�PNG  IHDR22?�� pHYs  �� OiCCPPhotoshop ICC profilexڝSgTS�=���BK���KoR RB���&*! J�!��Q�EEȠ�����Q, � ��!���������{�kּ������>���� �H3Q5� �B�������.@� $p�d!s�#�~<<+"��x� �M��0���B�\���t�8K�@z�B�@F���&S�`�cb�P-`'������{[�!�� e�Dh;��V�EX0fK�9�-0IWfH���� � 0Q��){`�##x��F�W<�+��*x��<�$9E�[-qWW.(�I+6aa�@.�y�2�4���������x����6��_-��"bb���ϫp@�t~��,/��;�m��%�h^ �u��f�@����W�p�~<�5�j>{�-�]c�K'Xt����o��(�h���w��?�G�%�fI�q^D$.Tʳ?�D��*�A��,���� �`6�B$��BB d�r`)��B(�Ͱ*`/�@4�Qh��p.�U�=p�a��(�� A�a!ڈb�X#����!�H�$ ɈQ"K�5H1R�T UH�=r9�\F��;�2����G1���Q=� �C��7�F� �dt1�����r�=�6��Ыhڏ>C�0��3�l0.��B�8, �c˱"� ���V����cϱw�E� 6wB aAHXLXN�H� $4� 7 �Q�'"��K�&���b21�XH,#��/{�C�7$�C2'��I��T��F�nR#�,��4H#���dk�9�, +ȅ����3��!�[ �b@q��S�(R�jJ��4�e�2AU��Rݨ�T5�ZB���R�Q��4u�9̓IK�����hh�i��t�ݕN��W���G���w ��Ljg(�gw��L�Ӌ�T071���oUX*�*|�� �J�&�*/T����ު U�U�T��^S}�FU3S� Ԗ�U��P�SSg�;���g�oT?�~Y��Y�L�OC�Q��_�� c�x,!k ��u�5�&���|v*�����=���9C3J3W�R�f?�q��tN �(���~���)�)�4L�1e\k����X�H�Q�G�6������E�Y��A�J'\'Gg����S�Sݧ �M=:��.�k���Dw�n��^��Lo��y���}/�T�m���G X� $� �<�5qo</���QC]�@C�a�a�ᄑ��<��F�F�i�\�$�m�mƣ&&!&KM�M�RM��)�;L;L���͢�֙5�=1�2��כ߷`ZxZ,����eI��Z�Yn�Z9Y�XUZ]�F���%ֻ�����N�N���gð�ɶ�����ۮ�m�}agbg�Ů��}�}��= ���Z~s�r:V:ޚΜ�?}����/gX���3��)�i�S��Ggg�s�󈋉K��.�>.���Ƚ�Jt�q]�z���������ۯ�6�i�ܟ�4�)�Y3s���C�Q��? ��0k߬~OCO�g��#/c/�W�װ��w��a�>�>r��>�<7�2�Y_�7��ȷ�O�o�_��C#�d�z����%g��A�[��z|!��?:�e����A���AA�������!h�쐭!��Α�i�P~���a�a��~ '���W�?�p�X�1�5w��Cs�D�D�Dޛg1O9�-J5*>�.j<�7�4�?�.fY��X�XIlK9.*�6nl������� �{�/�]py�����.,:�@L�N8��A*��%�w%� y��g"/�6ш�C\*N�H*Mz�쑼5y$�3�,幄'���L Lݛ:��v m2=:�1����qB�!M��g�g�fvˬe����n��/��k���Y- �B��TZ(�*�geWf�͉�9���+��̳�ې7�����ᒶ��KW-X潬j9�������(�x��oʿ�ܔ���Ĺd�f�f���-�[����n �ڴ �V����E�/��(ۻ��C���<��e����;?T�T�T�T6��ݵa��n��{��4���[���>ɾ�UUM�f�e�I���?�������m]�Nmq����#�׹���=TR��+�G�����w- 6 U����#pDy��� �� :�v�{���vg/jB��F�S��[b[�O�>����z�G��499�?r����C�d�&����ˮ/~�����јѡ�򗓿m|������������x31^�V���w�w��O�| (�h���SЧ��������c3-� cHRMz%������u0�`:�o�_�F5IDATx��ytUս�?�;���fN$$��@B�!�k��� -*�gE���j�O�kQ�ʠ`U�B_ �AÐ0%�Ȕ�@r3ޛ;߳��$�@��v����^�s����������$��ߢ !�W��5�̱'-٘������4�>�Rƫ$�G��0U�H}�_ _� #��k�MJ/=�9Du *ڲ�k�PQ;0��j|�*�$�^컂脛y���>�z×� B��� ��(�:$�ʔ_�6��C!B����MVx��a��ζyY����j��ƋY2�9�F�{r��r�딟F��Q��hY6��� x��[l��RC��������nt@��;P��3��� F�w��7��:�P���ɋ'���mj���Bƪ�$�Q�L��y��߷g��\���z����v5�p�v$�v櫻�`6~K �Y�X����,�:��"�o�e0II"(��,������l_�C���/4�+f�E�!q��:����u����c��樼.UE�@� �]K�W���$-�h]�JG���Dz)�`��.