			);

			$newsletter_signup_endpoint = base64_decode(self::NEWSLETTER_SIGNUP_ENDPOINT);

			$request = wp_remote_post($newsletter_signup_endpoint, array('timeout' => 15, 'sslverify' => true, 'body' => $api_params));

			if (is_wp_error($request)) {
				update_option('cmplz_newsletter_signup_error_email', $email, false); // save the email in an option
				update_option('cmplz_newsletter_signup_error', true, false); // save the failed attempt
				update_option('cmplz_newsletter_signup_error_timestamp', time(), false); // set an error with the timestamp
				// log the error
				if (WP_DEBUG) {
					$error_message = $request->get_error_message();
					if ($error_message) {
						error_log('COMPLIANZ: ' . $error_message);
					}
				}
			} else {
				$response_code = wp_remote_retrieve_response_code($request); // 200 ok
				if ($response_code === 200) {
					// if the method is called by the cron or there's a mismatch between the emails clean the options
					if ($retry || $email !== get_option('cmplz_newsletter_signup_error_email')) {
						// remove any failed attempts
						delete_option('cmplz_newsletter_signup_error_email');
						delete_option('cmplz_newsletter_signup_error');
						delete_option('cmplz_newsletter_signup_error_timestamp');
					}
					// save the email in the options
					cmplz_update_option_no_hooks('notifications_email_address', $email); // save the email in the options
					cmplz_update_option_no_hooks('send_notifications_email', 1); // enable the notifications
					cmplz_wsc_onboarding::update_onboarding_status('newsletter', true);
				}
			}
		}


		/**
		 * Website Scan Circuit Breaker
		 *
		 * This function checks if the Website scan endpoint accepts user signups and radar scans
		 * passing auth or scanner as $service.
		 *
		 * @param string $service The service to check | signup or scanner.
		 * @return bool Returns true if the Website scan endpoint accepts user signups, false otherwise.
		 *
		 */
		public static function wsc_api_open(string $service): bool
		{
			$wsc_cb_endpoint = base64_decode(self::WSC_CB_ENDPOINT);
			$request = wp_remote_get($wsc_cb_endpoint);

			if (is_wp_error($request)) {
				// @todo add wsc_logger
				error_log('wsc_api_open: ' . $request->get_error_message());
				return false;
			}

			$service = sprintf('%s_enabled', $service);

			$response_body = json_decode(wp_remote_retrieve_body($request));

			if (isset($response_body->$service) && $response_body->$service === 'true') {
				return true;
			}

			return false;
		}

		/**
		 * Check for failed onboarding consent store attempts
		 * If there's a failed attempt, try to store it again
		 *
		 *
		 * @return void
		 */
		public function check_failed_consent_onboarding(): void
		{
			$identifiers = self::CONS_IDENTIFIERS;

			foreach ($identifiers as $key => $type) {
				// check for the errors
				$error_timestamp = get_option('cmplz_consent_error_timestamp_' . $key, false);
				// store the consent for the time we can resend the rquest
				$error_consentdata = get_option('cmplz_consent_error_consentdata_' . $key, false);

				if ($error_consentdata && $error_timestamp < time() - 68400) {
					$this->store_onboarding_consent($key, [], true, $error_consentdata);
				}
			}
		}


		/**
		 * Check for failed newsletter signups
		 * If there's a failed attempt, try to sign up again
		 *
		 * @return bool
		 */
		public function check_failed_newsletter_signup(): bool
		{
			$failed = get_option('cmplz_newsletter_signup_error');
			$timestamp = get_option('cmplz_newsletter_signup_error_timestamp');
			$email = get_option('cmplz_newsletter_signup_error_email');
			if ($failed && $timestamp && $email) {
				// check if the error is older than 24 hours
				if ($timestamp < time() - 86400) {
					// try to sign up again
					self::newsletter_sign_up($email, true);
				}
			}
			return true;
		}

		/**
		 * Checks if the user is authenticated.
		 *
		 * This function retrieves the 'cmplz_wsc_auth_completed' option to determine
		 * if the user has completed the onboarding/authentication.
		 *
		 * @return bool True if authenticated, false otherwise.
		 */
		public static function wsc_is_authenticated(): bool
		{
			return get_option('cmplz_wsc_auth_completed', false);
		}
	}
}

Youez - 2016 - github.com/yon3zu
LinuXploit