PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-waf / src / class-compatibility.php
jetpack / jetpack_vendor / automattic / jetpack-waf / src Last commit date
brute-force-protection 8 months ago exceptions 8 months ago abstract-blocked-login-page.php 2 months ago class-brute-force-protection.php 1 month ago class-compatibility.php 1 month ago class-rest-controller.php 8 months ago class-waf-blocked-login-page.php 8 months ago class-waf-blocklog-manager.php 8 months ago class-waf-cli.php 8 months ago class-waf-constants.php 1 year ago class-waf-initializer.php 1 month ago class-waf-operators.php 2 years ago class-waf-request.php 6 months ago class-waf-rules-manager.php 1 year ago class-waf-runner.php 1 month ago class-waf-runtime.php 2 months ago class-waf-standalone-bootstrap.php 1 month ago class-waf-stats.php 1 year ago class-waf-transforms.php 2 years ago functions.php 1 year ago
class-compatibility.php
332 lines
1 <?php
2 /**
3 * Class used to manage backwards-compatibility of the package.
4 *
5 * @since 0.8.0
6 *
7 * @package automattic/jetpack-waf
8 */
9
10 namespace Automattic\Jetpack\Waf;
11
12 use Jetpack_Options;
13
14 /**
15 * Defines methods for ensuring backwards compatibility.
16 */
17 class Waf_Compatibility {
18
19 /**
20 * Returns the name for the IP allow list enabled/disabled option.
21 *
22 * @since 0.22.0
23 *
24 * @return string
25 */
26 private static function get_ip_allow_list_enabled_option_name() {
27 /**
28 * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution.
29 *
30 * @see peb6dq-2HL-p2
31 */
32 if ( ! defined( 'Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME' ) ) {
33 return 'jetpack_waf_ip_allow_list_enabled';
34 }
35
36 return Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME;
37 }
38
39 /**
40 * Returns the name for the IP block list enabled/disabled option.
41 *
42 * @since 0.22.0
43 *
44 * @return string
45 */
46 private static function get_ip_block_list_enabled_option_name() {
47 /**
48 * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution.
49 *
50 * @see peb6dq-2HL-p2
51 */
52 if ( ! defined( 'Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME' ) ) {
53 return 'jetpack_waf_ip_block_list_enabled';
54 }
55
56 return Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME;
57 }
58
59 /**
60 * Add compatibilty hooks
61 *
62 * @since 0.8.0
63 *
64 * @return void
65 */
66 public static function add_compatibility_hooks() {
67 add_filter( 'default_option_' . Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, __CLASS__ . '::default_option_waf_automatic_rules', 10, 3 );
68 add_filter( 'default_option_' . Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, __CLASS__ . '::default_option_waf_needs_update', 10, 3 );
69 add_filter( 'default_option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::default_option_waf_ip_allow_list', 10, 3 );
70 add_filter( 'option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::filter_option_waf_ip_allow_list', 10, 1 );
71 add_filter( 'default_option_' . self::get_ip_allow_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_allow_list_enabled', 10, 3 );
72 add_filter( 'default_option_' . self::get_ip_block_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_block_list_enabled', 10, 3 );
73 }
74
75 /**
76 * Run compatibility migrations.
77 *
78 * Note that this method should be compatible with sites where
79 * the request firewall is not active or not supported.
80 *
81 * @see Waf_Runner::is_supported_environment().
82 *
83 * @since 0.11.0
84 *
85 * @return void
86 */
87 public static function run_compatibility_migrations() {
88 self::migrate_brute_force_protection_ip_allow_list();
89 }
90
91 /**
92 * Provides a default value for sites that installed the WAF
93 * before the automatic rules option was introduced.
94 *
95 * @since 0.9.0
96 *
97 * @param mixed $default The default value to return if the option does not exist in the database.
98 * @param string $option Option name.
99 * @param bool $passed_default Was get_option() passed a default value.
