PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Audit / HighPrivilegeContentModeratorCheck.php
advanced-access-manager / application / Audit Last commit date
AuditCheckTrait.php 1 year ago CoreUserRoleOptionIntegrityCheck.php 1 year ago EditableFileSystemCheck.php 7 months ago ElevatedCoreRoleCheck.php 7 months ago EmptyUnusedRoleCheck.php 7 months ago HighPrivilegeContentModeratorCheck.php 7 months ago HighPrivilegeOrElevatedUserCheck.php 7 months ago HighPrivilegeRoleCheck.php 7 months ago HighPrivilegeUserCountCheck.php 7 months ago RestfulAutoDiscoverEndpointCheck.php 7 months ago RoleCapabilityNamingConventionCheck.php 7 months ago RoleIntegrityCheck.php 7 months ago RoleTransparencyCheck.php 7 months ago XmlRpcEndpointCheck.php 7 months ago
HighPrivilegeContentModeratorCheck.php
156 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Check for the high privilege roles
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_HighPrivilegeContentModeratorCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'high_privilege_content_moderator_roles';
27
28 /**
29 * List of roles that are allowed to be high-privileged
30 *
31 * @version 7.0.0
32 */
33 const WHITELISTED_ROLES = [
34 'administrator',
35 'editor'
36 ];
37
38 /**
39 * List of core capabilities that can cause damage to the site's content
40 *
41 * @version 7.0.0
42 */
43 const HIGH_PRIVILEGE_CAPS = [
44 'manage_categories',
45 'unfiltered_html',
46 'edit_published_pages',
47 'delete_published_pages',
48 'unfiltered_upload'
49 ];
50
51 /**
52 * Run the check
53 *
54 * @return array
55 *
56 * @access public
57 * @static
58 *
59 * @version 7.0.0
60 */
61 public static function run()
62 {
63 $issues = [];
64 $response = [ 'is_completed' => true ];
65
66 try {
67 // Scan for high privilege roles
68 array_push(
69 $issues,
70 ...self::_scan_for_high_privilege_roles(self::_read_role_key_option())
71 );
72 } catch (Exception $e) {
73 array_push($issues, self::_format_issue(
74 'APPLICATION_ERROR',
75 [
76 'message' => $e->getMessage()
77 ],
78 'error'
79 ));
80 }
81
82 if (count($issues) > 0) {
83 $response['issues'] = $issues;
84 }
85
86 // Determine final status for the check
87 self::_determine_check_status($response);
88
89 return $response;
90 }
91
92 /**
93 * Get a collection of error messages for current step
94 *
95 * @return array
96 * @access private
97 * @static
98 *
99 * @version 7.0.0
100 */
101 private static function _get_message_templates()
102 {
103 return [
104 'HIGH_CONTENT_MODERATOR_ROLE' => __(
105 'Detected high-privilege content moderator role %s (%s) with caps: %s',
106 'advanced-access-manager'
107 )
108 ];
109 }
110
111 /**
112 * Scan for high-privilege roles that are not whitelisted
113 *
114 * @param array $db_roles
115 *
116 * @return array
117 *
118 * @access private
119 * @static
120 *
121 * @version 7.0.0
122 */
123 private static function _scan_for_high_privilege_roles($db_roles)
124 {
125 $response = [];
126
127 foreach($db_roles as $role_id => $role) {
128 if (!in_array($role_id, self::WHITELISTED_ROLES)) {
129 $assigned_caps = array_keys(
130 array_filter($role['capabilities'], function($v) {
131 return !empty($v);
132 })
133 );
134
135 $matched = array_intersect($assigned_caps, self::HIGH_PRIVILEGE_CAPS);
136
137 if (!empty($matched)) {
138 array_push($response, self::_format_issue(
139 'HIGH_CONTENT_MODERATOR_ROLE',
140 [
141 'name' => translate_user_role(
142 !empty($role['name']) ? $role['name'] : $role_id
143 ),
144 'slug' => $role_id,
145 'caps' => $matched
146 ],
147 'critical'
148 ));
149 }
150 }
151 }
152
153 return $response;
154 }
155
156 }