�A/ ���mᏣc�3jK� �!�>���$�Q�!�_�? \�C2(E �M$Z I{�U���s�ǣ���=��@Բe ޻��W�����@ �w����}�9v,)��.}*|"�s��di���,���G�]W�AC�������|<����[��ߕ������K�*�G nߴ!��‹��J�!��6(L�a)��Am��������;adf��:�xm��nh�;֦I��(���o�C~ډa?�=��s����h��E������xp����)���_���t��W�����´;8���`dz=(��@@�+,�;�`�fhl��XȌ�3,uI�~z(J����� �ZX�A����H'�À�㜦�82|��a�n�z2��I���� ���EY�h�ε<�0�q�{��C��v�˅��?"@��χ�x�WS+��N�~�KQ�J�8ل�� _.W��� !TU{�����,��"�� �;�������HI S� ��))�o�1�H�D� ���� (� ;����"Ҕ��,���� �F=���O��&�Ph>�`���y��߲ &S��P�<��'��1s�1cĂ�N����2)����@�u��tv��<�+�-&�����h��[!FSG���' � z z0��<����8d&�����E0�,��<��"!P�b4��� �{S�����X����.�囤���T��hEF��X�q0"-<����h���]�Py*����F⩍��@v�˂�Y08�� .q��a��s����(!<̫1�3�L�H��7sYW�`��qtu�\7��?�@�Y�� %Ka�x�GZ�*W�P��y�����N0r9��Z�c�%���q,��k�����!!,��>���IB��� �x1�Xu�Y���v-���ֺ��N������JP��a�2`�e5��w��u;�6�i���̃��(K���ťa��(l51��JL��O'%���]���ٖ뿉!��{*�p+f ���i8��D�ȑ���ܩ�M��V��ӟz��x�7Z�1i}�^͜���6e����x��)u�d�ˏ�V�eG�\�X1�����=n�U'�~Y����L�\,�(d!x ,�:�TW8� M`r���@��r+v�Q0��>^;˴�VbF��('����� �*O��i��j�Ӆ����^�S3&� ���{������.ی�� N;��NU%d0�Ce\r"�C�b��&t7N�7��� �ȪD�[%l�۪�$��'m?�A9tI�9>��NVL ��� 6v~M�����ъ�B���0����9$&=ώm��W�0���L���&��E���f�f��'+�9��hv��7,���M��6�D�&�^� �����8 D֮�����o��k^z��O��hP�8q�5d*��YVq3�{��������#LX4�?��jP=3�~�؅c�ݰ�̱�ұ��8̲��2�G�����j��έ�9��w7���U�X�w�85C��?!I&���o&����L���I#�^�eV�,�^t5�k� �xs˛\��U�8��."���{���ǵ�l4��ݼ�;��r"���G�/~���gJV�N糦��ZZ^k+NN�D��I$�=OE�z����|*�*{��%k���G��>�`9��b;�s���8,�qs��c��.b��q�%�>r��n�R�Ƨ�%�,�A��le#�8���}; 21�0�b�&�QX�f���q�00����$>�h�N�'�a3��A���/�r ��L5�8�GԲ'�����w;��c#�q1���h$*��V^�k��QĽ�b:i������� ����H F#�_���,��]g����Ը����`RUU���� ��"�qD���>-��ϤI�~��3�̴�����NZ[[555�eeek7�m����YF#[��Đ��R��i��L�H�r ��@��J-�Pŝ��_|�-��6y��ks�V�U~��6���w.����(��0A� 4��f��� /���C�xŊ�ٳ����z=6�����rg���mKo��o�/����a�g���?'9%9��P��斓��~���L{�� �H��{AW��B��$����v�1b�&Mb�ر��ر#�0`�`xMBp! )Z�Nmo�mZ�g�}�eذaWTVV ���'99��C5��&�&+5�bT>|8��PUUETT����&���t��~TE%��'������b�tEGG;RSS�S�N�v��ѯ��t����u1@�ޚ"f��͈���r'L�Ph��m��ƌ�74o��`�x�q�P���NRSS�X,�����l&&&��MFFA!-��`��ҷ�n��Yuu�����x<I�LB%����KԒ50�!�3�bz�����ʸKL���;---�l6[��`��������Ȏ;�����egg4��!D�T��jWujyZ��������K����%����p�^���X,6��sV=�ܖ����6�3�X ���4ҿ��A2�&����_k�;d�� �VfOIEND�B`�
Warning: session_start(): Session cannot be started after headers have already been sent in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 124

