diff --git a/inc/spbc-auth.php b/inc/spbc-auth.php index 05efec2b4..1c60b3a99 100644 --- a/inc/spbc-auth.php +++ b/inc/spbc-auth.php @@ -22,7 +22,8 @@ die('Not allowed!'); } -add_filter('authenticate', 'spbc_authenticate', 20, 2); // Hooks for authentificate +add_filter('authenticate', 'spbc_authenticate', 20, 2); // Hooks for authenticate +add_action('lostpassword_post', 'spbc_lostpassword_rate_limit', 20, 2); // Hooks for lost password request checking // Hook for token-based logins (plugins like "Temporary Login Without Password") add_action('set_logged_in_cookie', 'spbc_detect_token_login', 10, 6); @@ -266,6 +267,30 @@ function spbc_authenticate($user, $username) return $user; } +function spbc_lostpassword_rate_limit($error) +{ + global $spbc; + $limit = !empty($spbc->settings['bfp__allowed_wrong_auths']) + ? (int) $spbc->settings['bfp__allowed_wrong_auths'] + : 5; + $period = !empty($spbc->settings['bfp__block_period__5_fails']) + ? (int) $spbc->settings['bfp__block_period__5_fails'] + : 3600; + $config = new RateLimiterConfig('lostpassword_rate_limit', $limit, $period); + $rate_limiter = new SpbcRateLimiter($config); + $rate_limiter_check = $rate_limiter->checkPassed(); + if ( ! $rate_limiter_check ) { + $limit_message = esc_html__('Current route access denied. (Security by CleanTalk)', 'security-malware-firewall'); + add_filter('lostpassword_errors', function ($_errors, $_user) use ($limit_message) { + return new WP_Error(403, $limit_message); + }, 20, 2); + if (function_exists('wc_add_notice')) { + wp_die($limit_message, '', ['response' => 403]); + } + } + return $error; +} + /** * Detecting new device *