PluginProbe ʕ •ᴥ•ʔ
Advanced Access Manager – Access Governance for WordPress / trunk
Advanced Access Manager – Access Governance for WordPress vtrunk
6.8.4 6.8.5 6.9.0 6.9.1 6.9.10 6.9.11 6.9.12 6.9.13 6.9.14 6.9.15 6.9.16 6.9.17 6.9.18 6.9.19 6.9.2 6.9.20 6.9.21 6.9.22 6.9.23 6.9.24 6.9.25 6.9.26 6.9.27 6.9.28 6.9.29 6.9.3 6.9.30 6.9.31 6.9.32 6.9.33 6.9.34 6.9.35 6.9.36 6.9.37 6.9.38 6.9.39 6.9.4 6.9.41 6.9.42 6.9.43 6.9.44 6.9.45 6.9.46 6.9.47 6.9.48 6.9.49 6.9.5 6.9.51 6.9.6 6.9.7 6.9.8 6.9.9 7.0.0 7.0.0-alpha.6 7.0.0-alpha.7 7.0.0-beta.1 7.0.0-rc1 7.0.0-rc2 7.0.0-rc3 7.0.1 7.0.10 7.0.11 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.1.0 7.1.1 trunk 3.0 4.0 4.0.1 4.1 4.2 4.3 4.4 4.4.1 4.5 4.6 4.6.1 4.6.2 4.7 4.7.1 4.7.2 4.7.5 4.7.6 4.8 4.8.1 4.9 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 4.9.5.1 4.9.5.2 5.0 5.0.1 5.0.2 5.0.3 5.0.4 5.0.5 5.0.6 5.0.7 5.0.8 5.1 5.1.1 5.10 5.11 5.2 5.2.1 5.2.5 5.2.6 5.2.7 5.3 5.3.1 5.3.2 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.4.3.1 5.4.3.2 5.5 5.5.1 5.5.2 5.6 5.6.1 5.6.1.1 5.7 5.7.1 5.7.2 5.7.3 5.8 5.8.1 5.8.2 5.8.3 5.9 5.9.1 5.9.1.1 5.9.2 5.9.2.1 5.9.3 5.9.4 5.9.5 5.9.6 5.9.6.1 5.9.6.2 5.9.6.3 5.9.7 5.9.7.1 5.9.7.2 5.9.7.3 5.9.8 5.9.8.1 5.9.9 5.9.9.1 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.1.0 6.1.1 6.2.0 6.2.1 6.2.2 6.3.0 6.3.1 6.3.2 6.3.3 6.4.0 6.4.1 6.4.2 6.4.3 6.5.0 6.5.1 6.5.2 6.5.3 6.5.4 6.6.0 6.6.1 6.6.2 6.6.3 6.6.4 6.7.0 6.7.1 6.7.2 6.7.3 6.7.4 6.7.5 6.7.6 6.7.7 6.7.8 6.7.9 6.8.0 6.8.1 6.8.2 6.8.3
advanced-access-manager / application / Audit / RestfulAutoDiscoverEndpointCheck.php
advanced-access-manager / application / Audit Last commit date
AuditCheckTrait.php 1 year ago CoreUserRoleOptionIntegrityCheck.php 1 year ago EditableFileSystemCheck.php 7 months ago ElevatedCoreRoleCheck.php 7 months ago EmptyUnusedRoleCheck.php 7 months ago HighPrivilegeContentModeratorCheck.php 7 months ago HighPrivilegeOrElevatedUserCheck.php 7 months ago HighPrivilegeRoleCheck.php 7 months ago HighPrivilegeUserCountCheck.php 7 months ago RestfulAutoDiscoverEndpointCheck.php 7 months ago RoleCapabilityNamingConventionCheck.php 7 months ago RoleIntegrityCheck.php 7 months ago RoleTransparencyCheck.php 7 months ago XmlRpcEndpointCheck.php 7 months ago
RestfulAutoDiscoverEndpointCheck.php
117 lines
1 <?php
2
3 /**
4 * ======================================================================
5 * LICENSE: This file is subject to the terms and conditions defined in *
6 * file 'license.txt', which is part of this source code package. *
7 * ======================================================================
8 */
9
10 /**
11 * Check if RESTful Auto-discovery endpoint is enabled
12 *
13 * @package AAM
14 * @version 7.0.0
15 */
16 class AAM_Audit_RestfulAutoDiscoverEndpointCheck
17 {
18
19 use AAM_Audit_AuditCheckTrait;
20
21 /**
22 * Step ID
23 *
24 * @version 7.0.0
25 */
26 const ID = 'restful_auto_discover_endpoint';
27
28 /**
29 * Run the check
30 *
31 * @return array
32 *
33 * @access public
34 * @static
35 *
36 * @version 7.0.0
37 */
38 public static function run()
39 {
40 $issues = [];
41 $response = [ 'is_completed' => true ];
42
43 try {
44 array_push($issues, ...self::_check_endpoint_accessability());
45 } catch (Exception $e) {
46 array_push($issues, self::_format_issue(
47 'APPLICATION_ERROR',
48 [
49 'message' => $e->getMessage()
50 ],
51 'error'
52 ));
53 }
54
55 if (count($issues) > 0) {
56 $response['issues'] = $issues;
57 }
58
59 // Determine final status for the check
60 self::_determine_check_status($response);
61
62 return $response;
63 }
64
65 /**
66 * Get a collection of error messages for current step
67 *
68 * @return array
69 * @access private
70 * @static
71 *
72 * @version 7.0.0
73 */
74 private static function _get_message_templates()
75 {
76 return [
77 'REST_OPEN_DISCOVER_ENDPOINT' => __(
78 'Detected open to anonymous users REST auto-discover endpoint',
79 'advanced-access-manager'
80 )
81 ];
82 }
83
84 /**
85 * Detect empty roles
86 *
87 * @return array
88 *
89 * @access private
90 * @static
91 *
92 * @version 7.0.0
93 */
94 private static function _check_endpoint_accessability()
95 {
96 $response = [];
97
98 $visitor = AAM::api()->visitor();
99
100 // Check if API route "/" is enabled
101 $api_route_enabled = $visitor->api_routes()->is_allowed('/');
102
103 // Additionally check if the same endpoint is restricted with URL Access
104 // service
105 $matched = $visitor->urls()->is_denied(rest_url());
106
107 $url_enabled = empty($matched) || $matched['type'] === 'allow';
108
109 // Verifying that auto-discover endpoint is disabled for visitors
110 if ($url_enabled && $api_route_enabled) {
111 array_push($response, self::_format_issue('REST_OPEN_DISCOVER_ENDPOINT'));
112 }
113
114 return $response;
115 }
116
117 }