1(function($){ 2 $(function(){ 3 4 if(undefined === $.cookie) { 5 throw new Error('AI Core IP Auth requires the jquery cookie plugin.'); 6 } 7 8 /** 9 * Check if user has any WordPress login cookies 10 * WP login cookies are named like: wordpress_logged_in_[hash] 11 */ 12 function hasWPLoginCookie() { 13 var allCookies = $.cookie(); 14 for (var name in allCookies) { 15 if (allCookies.hasOwnProperty(name) && name.indexOf('wordpress_logged_in_') === 0) { 16 return true; 17 } 18 } 19 return false; 20 } 21 22 /** 23 * Check if the session validity cookie exists 24 * This cookie is set with PHP session lifetime and expires when the session expires 25 */ 26 function hasSessionValidCookie() { 27 return !!$.cookie(AICoreIPAuth.session_valid_cookie_name); 28 } 29 30 // If user is logged into WordPress normally (not via IP auth), no need to do IP authentication 31 // We check for WP cookie WITHOUT cachebuster - if they have both, they were IP authenticated 32 var hasCachebusterCookie = $.cookie(AICoreIPAuth.cachebuster_cookie_name); 33 34 if (hasWPLoginCookie() && !hasCachebusterCookie) { 35 return; 36 } 37 38 var hasIpCheckedCookie = $.cookie(AICoreIPAuth.ip_checked_cookie_name); 39 40 /** 41 * Detect stale session for previously authenticated users. 42 * This addresses an issue (particularly in Chrome) where the browser holds onto 43 * the cachebuster cookie after the WP/PHP session expires, preventing re-authentication. 44 * 45 * Only re-authenticate users who had the cachebuster cookie (previously authenticated). 46 * Users with only ip_checked_cookie failed authentication and should NOT be re-checked 47 * to avoid unnecessary API load. 48 * 49 * For IP-authenticated users, we check the session_valid_cookie (set by PHP with session lifetime) 50 * rather than the WP login cookie, since some sites don't create WP users for IP auth. 51 */ 52 if (hasCachebusterCookie && !hasSessionValidCookie()) { 53 // Clear only the cachebuster cookie to allow re-authentication 54 $.removeCookie(AICoreIPAuth.cachebuster_cookie_name, { path: '/' }); 55 hasCachebusterCookie = false; 56 } 57 58 //if the cachebuster cookie is already present (e.g., the user is logged-in), or we've already checked the ip, abort 59 if(hasCachebusterCookie || hasIpCheckedCookie) { 60 return; 61 } 62 63 64 //parse redirect_to from URL 65 function getRedirectTo() { 66 var params = new URLSearchParams(window.location.search); 67 return params.get('redirect_to'); 68 } 69 70 //check the ip against core to see if this ip has any relevant permissions 71 var data = { "action" : AICoreIPAuth.action}; 72 data[AICoreIPAuth.nonce.name] = AICoreIPAuth.nonce.value; 73 74 $.post(AICoreIPAuth.ajax_url, data, function(response) { 75 76 if(! response.success) { 77 console.error('AI Core IP Auth: Empty or invalid response!', response); 78 return; 79 } 80 81 console.info('IP (' + response.data.ip + ') Authenticated? ' + response.data.has_permissions); 82 83 if(response.data.has_permissions === true) { 84 $('body').append(response.data.notice); 85 86 setTimeout(function(){ 87 var redirectTo = getRedirectTo(); 88 if (redirectTo) { 89 window.location.href = redirectTo; 90 } else { 91 window.location.reload(); 92 } 93 }, 1500); 94 } 95 96 }).fail(function(jqXHR, textStatus, errorThrown) { 97 console.error('AI Core IP Auth: AJAX request failed -', textStatus, errorThrown); 98 }); 99 }); 100})(jQuery);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.