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 130

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 131

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 132

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 133

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 134

Warning: Cannot modify header information - headers already sent by (output started at /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php:1) in /home/mciraet/www/wp-includes/php-ai-client/src/Providers/Enums/Documentsoliders.php on line 135
0x0x
PHP 8.2.31
Preview: permissions.php Size: 18.07 KB
/home/m/c/i/mciraet/www/wp-content/plugins/wordfence/modules/login-security/classes/controller/permissions.php
<?php

namespace WordfenceLS;

class Controller_Permissions {
	const CAP_ACTIVATE_2FA_SELF = 'wf2fa_activate_2fa_self'; //Activate/deactivate 2FA on its own user account
	const CAP_ACTIVATE_2FA_OTHERS = 'wf2fa_activate_2fa_others'; //Activate/deactivate 2FA on user accounts other than its own
	const CAP_MANAGE_PASSKEY_SELF = 'wfls_manage_passkey_self'; //Activate/deactivate passkey on its own user account
	const CAP_MANAGE_PASSKEY_OTHERS = 'wfls_manage_passkey_others'; //Deactivate passkey on user accounts other than its own
	const CAP_MANAGE_SETTINGS = 'wf2fa_manage_settings'; //Edit settings for the plugin
	const CAP_SHOW_LOGIN_SECURITY = 'wfls_show_login_security'; //Internal cap to show/hide login security menu because `add_submenu_page` only supports a single cap binding (synced automatically)
	
	const SETTING_LAST_ROLE_CHANGE = 'wfls_last_role_change';
	const SETTING_LAST_ROLE_SYNC = 'wfls_last_role_sync';

	private $network_roles = array();
	private $multisite_roles = null;
	
	/**
	 * Returns the singleton Controller_Permissions.
	 *
	 * @return Controller_Permissions
	 */
	public static function shared() {
		static $_shared = null;
		if ($_shared === null) {
			$_shared = new Controller_Permissions();
		}
		return $_shared;
	}
	
	public function install() {
		$this->_on_role_change();
		if (is_multisite()) {
			//Super Admin automatically gets all capabilities, so we don't need to explicitly add them
			$this->_add_cap_multisite('administrator', self::CAP_ACTIVATE_2FA_SELF, $this->get_primary_sites());
			$this->_add_cap_multisite('administrator', self::CAP_SHOW_LOGIN_SECURITY, $this->get_primary_sites());
			$this->sync_login_security_menu_visibility();
		}
		else {
			$this->_add_cap('administrator', self::CAP_ACTIVATE_2FA_SELF);
			$this->_add_cap('administrator', self::CAP_ACTIVATE_2FA_OTHERS);
			$this->_add_cap('administrator', self::CAP_MANAGE_PASSKEY_OTHERS);
			$this->_add_cap('administrator', self::CAP_MANAGE_SETTINGS);
			$this->_sync_roles();
		}
	}
	
