lifecycle.php
Activation and deactivation routines.
Table of Contents
Functions
- creationell_captcha_activate() : void
- Runs on plugin activation: seeds default options and HMAC secrets.
- creationell_captcha_deactivate() : void
- Runs on plugin deactivation: clears every cron slot the plugin owns, sweeps the expired replay markers out of the options table and lets every module react via the `creationell_captcha_deactivated` action hook.
- creationell_captcha_deactivate_site() : void
- The deactivation work for exactly one site: clears the three cron slots this plugin owns there and sweeps that site's expired replay markers.
- creationell_captcha_deactivate_network() : int
- Runs the per-site deactivation work on every site of the network.
- creationell_captcha_delete_expired_replay_markers() : int
- Deletes those replay-marker options of the current site whose lifetime has already run out.
Functions
creationell_captcha_activate()
Runs on plugin activation: seeds default options and HMAC secrets.
creationell_captcha_activate() : void
creationell_captcha_deactivate()
Runs on plugin deactivation: clears every cron slot the plugin owns, sweeps the expired replay markers out of the options table and lets every module react via the `creationell_captcha_deactivated` action hook.
creationell_captcha_deactivate([bool $network_deactivating = false ]) : void
B-M5: cron slots and replay markers are per-site data, so on a network-wide
deactivation the work has to be done on every site of the network — not just
on whichever site happens to be current when deactivate_{$plugin} fires
(that is the network admin's site, usually the main site). uninstall.php
already walks the network this way since DS-3; this is the same walk for the
same reason.
Parameters
- $network_deactivating : bool = false
-
Whether the plugin is being deactivated for the whole network. WordPress passes this as the single argument of
deactivate_{$plugin}(wp-admin/includes/plugin.php,deactivate_plugins()); the default keeps the function callable by hand.
creationell_captcha_deactivate_site()
The deactivation work for exactly one site: clears the three cron slots this plugin owns there and sweeps that site's expired replay markers.
creationell_captcha_deactivate_site() : void
Everything in here is relative to the CURRENT site, so it is safe to call
from inside a switch_to_blog() bracket — wp_clear_scheduled_hook() works
on the current site's cron option and the sweep re-reads $wpdb->options
on every call.
creationell_captcha_deactivate_network()
Runs the per-site deactivation work on every site of the network.
creationell_captcha_deactivate_network() : int
Walks the sites in batches instead of materialising every site id at once —
same shape and same batch size as the DS-3 walk in uninstall.php, so both
routines behave the same way on the same network.
Return values
int —Number of sites processed.
creationell_captcha_delete_expired_replay_markers()
Deletes those replay-marker options of the current site whose lifetime has already run out.
creationell_captcha_delete_expired_replay_markers() : int
Live markers are deliberately left in place. Removing them as well would be
tidier — nothing sweeps them while the plugin is unloaded — but it would
re-open the window CM-9 closed: a payload whose marker is gone passes
Engine::verify() a second time as long as its own signed expiresAt has
not been reached (challenge_expiry, default 300 s, settings range
60–3600 s, checked inside the ALTCHA library independently of the marker —
lib/altcha-org/altcha/src/Altcha.php, verifySolution()). Deactivating
and re-activating inside that window is an everyday admin action — update,
debugging, changing the plugin load order — so the marker has to survive it.
What stays behind when the plugin is never re-activated is one option row per
payload whose challenge has not run out yet (since 1.1.0 the marker lifetime
is the challenge's own remaining validity — Engine::replay_marker_lifetime()).
uninstall.php removes those unconditionally, and after a re-activation the
next successful claim re-arms the cron slot cleared in
creationell_captcha_deactivate_site() (Engine::claim_replay_marker() →
schedule_replay_cleanup()), whose sweep then drops them.
The predicate is the one Engine::cleanup_replay_markers() uses: the marker
value is the Unix timestamp the marker expires at, written by
Engine::claim_replay_marker(). A row with a non-numeric value casts to 0
and is therefore treated as expired — same fail-open-on-garbage behaviour as
the sweep, and no caller outside the engine ever writes these rows.
Return values
int —Number of option rows removed.