From 1708bae91a686e7154fce83b5a1e8d2163a4540f Mon Sep 17 00:00:00 2001 From: Friederich Loheide Date: Wed, 23 Sep 2026 16:34:19 +0000 Subject: [PATCH] Fix certificate storage being undone by the settings sanitiser store_certificate() and remove_certificate() wrote the option with update_option(), which runs the registered sanitize() callback in the admin (including admin-ajax). sanitize() expects raw form input, so it restored the previous certificate fields and encrypted the stored client secret a second time: "Generate certificate" did not keep the new certificate and broke an existing client secret. Internal writes now bypass the form sanitiser. Co-Authored-By: Claude Opus 5.5 (1M context) --- includes/class-m365-login-settings.php | 30 +++++++++++++++++++++++--- 1 file changed, 27 insertions(+), 3 deletions(-) diff --git a/includes/class-m365-login-settings.php b/includes/class-m365-login-settings.php index 8fcbfaf..a4b8bd6 100644 --- a/includes/class-m365-login-settings.php +++ b/includes/class-m365-login-settings.php @@ -19,6 +19,13 @@ class M365_Login_Settings { */ private $cache = null; + /** + * Set while the plugin writes already sanitised values (skips the form sanitiser). + * + * @var bool + */ + private $raw_write = false; + /** * Default settings. * @@ -199,8 +206,7 @@ class M365_Login_Settings { $all = $this->all(); $all['cert_private_key'] = $enc; $all['cert_certificate'] = $pair['certificate']; - update_option( M365_LOGIN_OPTION, $all ); - $this->cache = null; + $this->write( $all ); return true; } @@ -211,8 +217,22 @@ class M365_Login_Settings { $all = $this->all(); $all['cert_private_key'] = ''; $all['cert_certificate'] = ''; + $this->write( $all ); + } + + /** + * Stores already sanitised settings. + * + * The option is registered with sanitize() as callback, which expects raw form input + * (it would, for example, encrypt the stored client secret a second time). + * + * @param array $all Complete settings. + */ + private function write( $all ) { + $this->raw_write = true; update_option( M365_LOGIN_OPTION, $all ); - $this->cache = null; + $this->raw_write = false; + $this->cache = null; } /** @@ -379,6 +399,10 @@ class M365_Login_Settings { * @return array */ public function sanitize( $input ) { + if ( $this->raw_write ) { + return $input; + } + $defaults = $this->defaults(); $current = $this->all(); $input = is_array( $input ) ? $input : array();