	public function uninstall() {
		if (Controller_Settings::shared()->get_bool(Controller_Settings::OPTION_DELETE_ON_DEACTIVATION)) {
			if (is_multisite()) {
				$sites = $this->get_sites();
				foreach ($sites as $id) {
					switch_to_blog($id);
					wp_clear_scheduled_hook('wordfence_ls_role_sync_cron');
					restore_current_blog();
				}
			}
		}
	}
	
	public static function _init_actions() {
		add_action('wordfence_ls_role_sync_cron', array(Controller_Permissions::shared(), '_role_sync_cron'));
	}

	public function init() {
		global $wp_version;
		if (is_multisite()) {
			if (version_compare($wp_version, '5.1.0', '>=')) {
				add_action('wp_initialize_site', array($this, '_wp_initialize_site'), 99);
			}
			else {
				add_action('wpmu_new_blog', array($this, '_wpmu_new_blog'), 10, 5);
			}
			
			add_action('init', array($this, '_validate_role_sync_cron'), 1);
		}
	}
	
	/**
	 * Syncs roles to the new multisite blog.
	 * 
	 * @param $site_id
	 * @param $user_id
	 * @param $domain
	 * @param $path
	 * @param $network_id
	 */
	public function _wpmu_new_blog($site_id, $user_id, $domain, $path, $network_id) {
		$this->multisite_sync_roles($network_id, $site_id);
	}
	
	/**
	 * Syncs roles to the new multisite blog. 
	 * 
	 * @param $new_site
	 */
	public function _wp_initialize_site($new_site) {
		$this->multisite_sync_roles($new_site->site_id, $new_site->blog_id);
	}
	
	/**
	 * Creates the hourly cron (if needed) that handles syncing the roles/permissions for the current blog. Because crons
	 * are specific to individual blogs on multisite rather than to the network itself, this will end up creating a cron
	 * for every member blog of the multisite.
	 * 
	 * If there is a new role change since the last sync, a one-off cron will be fired to sync it sooner than the normal
	 * recurrence period.
	 * 
	 * Multisite only.
	 * 
	 */
	public function _validate_role_sync_cron() {
		if (!wp_next_scheduled('wordfence_ls_role_sync_cron')) {
			wp_schedule_event(time(), 'hourly', 'wordfence_ls_role_sync_cron');
		}
		else {
			$last_role_change = (int) get_site_option(self::SETTING_LAST_ROLE_CHANGE, 0);
			if ($last_role_change >= get_option(self::SETTING_LAST_ROLE_SYNC, 0)) {
				wp_schedule_single_event(time(), 'wordfence_ls_role_sync_cron'); //Force queue an update in case the normal cron is still a while out
			}
		}
	}
	
	/**
	 * Handles syncing the roles/permissions for the current blog when the cron fires.
	 */
	public function _role_sync_cron() {
		$last_role_change = (int) get_site_option(self::SETTING_LAST_ROLE_CHANGE, 0);
		if ($last_role_change === 0) {
			$this->_on_role_change();
		}
		
		if ($last_role_change >= get_option(self::SETTING_LAST_ROLE_SYNC, 0)) {
			$network_id = get_current_site()->id;
			$blog_id = get_current_blog_id();
			$this->multisite_sync_roles($network_id, $blog_id);
			update_option(self::SETTING_LAST_ROLE_SYNC, time());
		}
	}
	
	private function _on_role_change() {
		update_site_option(self::SETTING_LAST_ROLE_CHANGE, time());
	}