100 *
101 * @return mixed The default value to return if the option does not exist in the database.
102 */
103 public static function default_option_waf_automatic_rules( $default, $option, $passed_default ) {
104 // Allow get_option() to override this default value
105 if ( $passed_default ) {
106 return $default;
107 }
108
109 return self::get_default_automatic_rules_option();
110 }
111
112 /**
113 * If the option is not available, use the WAF module status
114 * to determine whether or not to run automatic rules.
115 *
116 * @since 0.9.0
117 *
118 * @return bool The default value for automatic rules.
119 */
120 public static function get_default_automatic_rules_option() {
121 return Waf_Runner::is_enabled();
122 }
123
124 /**
125 * Provides a default value for sites that installed the WAF
126 * before the NEEDS_UPDATE_OPTION_NAME option was added.
127 *
128 * @since 0.8.0
129 *
130 * @param mixed $default The default value to return if the option does not exist in the database.
131 * @param string $option Option name.
132 * @param bool $passed_default Was get_option() passed a default value.
133 *
134 * @return mixed The default value to return if the option does not exist in the database.
135 */
136 public static function default_option_waf_needs_update( $default, $option, $passed_default ) {
137 // Allow get_option() to override this default value
138 if ( $passed_default ) {
139 return $default;
140 }
141
142 // If the option hasn't been added yet, the WAF needs to be updated.
143 return true;
144 }
145
146 /**
147 * Merge the WAF and Brute Force Protection IP allow lists.
148 *
149 * @since 0.11.0
150 *
151 * @param string $waf_allow_list The WAF IP allow list.
152 * @param array $brute_force_allow_list The Brute Force Protection IP allow list. Array of IP objects.
153 *
154 * @return string The merged IP allow list.
155 */
156 public static function merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list ) {
157
158 // Drop malformed entries.
159 $brute_force_allow_list = is_array( $brute_force_allow_list ) ? array_filter( $brute_force_allow_list, 'is_object' ) : array();
160
161 if ( empty( $brute_force_allow_list ) ) {
162 return $waf_allow_list;
163 }
164
165 // Convert the IP objects to strings.
166 $brute_force_allow_list = array_map(
167 function ( $ip_object ) {
168 if ( ! empty( $ip_object->range ) ) {
169 return $ip_object->range_low . '-' . $ip_object->range_high;
170 }
171
172 return $ip_object->ip_address;
173 },
174 $brute_force_allow_list
175 );
176
177 $brute_force_allow_list_string = implode( "\n", $brute_force_allow_list );
178
179 if ( empty( $waf_allow_list ) ) {
180 return $brute_force_allow_list_string;
181 }
182
183 // Return the lists merged into a single string.
184 return "$waf_allow_list\n$brute_force_allow_list_string";
185 }
186
187 /**
188 * Migrate the brute force protection IP allow list option to the WAF option.
189 *
190 * @since 0.11.0
191 *
192 * @return void
193 */
194 public static function migrate_brute_force_protection_ip_allow_list() {
195 // Get the allow list values directly from the database to avoid filters.
196 $brute_force_allow_list = Jetpack_Options::get_raw_option( 'jetpack_protect_whitelist' );
197 $waf_allow_list = Jetpack_Options::get_raw_option( 'jetpack_waf_ip_allow_list' );
198
199 if ( ! empty( $brute_force_allow_list ) ) {
200
201 if ( empty( $waf_allow_list ) ) {
202 $waf_allow_list = '';
203 }
204
205 // Merge the two allow lists.
206 $merged_allow_list = self::merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list );
207
208 // Update the WAF IP allow list with the merged list.
209 Jetpack_Options::update_raw_option( 'jetpack_waf_ip_allow_list', $merged_allow_list );
210
211 // Delete the old option if the update was successful.
212 // Check the values directly as `update_raw_option()` returns false if the value hasn't changed.
