CreaCaptcha

lifecycle.php

Activation and deactivation routines.

Table of Contents

Functions

creationell_captcha_activate()  : void
Runs on plugin activation: seeds default options and HMAC secrets.
creationell_captcha_deactivate()  : void
Runs on plugin deactivation: clears every cron slot the plugin owns, sweeps the expired replay markers out of the options table and lets every module react via the `creationell_captcha_deactivated` action hook.
creationell_captcha_deactivate_site()  : void
The deactivation work for exactly one site: clears the three cron slots this plugin owns there and sweeps that site's expired replay markers.
creationell_captcha_deactivate_network()  : int
Runs the per-site deactivation work on every site of the network.
creationell_captcha_delete_expired_replay_markers()  : int
Deletes those replay-marker options of the current site whose lifetime has already run out.

Functions

creationell_captcha_activate()

Runs on plugin activation: seeds default options and HMAC secrets.

creationell_captcha_activate() : void

creationell_captcha_deactivate()

Runs on plugin deactivation: clears every cron slot the plugin owns, sweeps the expired replay markers out of the options table and lets every module react via the `creationell_captcha_deactivated` action hook.

creationell_captcha_deactivate([bool $network_deactivating = false ]) : void

B-M5: cron slots and replay markers are per-site data, so on a network-wide deactivation the work has to be done on every site of the network — not just on whichever site happens to be current when deactivate_{$plugin} fires (that is the network admin's site, usually the main site). uninstall.php already walks the network this way since DS-3; this is the same walk for the same reason.

Parameters
$network_deactivating : bool = false

Whether the plugin is being deactivated for the whole network. WordPress passes this as the single argument of deactivate_{$plugin} (wp-admin/includes/plugin.php, deactivate_plugins()); the default keeps the function callable by hand.

creationell_captcha_deactivate_site()

The deactivation work for exactly one site: clears the three cron slots this plugin owns there and sweeps that site's expired replay markers.

creationell_captcha_deactivate_site() : void

Everything in here is relative to the CURRENT site, so it is safe to call from inside a switch_to_blog() bracket — wp_clear_scheduled_hook() works on the current site's cron option and the sweep re-reads $wpdb->options on every call.

creationell_captcha_deactivate_network()

Runs the per-site deactivation work on every site of the network.

creationell_captcha_deactivate_network() : int

Walks the sites in batches instead of materialising every site id at once — same shape and same batch size as the DS-3 walk in uninstall.php, so both routines behave the same way on the same network.

Return values
int —

Number of sites processed.

creationell_captcha_delete_expired_replay_markers()

Deletes those replay-marker options of the current site whose lifetime has already run out.

creationell_captcha_delete_expired_replay_markers() : int

Live markers are deliberately left in place. Removing them as well would be tidier — nothing sweeps them while the plugin is unloaded — but it would re-open the window CM-9 closed: a payload whose marker is gone passes Engine::verify() a second time as long as its own signed expiresAt has not been reached (challenge_expiry, default 300 s, settings range 60–3600 s, checked inside the ALTCHA library independently of the marker — lib/altcha-org/altcha/src/Altcha.php, verifySolution()). Deactivating and re-activating inside that window is an everyday admin action — update, debugging, changing the plugin load order — so the marker has to survive it.

What stays behind when the plugin is never re-activated is one option row per payload whose challenge has not run out yet (since 1.1.0 the marker lifetime is the challenge's own remaining validity — Engine::replay_marker_lifetime()). uninstall.php removes those unconditionally, and after a re-activation the next successful claim re-arms the cron slot cleared in creationell_captcha_deactivate_site() (Engine::claim_replay_marker() → schedule_replay_cleanup()), whose sweep then drops them.

The predicate is the one Engine::cleanup_replay_markers() uses: the marker value is the Unix timestamp the marker expires at, written by Engine::claim_replay_marker(). A row with a non-numeric value casts to 0 and is therefore treated as expired — same fail-open-on-garbage behaviour as the sweep, and no caller outside the engine ever writes these rows.

Return values
int —

Number of option rows removed.


        
On this page

Search results