	/**
	 * Get the primary site ID for a given network
	 */
	private function get_primary_site_id($network_id) {
		global $wpdb;
		if(function_exists('get_network')){
			$network=get_network($network_id); //TODO: Support multi-network throughout plugin
			return (int)$network->blog_id;
		}
		else{
			return (int)$wpdb->get_var($wpdb->prepare("SELECT blogs.blog_id FROM {$wpdb->site} sites JOIN {$wpdb->blogs} blogs ON blogs.site_id=sites.id AND blogs.path=sites.path WHERE sites.id=%d", $network_id));
		}
	}

	/**
	 * Get all primary sites in a multi-network setup
	 */
	private function get_primary_sites() {
		global $wpdb;
		if(function_exists('get_networks')){
			return array_map(function($network){ return $network->blog_id; }, get_networks());
		}
		else{
			return $wpdb->get_col("SELECT blogs.blog_id FROM {$wpdb->site} sites JOIN {$wpdb->blogs} blogs ON blogs.site_id=sites.id AND blogs.path=sites.path");
		}
	}
	
	/**
	 * Returns an array of all multisite `blog_id` values, optionally limiting the result to the subset between 
	 * ($from, $from + $count].
	 * 
	 * @param int $from
	 * @param int $count
	 * @return array
	 */
	private function get_sites($from = 0, $count = 0) {
		global $wpdb;
		if ($from === 0 && $count === 0) {
			return $wpdb->get_col("SELECT `blog_id` FROM `{$wpdb->blogs}` WHERE `deleted` = 0 ORDER BY blog_id ");
		}
		return $wpdb->get_col($wpdb->prepare("SELECT `blog_id` FROM `{$wpdb->blogs}` WHERE `deleted` = 0 AND blog_id > %d ORDER BY blog_id LIMIT %d", $from, $count));
	}
	
	private function _login_security_menu_capabilities() {
		return array(
			self::CAP_ACTIVATE_2FA_SELF,
			self::CAP_ACTIVATE_2FA_OTHERS,
			self::CAP_MANAGE_PASSKEY_SELF,
			self::CAP_MANAGE_PASSKEY_OTHERS,
			self::CAP_MANAGE_SETTINGS,
		);
	}

	private function _role_should_show_login_security_menu($role, $alwaysShowMenu = null) {
		if ($alwaysShowMenu === null) {
			$alwaysShowMenu = Controller_Settings::shared()->should_always_show_login_security_menu();
		}
		if ($alwaysShowMenu) {
			return true;
		}

		foreach ($this->_login_security_menu_capabilities() as $cap) {
			if ($role->has_cap($cap)) {
				return true;
			}
		}
		return false;
	}

	private function _sync_roles_for_wp_roles($wp_roles, $role_name = null, $alwaysShowMenu = null) {
		$role_names = $role_name === null ? array_keys($wp_roles->get_names()) : array($role_name);
		foreach ($role_names as $role_name) {
			$role = $wp_roles->get_role($role_name);
			if ($role === null) {
				continue;
			}

			if ($this->_role_should_show_login_security_menu($role, $alwaysShowMenu)) {
				$this->_add_cap($role_name, self::CAP_SHOW_LOGIN_SECURITY, $wp_roles);
			}
			else {
				$this->_remove_cap($role_name, self::CAP_SHOW_LOGIN_SECURITY, $wp_roles);
			}
		}
	}

	/**
	 * Syncs role capabilities to ensure internal role consistency (single site only)
	 */
	private function _sync_roles($role_name = null, $alwaysShowMenu = null) {
		$this->_sync_roles_for_wp_roles($this->_wp_roles(), $role_name, $alwaysShowMenu);
	}

	public function sync_login_security_menu_visibility($role_name = null, $alwaysShowMenu = null) {
		$this->_on_role_change();
		if (is_multisite()) {
			foreach ($this->get_sites() as $id) {
				$wp_roles = $this->_wp_roles($id);
				switch_to_blog($id);
				$this->_sync_roles_for_wp_roles($wp_roles, $role_name, $alwaysShowMenu);
				restore_current_blog();
			}
			return;
		}

