PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Audit / CoreUserRoleOptionIntegrityCheck.php
advanced-access-manager / application / Audit Last commit date
AuditCheckTrait.php 1 year ago CoreUserRoleOptionIntegrityCheck.php 1 year ago EditableFileSystemCheck.php 7 months ago ElevatedCoreRoleCheck.php 7 months ago EmptyUnusedRoleCheck.php 7 months ago HighPrivilegeContentModeratorCheck.php 7 months ago HighPrivilegeOrElevatedUserCheck.php 7 months ago HighPrivilegeRoleCheck.php 7 months ago HighPrivilegeUserCountCheck.php 7 months ago RestfulAutoDiscoverEndpointCheck.php 7 months ago RoleCapabilityNamingConventionCheck.php 7 months ago RoleIntegrityCheck.php 7 months ago RoleTransparencyCheck.php 7 months ago XmlRpcEndpointCheck.php 7 months ago
CoreUserRoleOptionIntegrityCheck.php
161 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Role integrity audit check
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_CoreUserRoleOptionIntegrityCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'user_roles_option_integrity';
27
28 /**
29 * Run the check
30 *
31 * @return array
32 *
33 * @access public
34 * @static
35 *
36 * @version 7.0.0
37 */
38 public static function run()
39 {
40 $issues = [];
41 $response = [ 'is_completed' => true ];
42
43 try {
44 $db_roles = self::_read_role_key_option();
45
46 // The core user_roles structure is intact and not deviated from
47 // the WordPress core original standard
48 array_push(
49 $issues,
50 ...self::_validate_core_option_structure($db_roles)
51 );
52 } catch (Exception $e) {
53 array_push($issues, self::_format_issue(
54 'APPLICATION_ERROR',
55 [
56 'message' => $e->getMessage()
57 ],
58 'error'
59 ));
60 }
61
62 if (count($issues) > 0) {
63 $response['issues'] = $issues;
64 }
65
66 // Determine final status for the check
67 self::_determine_check_status($response);
68
69 return $response;
70 }
71
72 /**
73 * Get a collection of error messages for current step
74 *
75 * @return array
76 * @access private
77 * @static
78 *
79 * @version 7.0.0
80 */
81 private static function _get_message_templates()
82 {
83 return [
84 'INVALID_ROLE_SLUG' => __(
85 'Detected role %s (%s) with invalid slug',
86 'advanced-access-manager'
87 ),
88 'ILLEGAL_ROLE_PROPERTY' => __(
89 'Detected role %s (%s) with invalid properties: %s',
90 'advanced-access-manager'
91 ),
92 'MISSING_ROLE_PROPERTY' => __(
93 'Detected role %s (%s) with missing mandatory properties: %s',
94 'advanced-access-manager'
95 )
96 ];
97 }
98
99 /**
100 * Validate WordPress core option _user_roles
101 *
102 * @param array $db_roles
103 *
104 * @return array
105 *
106 * @access private
107 * @static
108 *
109 * @version 7.0.0
110 */
111 private static function _validate_core_option_structure($db_roles)
112 {
113 $response = [];
114
115 foreach($db_roles as $role_id => $role) {
116 // Step #1. Validating that all the keys are strings
117 if (!is_string($role_id)) {
118 array_push($response, self::_format_issue(
119 'INVALID_ROLE_SLUG',
120 [
121 'name' => isset($role['name']) ? $role['name'] : $role_id,
122 'slug' => $role_id
123 ],
124 'warning'
125 ));
126 }
127
128 // Step #2. Verifying that each role has only proper properties & no core
129 // props are missing
130 $props = array_keys($role);
131 $invalid_props = array_diff($props, ['name', 'capabilities']);
132 $missing_props = array_diff(['name', 'capabilities'], $props);
133
134 if (!empty($invalid_props)) {
135 array_push($response, self::_format_issue(
136 'ILLEGAL_ROLE_PROPERTY',
137 [
138 'name' => isset($role['name']) ? $role['name'] : $role_id,
139 'slug' => $role_id,
140 'props' => $invalid_props
141 ]
142 ));
143 }
144
145 if (!empty($missing_props)) {
146 array_push($response, self::_format_issue(
147 'MISSING_ROLE_PROPERTY',
148 [
149 'name' => isset($role['name']) ? $role['name'] : $role_id,
150 'slug' => $role_id,
151 'props' => $missing_props
152 ],
153 'critical'
154 ));
155 }
156 }
157
158 return $response;
159 }
160
161 }