PluginProbe ʕ •ᴥ•ʔ
Jetpack – WP Security, Backup, Speed, & Growth / 16.2-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.2-a.1
16.1.2 16.2-a.1 16.1.1 16.1 16.1-beta 16.1-beta.2 16.1-beta.3 16.1-a.5 16.1-a.3 16.0.1 16.1-a.1 16.0 16.0-beta 16.0-a.7 16.0-a.5 15.9.1 16.0-a.3 16.0-a.1 15.9 15.9-beta 15.9-a.7 15.9-a.5 15.9-a.3 15.9-a.1 15.8 15.8-beta 15.8-a.7 15.8-a.5 5.2.5 5.3.4 5.4.4 5.5.5 5.6.5 5.7.5 5.8.4 5.9.4 6.0.4 6.1 6.1.1 6.1.2 6.1.3 6.1.4 6.1.5 6.2 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.1 6.3.2 6.3.3 6.3.4 6.3.5 6.3.6 6.3.7 6.4 6.4.1 6.4.2 6.4.3 6.4.4 6.4.5 6.4.6 6.5 6.5.1 6.5.2 6.5.3 6.5.4 6.6 6.6.1 6.6.2 6.6.3 6.6.4 6.6.5 6.7 6.7.1 6.7.2 6.7.3 6.7.4 6.8 6.8.1 6.8.2 6.8.3 6.8.4 6.8.5 6.9 6.9.1 6.9.2 6.9.3 6.9.4 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.1 7.1.1 7.1.2 7.1.3 7.1.4 7.1.5 7.2 7.2.1 7.2.1.1 7.2.2 7.2.3 7.2.4 7.2.5 7.3 7.3.0.1 7.3.1 7.3.1.1 7.3.2 7.3.3 7.3.4 7.3.5 7.4 7.4.1 7.4.2 7.4.3 7.4.4 7.4.5 7.5 7.5.0.1 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.5.6 7.5.7 7.6 7.6.1 7.6.2 7.6.3 7.6.4 7.7 7.7.1 7.7.2 7.7.3 7.7.4 7.7.5 7.7.6 7.8 7.8.1 7.8.2 7.8.3 7.8.4 7.9 7.9.1 7.9.2 7.9.3 7.9.4 8.0 8.0.1 8.0.2 8.0.3 8.1 8.1.1 8.1.2 8.1.3 8.1.4 8.2 8.2.0.1 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.2.6 8.3 8.3.1 8.3.2 8.3.3 8.4 8.4.1 8.4.2 8.4.3 8.4.4 8.4.5 8.5 8.5.1 8.5.2 8.5.3 8.6 8.6.1 8.6.2 8.6.3 8.6.4 8.7 8.7.0.1 8.7.1 8.7.2 8.7.3 8.7.4 8.8 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.9 8.9.1 8.9.2 8.9.3 8.9.4 9.0 9.0.1 9.0.2 9.0.3 9.0.4 9.0.5 9.1 9.1.1 9.1.2 9.1.3 9.2 9.2.1 9.2.2 9.2.3 9.2.4 9.3 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.4 9.4.1 9.4.2 9.4.3 9.4.4 9.5 9.5.1 9.5.2 9.5.3 9.5.4 9.5.5 9.6 9.6.1 9.6.2 9.6.3 9.6.4 9.7 9.7.1 9.7.2 15.7-beta.2 9.7.3 15.7.1 9.8 15.8-a.1 9.8.1 15.8-a.3 9.8.2 2.0.9 9.8.3 2.1.7 9.9 2.2.10 9.9.1 2.3.10 9.9.2 2.4.7 9.9.3 2.5.5 2.6.6 2.7.5 2.8.5 2.9.6 3.0.6 3.1.5 3.2.5 3.3.6 3.4.6 3.5.6 3.6.4 3.7.5 3.8.5 3.9.10 4.0.7 4.1.4 4.2.5 4.3.5 4.4.5 4.5.3 4.6.3 4.7.4 4.8.5 4.9.3 5.0.3 5.1.4 trunk 10.0 10.0.1 10.0.2 10.1 10.1.1 10.1.2 10.2 10.2.1 10.2.2 10.2.3 10.3 10.3.1 10.3.2 10.4 10.4.1 10.4.2 10.5 10.5.1 10.5.2 10.5.3 10.6 10.6.1 10.6.2 10.7 10.7.1 10.7.2 10.8 10.8.1 10.8.2 10.9 10.9.1 10.9.2 10.9.3 11.0 11.0.1 11.0.2 11.1 11.1.1 11.1.2 11.1.3 11.1.4 11.2 11.2.1 11.2.2 11.3 11.3.1 11.3.2 11.3.3 11.3.4 11.4 11.4.1 11.4.2 11.5 11.5.1 11.5.2 11.5.3 11.6 11.6.1 11.6.2 11.7 11.7.1 11.7.2 11.7.3 11.8 11.8.3 11.8.4 11.8.5 11.8.6 11.9 11.9.1 11.9.2 11.9.3 12.0 12.0.1 12.0.2 12.1 12.1.1 12.1.2 