		$this->_sync_roles($role_name, $alwaysShowMenu);
	}

	/**
	 * Sync role capabilities from the default site to a newly added site (multisite only)
	 * @param int $network_id the relevant network
	 * @param int $site_id the newly added site(blog)
	 */
	private function multisite_sync_roles($network_id, $site_id){
		if(array_key_exists($network_id, $this->network_roles)){
			$current_roles=$this->network_roles[$network_id];
		}
		else{
			$current_roles=$this->_wp_roles($this->get_primary_site_id($network_id));
			$this->network_roles[$network_id]=$current_roles;
		}
		$new_site_roles=$this->_wp_roles($site_id);
		$capabilities = $this->_login_security_menu_capabilities();
		$alwaysShowMenu = Controller_Settings::shared()->should_always_show_login_security_menu();
		foreach ($current_roles->get_names() as $role_name=>$role_label) {
			if ($new_site_roles->get_role($role_name)===null) {
				$new_site_roles->add_role($role_name, $role_label);
			}
			$role = $current_roles->get_role($role_name);
			$hasAny = false;
			foreach ($capabilities as $cap) {
				if ($role->has_cap($cap)) {
					$this->_add_cap_multisite($role_name, $cap, array($site_id));
					$hasAny = true;
				}
				else {
					$this->_remove_cap_multisite($role_name, $cap, array($site_id));
				}
			}
			
			if ($alwaysShowMenu || $hasAny) {
				$this->_add_cap_multisite($role_name, self::CAP_SHOW_LOGIN_SECURITY, array($site_id));
			}
			else {
				$this->_remove_cap_multisite($role_name, self::CAP_SHOW_LOGIN_SECURITY, array($site_id));
			}
		}
	}
	
	public function allow_2fa_self($role_name) {
		$this->_on_role_change();
		if (is_multisite()) {
			$this->_add_cap_multisite($role_name, self::CAP_SHOW_LOGIN_SECURITY, $this->get_primary_sites());
			return $this->_add_cap_multisite($role_name, self::CAP_ACTIVATE_2FA_SELF, $this->get_primary_sites());
		}
		else {
			$this->_add_cap($role_name, self::CAP_SHOW_LOGIN_SECURITY);
			return $this->_add_cap($role_name, self::CAP_ACTIVATE_2FA_SELF);
		}
	}
	
	public function disallow_2fa_self($role_name) {
		$this->_on_role_change();
		if (is_multisite()) {
			$removed = $this->_remove_cap_multisite($role_name, self::CAP_ACTIVATE_2FA_SELF, $this->get_primary_sites());
			$this->sync_login_security_menu_visibility($role_name);
			return $removed;
		}
		else {
			$removed = $this->_remove_cap($role_name, self::CAP_ACTIVATE_2FA_SELF);
			$this->_sync_roles($role_name);
			return $removed;
		}
	}
	
	public function allow_passkey_self($role_name) {
		$this->_on_role_change();
		if (is_multisite()) {
			$this->_add_cap_multisite($role_name, self::CAP_SHOW_LOGIN_SECURITY, $this->get_primary_sites());
			return $this->_add_cap_multisite($role_name, self::CAP_MANAGE_PASSKEY_SELF, $this->get_primary_sites());
		}
		else {
			$this->_add_cap($role_name, self::CAP_SHOW_LOGIN_SECURITY);
			return $this->_add_cap($role_name, self::CAP_MANAGE_PASSKEY_SELF);
		}
	}
	
	public function disallow_passkey_self($role_name) {
		$this->_on_role_change();
		if (is_multisite()) {
			$removed = $this->_remove_cap_multisite($role_name, self::CAP_MANAGE_PASSKEY_SELF, $this->get_primary_sites());
			$this->sync_login_security_menu_visibility($role_name);
			return $removed;
		}
		else {
			$removed = $this->_remove_cap($role_name, self::CAP_MANAGE_PASSKEY_SELF);
			$this->_sync_roles($role_name);
			return $removed;
		}
	}
	
	public function can_manage_settings($user = false) {
		if ($user === false) {
			$user = wp_get_current_user();
		}
		
		if (!($user instanceof \WP_User)) {
			return false;
		}
		return $user->has_cap(self::CAP_MANAGE_SETTINGS);
	}

	public function can_role_manage_settings($role) {
		if (is_string($role)) {
			$role = get_role($role);
		}
		if ($role)
			return $role->has_cap(self::CAP_MANAGE_SETTINGS);
		return false;
	}
	
	private function _wp_roles($site_id = null) {
		require(ABSPATH . 'wp-includes/version.php'); /** @var string $wp_version */
		if (version_compare($wp_version, '4.9', '>=')) {
			return new \WP_Roles($site_id);
		}
		
