PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-rest-controller.php +58 -11 12.0.3 → 16.3-beta View file →
@@ -9,8 +9,10 @@
9 9
10 10 use Automattic\Jetpack\Connection\REST_Connector;
11 11 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
12 12 use WP_Error;
13 +use WP_REST_Request;
14 +use WP_REST_Response;
13 15 use WP_REST_Server;
14 16
15 17 /**
16 18 * Defines our endponts.
@@ -21,8 +23,14 @@
21 23 *
22 24 * @return void
23 25 */
24 26 public static function register_rest_routes() {
27 + // Ensure routes are only initialized once.
28 + static $routes_registered = false;
29 + if ( $routes_registered ) {
30 + return;
31 + }
32 +
25 33 register_rest_route(
26 34 'jetpack/v4',
27 35 '/waf',
28 36 array(
@@ -50,8 +58,10 @@
50 58 'callback' => __CLASS__ . '::update_rules',
51 59 'permission_callback' => __CLASS__ . '::waf_permissions_callback',
52 60 )
53 61 );
62 +
63 + $routes_registered = true;
54 64 }
55 65
56 66 /**
57 67 * Update rules endpoint
@@ -68,9 +78,9 @@
68 78
69 79 return rest_ensure_response(
70 80 array(
71 81 'success' => true,
72 - 'message' => __( 'Rules updated succesfully', 'jetpack-waf' ),
82 + 'message' => __( 'Rules updated successfully', 'jetpack-waf' ),
73 83 )
74 84 );
75 85 }
76 86
@@ -79,9 +89,17 @@
79 89 *
80 90 * @return WP_REST_Response
81 91 */
82 92 public static function waf() {
83 - return rest_ensure_response( Waf_Runner::get_config() );
93 + return rest_ensure_response(
94 + array_merge(
95 + Waf_Runner::get_config(),
96 + array(
97 + 'waf_supported' => Waf_Runner::is_supported_environment(),
98 + 'automatic_rules_last_updated' => Waf_Stats::get_automatic_rules_last_updated(),
99 + )
100 + )
101 + );
84 102 }
85 103
86 104 /**
87 105 * Update WAF Endpoint
@@ -92,14 +110,19 @@
92 110 */
93 111 public static function update_waf( $request ) {
94 112 // Automatic Rules Enabled
95 113 if ( isset( $request[ Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ] ) ) {
96 - update_option( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, (bool) $request->get_param( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ) );
114 + update_option( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, $request->get_param( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ) ? '1' : '' );
97 115 }
98 116
99 - // IP Lists Enabled
100 - if ( isset( $request[ Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME ] ) ) {
101 - update_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, (bool) $request->get_param( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME ) );
117 + /**
118 + * IP Lists Enabled
119 + *
120 + * @deprecated 0.17.0 This is a legacy option maintained here for backwards compatibility.
121 + */
122 + if ( isset( $request['jetpack_waf_ip_list'] ) ) {
123 + update_option( Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME, $request['jetpack_waf_ip_list'] ? '1' : '' );
124 + update_option( Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME, $request['jetpack_waf_ip_list'] ? '1' : '' );
102 125 }
103 126
104 127 // IP Block List
105 128 if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] ) ) {
@@ -104,19 +127,40 @@
104 127 // IP Block List
105 128 if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] ) ) {
106 129 update_option( Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME, $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] );
107 130 }
131 + if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME ] ) ) {
132 + update_option( Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME, $request[ Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME ] ? '1' : '' );
133 + }
108 134
109 135 // IP Allow List
110 136 if ( isset( $request[ Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ] ) ) {
111 137 update_option( Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, $request[ Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ] );
112 138 }
139 + if ( isset( $request[ Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME ] ) ) {
140 + update_option( Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME, $request[ Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME ] ? '1' : '' );
141 + }
113 142
114 143 // Share Data
115 144 if ( isset( $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ) ) {
116 - update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, (bool) $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] );
145 + // If a user disabled the regular share we should disable the debug share data option.
146 + if ( ! $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ) {
147 + update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, '' );
148 + }
149 +
150 + update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ? '1' : '' );
117 151 }
118 152
153 + // Share Debug Data
154 + if ( isset( $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ) ) {
155 + // If a user toggles the debug share we should enable the regular share data option.
156 + if ( $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ) {
157 + update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, 1 );
158 + }
159 +
160 + update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ? '1' : '' );
161 + }
162 +
119 163 // Brute Force Protection
120 164 if ( isset( $request['brute_force_protection'] ) ) {
121 165 $enable_brute_force = (bool) $request['brute_force_protection'];
122 166 $brute_force_protection_toggled =
@@ -136,12 +180,15 @@
136 180 );
137 181 }
138 182 }
139 183
140 - try {
141 - Waf_Runner::update_waf();
142 - } catch ( Waf_Exception $e ) {
143 - return $e->get_wp_error();
184 + // Only attempt to update the WAF if the module is supported
185 + if ( Waf_Runner::is_supported_environment() ) {
186 + try {
187 + Waf_Runner::update_waf();
188 + } catch ( Waf_Exception $e ) {
189 + return $e->get_wp_error();
190 + }
144 191 }
145 192
146 193 return self::waf();
147 194 }