12.2 12.2.1 12.2.2 12.3 12.3.1 12.4 12.4.1 12.5 12.5.1 12.6 12.6.1 12.6.2 12.6.3 12.7 12.7.1 12.7.2 12.8 12.8.1 12.8.2 12.9 12.9.1 12.9.2 12.9.3 12.9.4 13.0 13.0.1 13.1 13.1.1 13.1.2 13.1.3 13.1.4 13.2 13.2.1 13.2.2 13.2.3 13.3 13.3.1 13.3.2 13.4 13.4.1 13.4.2 13.4.3 13.4.4 13.5 13.5.1 13.6 13.6.1 13.7 13.7.1 13.8 13.8.1 13.8.2 13.9 13.9.1 14.0 14.1 14.2 14.2.1 14.3 14.4 14.4.1 14.5 14.6 14.7 14.8 14.9 14.9.1 15.0 15.0.1 15.0.2 15.1 15.1.1 15.2 15.3 15.3.1 15.4 15.5 15.6 15.7 15.7-a.1 15.7-a.3 15.7-a.5 15.7-a.7 15.7-beta
jetpack / jetpack_vendor / automattic / jetpack-waf / src / functions.php
jetpack / jetpack_vendor / automattic / jetpack-waf / src Last commit date
brute-force-protection 8 months ago exceptions 8 months ago abstract-blocked-login-page.php 2 months ago class-brute-force-protection.php 1 month ago class-compatibility.php 1 month ago class-rest-controller.php 8 months ago class-waf-blocked-login-page.php 8 months ago class-waf-blocklog-manager.php 8 months ago class-waf-cli.php 8 months ago class-waf-constants.php 1 year ago class-waf-initializer.php 1 month ago class-waf-operators.php 2 years ago class-waf-request.php 6 months ago class-waf-rules-manager.php 1 year ago class-waf-runner.php 1 month ago class-waf-runtime.php 2 months ago class-waf-standalone-bootstrap.php 1 month ago class-waf-stats.php 1 year ago class-waf-transforms.php 2 years ago functions.php 1 year ago
functions.php
121 lines
1 <?php
2 /**
3 * Utility functions for WAF.
4 *
5 * @package automattic/jetpack-waf
6 */
7
8 namespace Automattic\Jetpack\Waf;
9
10 /**
11 * A wrapper for WordPress's `wp_unslash()`.
12 *
13 * Even though PHP itself dropped the option to add slashes to superglobals a decade ago,
14 * WordPress still does it through some misguided extreme backwards compatibility. 🙄
15 *
16 * If WordPress's function exists, assume it needs to be called. If not, assume it doesn't.
17 *
18 * @param string|array $value String or array of data to unslash.
19 * @return string|array Possibly unslashed $value.
20 */
21 function wp_unslash( $value ) {
22 if ( function_exists( '\\wp_unslash' ) ) {
23 return \wp_unslash( $value );
24 } else {
25 return $value;
26 }
27 }
28
29 /**
30 * PHP helpfully parses request data into nested arrays in superglobals like $_GET and $_POST,
31 * and as part of that parsing turns field names like "myfield[x][y]" into a nested array
32 * that looks like [ "myfield" => [ "x" => [ "y" => "..." ] ] ]
33 * However, modsecurity (and thus our WAF rules) expect the original (non-nested) names.