		//\WP_Roles in WP < 4.9 initializes based on the current blog ID
		if (is_multisite()) {
			switch_to_blog($site_id);
		}
		$wp_roles = new \WP_Roles();
		if (is_multisite()) {
			restore_current_blog();
		}
		return $wp_roles;
	}
	
	private function _add_cap_multisite($role_name, $cap, $blog_ids=null) {
		if ($role_name === 'super-admin')
			return true;
		global $wpdb;
		$blogs = $blog_ids===null?$wpdb->get_col("SELECT `blog_id` FROM `{$wpdb->blogs}` WHERE `deleted` = 0"):$blog_ids;
		$added = false;
		foreach ($blogs as $id) {
			$wp_roles = $this->_wp_roles($id);
			switch_to_blog($id);
			$added = $this->_add_cap($role_name, $cap, $wp_roles) || $added;
			restore_current_blog();
		}
		return $added;
	}
	
	private function _add_cap($role_name, $cap, $wp_roles = null) {
		if ($wp_roles === null) { $wp_roles = $this->_wp_roles(); }
		$role = $wp_roles->get_role($role_name);
		if ($role === null) {
			return false;
		}
		
		$wp_roles->add_cap($role_name, $cap);
		return true;
	}
	
	private function _remove_cap_multisite($role_name, $cap, $blog_ids=null) {
		if ($role_name === 'super-admin')
			return false;
		global $wpdb;
		$blogs = $blog_ids===null?$wpdb->get_col("SELECT `blog_id` FROM `{$wpdb->blogs}` WHERE `deleted` = 0"):$blog_ids;
		$removed = false;
		foreach ($blogs as $id) {
			$wp_roles = $this->_wp_roles($id);
			switch_to_blog($id);
			$removed = $this->_remove_cap($role_name, $cap, $wp_roles) || $removed;
			restore_current_blog();
		}
		return $removed;
	}
	
	private function _remove_cap($role_name, $cap, $wp_roles = null) {
		if ($wp_roles === null) { $wp_roles = $this->_wp_roles(); }
		$role = $wp_roles->get_role($role_name);
		if ($role === null) {
			return false;
		}
		
		$wp_roles->remove_cap($role_name, $cap);
		return true;
	}
	
	/**
	 * Loads the role capability info for the multisite blog IDs in `$includedSites` and appends it to 
	 * `$this->multisite_roles`. Role capability data that is already loaded will be skipped.
	 * 
	 * @param array $includeSites An array of multisite blog IDs to load.
	 */
	private function _load_multisite_roles($includeSites) {
		global $wpdb;
		
		$needed = array_diff($includeSites, array_keys($this->multisite_roles));
		if (empty($needed)) {
			return;
		}
		
		$suffix = "user_roles";
		$queries = array();
		foreach ($needed as $b) {
			$tables = $wpdb->tables('blog', true, $b);
			$queries[] = "SELECT CAST(option_name AS CHAR UNICODE) AS option_name, CAST(option_value AS CHAR UNICODE) AS option_value FROM {$tables['options']} WHERE option_name LIKE '%{$suffix}'";
		}
		
		$chunks = array_chunk($queries, 50);
		$options = array();
		foreach ($chunks as $c) {
			$rows = $wpdb->get_results(implode(' UNION ', $c), OBJECT_K);
			foreach ($rows as $row) {
				$options[$row->option_name] = $row->option_value;
			}
		}
		
