` header. The key is read from the * encrypted option; never logged, never exposed to the client. * * Responses are cached in WordPress transients where it makes sense * (catalog, per-plugin update probe). */ class Robotstxt_Manager_Core_Client { /** * REST namespace on the remote Core install. * * @var non-falsy-string */ private const REST_NAMESPACE = 'robotstxt-core/v1'; /** * Default request timeout in seconds. * * @var int */ private const TIMEOUT = 15; /** * Transient TTL for the catalog cache (seconds). Default 1 hour. * * @var int */ public const CATALOG_TTL_DEFAULT = HOUR_IN_SECONDS; /** * Base URL of the remote Core install (no trailing slash). * * @var string */ private string $store_url; /** * Account-level API key (plaintext, never logged). * * @var string */ private string $api_key; /** * Constructor. * * @param string $store_url Base URL of the remote Plugins Core install. * @param string $api_key Account-level API key (plaintext). */ public function __construct( string $store_url, string $api_key ) { $this->store_url = rtrim( $store_url, '/' ); $this->api_key = $api_key; } /** * Builds a client configured from the saved plugin options. * * @return self */ public static function from_options(): self { $store_url_raw = get_option( 'robotstxt_manager_store_url', '' ); $api_key_raw = get_option( 'robotstxt_manager_api_key', '' ); $store_url = is_string( $store_url_raw ) ? $store_url_raw : ''; $api_key = is_string( $api_key_raw ) ? Robotstxt_Manager_Encryption::decrypt( $api_key_raw ) : ''; return new self( $store_url, $api_key ); } /** * Returns whether the client has both a URL and a key configured. * * @return bool */ public function is_configured(): bool { return '' !== $this->store_url && '' !== $this->api_key; } /** * Returns the configured store URL. * * @return string */ public function get_store_url(): string { return $this->store_url; } /** * Tests connectivity to the remote Core install. * * Performs a lightweight authenticated GET against the catalog endpoint. * Used by the Settings screen "Test connection" button and by the * pre-save validation in Robotstxt_Manager_Settings::sanitize_api_key(). * * @return array{ * ok:bool, * message:string, * catalog_count?:int, * } */ public function test_connection(): array { if ( '' === $this->store_url ) { return array( 'ok' => false, 'message' => __( 'Store URL is not configured.', 'robotstxt-manager' ), ); } if ( '' === $this->api_key ) { return array( 'ok' => false, 'message' => __( 'API key is not configured.', 'robotstxt-manager' ), ); } $response = $this->get( '/plugins' ); if ( is_wp_error( $response ) ) { return array( 'ok' => false, /* translators: %s: HTTP transport error message. */ 'message' => sprintf( __( 'Could not reach Plugins Core: %s', 'robotstxt-manager' ), $response->get_error_message() ), ); } $body = wp_remote_retrieve_body( $response ); $count = is_array( json_decode( $body, true ) ) ? count( json_decode( $body, true ) ) : 0; return array( 'ok' => true, 'message' => __( 'Connected.', 'robotstxt-manager' ), 'catalog_count' => $count, ); } /** * Returns the full plugin catalog from Core, cached in a transient. * * @return list> Catalog entries (slug, name, type, price, etc.). */ public function get_catalog(): array { if ( ! $this->is_configured() ) { return array(); } $cache_key = 'robotstxt_manager_catalog'; $cached = get_transient( $cache_key ); if ( is_array( $cached ) ) { $typed = array(); foreach ( $cached as $entry ) { if ( is_array( $entry ) ) { $row = array(); foreach ( $entry as $k => $v ) { if ( is_string( $k ) ) { $row[ $k ] = $v; } } $typed[] = $row; } } return $typed; } $response = $this->get( '/plugins' ); if ( is_wp_error( $response ) ) { return array(); } $body = wp_remote_retrieve_body( $response ); $data = json_decode( $body, true ); if ( ! is_array( $data ) ) { return array(); } $catalog = array(); foreach ( $data as $entry ) { if ( is_array( $entry ) ) { $row = array(); foreach ( $entry as $k => $v ) { if ( is_string( $k ) ) { $row[ $k ] = $v; } } $catalog[] = $row; } } $ttl = $this->get_catalog_ttl(); set_transient( $cache_key, $catalog, $ttl ); return $catalog; } /** * Clears the cached catalog response. Called when settings change or * when the admin user clicks "Refresh" on the catalog screen. * * @return void */ public function clear_catalog_cache(): void { delete_transient( 'robotstxt_manager_catalog' ); } /** * Returns the configured catalog-cache TTL in seconds. * * @return int */ private function get_catalog_ttl(): int { $raw = get_option( 'robotstxt_manager_cache_ttl_minutes', 60 ); $min = is_numeric( $raw ) ? (int) $raw : 60; if ( $min < 1 ) { return self::CATALOG_TTL_DEFAULT; } return $min * MINUTE_IN_SECONDS; } /** * Performs an authenticated GET request to the Core REST API. * * @param string $endpoint Path relative to the REST namespace (e.g. '/plugins'). * * @return WP_Error|array WP_Error on failure, or the wp_remote_get response array on success. */ private function get( string $endpoint ) { $url = $this->store_url . '/wp-json/' . self::REST_NAMESPACE . $endpoint; return wp_remote_get( $url, array( 'headers' => array( 'Authorization' => 'Bearer ' . $this->api_key, 'Accept' => 'application/json', ), 'timeout' => self::TIMEOUT, ) ); } }