34 *
35 * Therefore, this method takes an array of any depth and returns a single-depth array with nested
36 * keys translated back to a single string with brackets.
37 *
38 * Because there might be multiple items with the same name, this function will return an array of tuples,
39 * with the first item in the tuple the re-created original field name, and the second item the value.
40 *
41 * @example
42 * flatten_array( [ "field1" => "abc", "field2" => [ "d", "e", "f" ] ] )
43 * => [
44 * [ "field1", "abc" ],
45 * [ "field2[0]", "d" ],
46 * [ "field2[1]", "e" ],
47 * [ "field2[2]", "f" ],
48 * ]
49 *
50 * @param array $array An array that resembles one of the PHP superglobals like $_GET or $_POST.
51 * @param string $key_prefix String that should be prepended to the keys output by this function.
52 * Usually only used internally as part of recursion when flattening a nested array.
53 * @param bool|null $dot_notation Whether to use dot notation instead of bracket notation.
54 *
55 * @return array{0: string, 1: scalar}[] $key_prefix An array of key/value tuples, one for each distinct value in the input array.
56 */
57 function flatten_array( $array, $key_prefix = '', $dot_notation = null ) {
58 $return = array();
59 foreach ( $array as $source_key => $source_value ) {
60 $key = $source_key;
61 if ( ! empty( $key_prefix ) ) {
62 $key = $dot_notation ? "$key_prefix.$source_key" : $key_prefix . "[$source_key]";
63 }
64
65 if ( ! is_array( $source_value ) ) {
66 $return[] = array( $key, $source_value );
67 } else {
68 $return = array_merge( $return, flatten_array( $source_value, $key, $dot_notation ) );
69 }
70 }
71 return $return;
72 }
73
74 /**
75 * Polyfill for getallheaders, which is not available in all PHP environments.
76 *
77 * @link https://github.com/ralouphie/getallheaders
78 */
79 if ( ! function_exists( 'getallheaders' ) ) {
80 /**
81 * Get all HTTP header key/values as an associative array for the current request.
82 *
83 * @return array The HTTP header key/value pairs.
84 */
85 function getallheaders() {
86 // phpcs:disable WordPress.Security.ValidatedSanitizedInput
87 $headers = array();
88
89 $copy_server = array(
90 'CONTENT_TYPE' => 'Content-Type',
91 'CONTENT_LENGTH' => 'Content-Length',
92 'CONTENT_MD5' => 'Content-Md5',
93 );
94
95 foreach ( $_SERVER as $key => $value ) {
96 if ( substr( $key, 0, 5 ) === 'HTTP_' ) {
97 $key = substr( $key, 5 );
98 if ( ! isset( $copy_server[ $key ] ) || ! isset( $_SERVER[ $key ] ) ) {
99 $key = str_replace( ' ', '-', ucwords( strtolower( str_replace( '_', ' ', $key ) ) ) );
100 $headers[ $key ] = $value;
101 }
102 } elseif ( isset( $copy_server[ $key ] ) ) {
103 $headers[ $copy_server[ $key ] ] = $value;
104 }
105 }
106
107 if ( ! isset( $headers['Authorization'] ) ) {
108 if ( isset( $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] ) ) {
109 $headers['Authorization'] = $_SERVER['REDIRECT_HTTP_AUTHORIZATION'];
110 } elseif ( isset( $_SERVER['PHP_AUTH_USER'] ) ) {
111 $basic_pass = $_SERVER['PHP_AUTH_PW'] ?? '';
112 $headers['Authorization'] = 'Basic ' . base64_encode( $_SERVER['PHP_AUTH_USER'] . ':' . $basic_pass );
113 } elseif ( isset( $_SERVER['PHP_AUTH_DIGEST'] ) ) {
114 $headers['Authorization'] = $_SERVER['PHP_AUTH_DIGEST'];
115 }
116 }
117
118 return $headers;
119 }
120 }
121