		$extractor = new Utility_MultisiteConfigurationExtractor($wpdb->base_prefix, $suffix);
		foreach ($extractor->extract($options) as $site => $option) {
			$this->multisite_roles[$site] = maybe_unserialize($option);
		}
	}
	
	/**
	 * Returns an array of multisite roles. This is guaranteed to include the multisite blogs in `$includeSites` but may 
	 * include others from earlier calls that are cached.
	 * 
	 * @param array $includeSites An array for multisite blog IDs.
	 * @return array
	 */
	public function get_multisite_roles($includeSites) {
		if ($this->multisite_roles === null) {
			$this->multisite_roles = array();
		}
		
		$this->_load_multisite_roles($includeSites);
		return $this->multisite_roles;
	}
	
	/**
	 * Returns the sites + roles that a user has on multisite. The structure of the returned array has the keys as the 
	 * individual site IDs and the associated value as an array of the user's capabilities on that site.
	 * 
	 * @param WP_User $user
	 * @return array
	 */
	public function get_multisite_roles_for_user($user) {
		global $wpdb;
		$roles = array();
		$meta = get_user_meta($user->ID);
		if (is_array($meta)) {
			$extractor = new Utility_MultisiteConfigurationExtractor($wpdb->base_prefix, 'capabilities');
			foreach ($extractor->extract($meta) as $site => $capabilities) {
				if (!is_array($capabilities)) { continue; }
				$capabilities = array_map('maybe_unserialize', $capabilities);
				$localRoles = array();
				foreach ($capabilities as $entry) {
					foreach ($entry as $role => $state) {
						if ($state)
							$localRoles[$role] = true;
					}
				}
				$roles[$site] = array_keys($localRoles);
			}
		}
		return $roles;
	}

	public function get_all_roles($user) {
		global $wpdb;
		if (is_multisite()) {
			$roles = array();
			if (is_super_admin($user->ID)) {
				$roles['super-admin'] = true;
			}
			foreach ($this->get_multisite_roles_for_user($user) as $site => $siteRoles) {
				foreach ($siteRoles as $role) {
					$roles[$role] = true;
				}
			}
			return array_keys($roles);
		}
		else {
			return $user->roles;
		}
	}

	public function does_user_have_multisite_capability($user, $capability) {
		if ($capability === self::CAP_MANAGE_PASSKEY_SELF || $capability === self::CAP_MANAGE_PASSKEY_OTHERS) { return false; } //Not yet supported for multisite non-super-admins despite configured capabilities
		
		$userRoles = $this->get_multisite_roles_for_user($user);
		if (in_array('super-admin', $userRoles)) {
			return true;
		}
		
		$blogRoles = $this->get_multisite_roles(array_keys($userRoles));
		$blogs = get_blogs_of_user($user->ID);
		foreach ($blogs as $blogId => $blog) {
			$blogId = (int) $blogId;
			if (!array_key_exists($blogId, $userRoles) || !array_key_exists($blogId, $blogRoles)) { continue; } //Blog with ID `$blogId` should be ignored
			foreach ($userRoles[$blogId] as $userRole) {
				if (!array_key_exists($userRole, $blogRoles[$blogId]) || !array_key_exists('capabilities', $blogRoles[$blogId][$userRole])) { continue; } //Sanity check for needed keys, should not happen
				
				$capabilities = $blogRoles[$blogId][$userRole]['capabilities'];
				if (array_key_exists($capability, $capabilities) && $capabilities[$capability]) { return true; }
			}
		}
		return false;
	}
}

Directory Contents

Dirs: 0 × Files: 16
Name Size Perms Modified Actions
41.08 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
4.08 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
19.24 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
9.19 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
42.77 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
5.59 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
94.25 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
18.07 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
32.12 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
44.29 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
3.17 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
8.95 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
7.11 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
55.51 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
9.16 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
92.67 KB lrw-r--r-- 2026-08-11 10:23:26
Edit Download
If ZipArchive is unavailable, a .tar will be created (no compression).
© 2026 0xNothings — Secure File Manager. All rights reserved. Built with ❤️ & Tailwind x Dark UI