213 if ( Jetpack_Options::get_raw_option( 'jetpack_waf_ip_allow_list' ) === $merged_allow_list ) {
214 delete_option( 'jetpack_protect_whitelist' );
215 }
216 }
217 }
218
219 /**
220 * Filter for Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME's option value.
221 * Merges the deprecated IP allow list from the brute force protection module
222 * with the existing option value, and flags that the WAF needs to be updated.
223 *
224 * @since 0.11.0
225 *
226 * @param array $waf_allow_list The current value of the option.
227 *
228 * @return array The merged IP allow list.
229 */
230 public static function filter_option_waf_ip_allow_list( $waf_allow_list ) {
231 $brute_force_allow_list = Jetpack_Options::get_raw_option( 'jetpack_protect_whitelist', false );
232 if ( false !== $brute_force_allow_list ) {
233 $waf_allow_list = self::merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list );
234 update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, true );
235 }
236
237 return $waf_allow_list;
238 }
239
240 /**
241 * Default option for when the Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME option is not set.
242 *
243 * @param mixed $default The default value to return if the option does not exist in the database.
244 * @param string $option Option name.
245 * @param bool $passed_default Was get_option() passed a default value.
246 *
247 * @return mixed The default value to return if the option does not exist in the database.
248 */
249 public static function default_option_waf_ip_allow_list( $default, $option, $passed_default ) {
250 // Allow get_option() to override this default value
251 if ( $passed_default ) {
252 return $default;
253 }
254
255 $waf_allow_list = '';
256
257 // If the brute force option exists, use that and flag that the WAF needs to be updated.
258 $brute_force_allow_list = Jetpack_Options::get_raw_option( 'jetpack_protect_whitelist', false );
259 if ( false !== $brute_force_allow_list ) {
260 $waf_allow_list = self::merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list );
261 update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, true );
262 }
263
264 return $waf_allow_list;
265 }
266
267 /**
268 * Check if the brute force protection code is being run by an older version of Jetpack (< 12.0).
269 *
270 * @since 0.11.1
271 *
272 * @return bool
273 */
274 public static function is_brute_force_running_in_jetpack() {
275 return defined( 'JETPACK__VERSION' ) && version_compare( JETPACK__VERSION, '12', '<' );
276 }
277
278 /**
279 * Default the allow list enabled option to the value of the generic IP lists enabled option it replaced.
280 *
281 * @since 0.17.0
282 *
283 * @param mixed $default The default value to return if the option does not exist in the database.
284 * @param string $option Option name.
285 * @param bool $passed_default Was get_option() passed a default value.
286 *
287 * @return mixed The default value to return if the option does not exist in the database.
288 */
289 public static function default_option_waf_ip_allow_list_enabled( $default, $option, $passed_default ) {
290 // Allow get_option() to override this default value
291 if ( $passed_default ) {
292 return $default;
293 }
294
295 // If the deprecated IP lists option was set to false, disable the allow list.
296 // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility.
297 $deprecated_option = Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, true );
298 if ( ! $deprecated_option ) {
299 return false;
300 }
301
302 // If the allow list is empty, disable the allow list.
303 if ( ! Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ) ) {
304 return false;
305 }
306
307 // Default to enabling the allow list.
308 return true;
309 }
310
311 /**
312 * Default the block list enabled option to the value of the generic IP lists enabled option it replaced.
313 *
314 * @since 0.17.0
315 *
316 * @param mixed $default The default value to return if the option does not exist in the database.
317 * @param string $option Option name.
318 * @param bool $passed_default Was get_option() passed a default value.
319 *
320 * @return mixed The default value to return if the option does not exist in the database.
321 */
322 public static function default_option_waf_ip_block_list_enabled( $default, $option, $passed_default ) {
323 // Allow get_option() to override this default value
324 if ( $passed_default ) {
325 return $default;
326 }
327
328 // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility.
329 return Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, false );
330 }
331 }
332