Conversation
- Introduced new REST API routes for user authentication: `/auth/login`, `/auth/refresh`, and `/auth/logout`. - Updated permission callbacks for various existing routes to use more specific permission checks. - Enhanced author detail retrieval to include user metadata conditionally based on permissions. - Improved response handling in course and quiz endpoints to ensure proper data structure and access control.
- Introduced new methods for processing authenticated read, write, and delete requests, ensuring that API key permissions are validated alongside user authentication. - Refactored the existing process_api_request method to delegate permission checks to the new methods, improving code clarity and maintainability. - Updated documentation to reflect changes in permission handling and method responsibilities.
- Updated permission callbacks for login, refresh, and logout routes to use a default true return value, streamlining access control. - Introduced new methods in RestAuth class to determine route types (login, refresh, logout) for better clarity and maintainability. - Enhanced documentation to reflect the changes in permission handling and route identification.
- Changed permission checks in the RestAuth class from 'administrator' to 'manage_options' for generating and revoking API keys. - This adjustment aligns permission handling with WordPress best practices, ensuring that only users with the appropriate capabilities can manage API keys.
…class - Replaced the deprecated base64_encode and base64_decode functions with sodium_bin2base64 and sodium_base642bin for enhanced security and JWT compatibility. - Updated method documentation to clarify that the encoding and decoding are now JWT-safe and do not include padding. - Added error handling for decoding to ensure robustness against invalid input.
- Changed header names from 'X-Tutor-Api-Key' and 'X-Tutor-User-Token' to 'Tutor-Api-Key' and 'Tutor-User-Token' for consistency and clarity. - Updated method documentation to reflect the new header names, ensuring accurate API usage guidance.
- Simplified the get_api_credentials_from_request method to exclusively read API key and secret from Tutor-Api-* headers, removing support for Basic auth and PHP_AUTH_USER/PW. - Updated method documentation to reflect the changes in credential retrieval, ensuring clarity for API users.
- Updated the handling of the REDIRECT_HTTP_AUTHORIZATION server variable to sanitize its value using sanitize_text_field before assigning it to the headers array. - This change enhances security by ensuring that the authorization header is properly sanitized, preventing potential security vulnerabilities.
- Updated the `quiz_attempt_details` method to sanitize the quiz ID parameter using the `Input::sanitize` method, improving security against potential injection attacks. - Modified the `get_quiz_attempt_ans` method to accept the attempt ID instead of the quiz ID, ensuring that answers are fetched based on the specific attempt, preventing cross-user answer leaks. - Enhanced method documentation to reflect the changes and clarify the purpose of the parameters.
- Eliminated the login rate limit functionality, including constants and methods related to tracking failed login attempts. - Updated the login authentication process to remove rate limiting checks, simplifying the login flow. - Adjusted method documentation to reflect the removal of rate limiting features, ensuring clarity for future development.
- Added functionality to manage access and refresh token lifetimes through a new settings form in the admin dashboard. - Introduced new constants and methods in the RestAuth class to handle token lifetime configurations, including validation for minimum and maximum values. - Updated the manage-api-keys.js script to handle form submissions for saving token settings with appropriate user feedback. - Enhanced the manage-tokens.php view to display and allow editing of token lifetime settings. - Improved overall documentation for new methods and constants related to token management.
- Updated the REST_Author, REST_Course, and REST_Quiz classes to use `self::send()` instead of `static::send()`, ensuring consistency in method calls. - This change improves clarity and aligns with best practices for method referencing within the same class context.
- Updated the RestAuth class to introduce new constants and methods for managing access and refresh token lifetimes, allowing for unlimited expiration settings. - Refactored existing methods to convert token lifetimes from seconds to days for better usability in the admin UI. - Enhanced the manage-tokens.php view to reflect these changes, including validation for token lifetime inputs and user-friendly messaging regarding expiration settings. - Improved documentation for new methods and constants related to token management, ensuring clarity for future development.
…th class - Modified the permission check logic to ensure that only the 'Delete' and 'All' permissions are considered valid for API key deletion. - Updated documentation to clarify the changes and align with pre-4.0.10 Pro route allowlists, specifying that 'Write' and 'Read/Write' do not authorize DELETE actions.
- Updated the version annotations in the REST_Quiz and RestAuth classes to reflect the new version 4.2.0, ensuring accurate documentation of changes and features. - This change aligns the documentation with the latest updates and clarifies the version history for future reference.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/auth/login,/auth/refresh, and/auth/logout.