PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-sync/src/modules/class-protect.php +35 -2 12.7.3 → 16.3-beta View file →
@@ -9,8 +9,12 @@
9 9
10 10 use Automattic\Jetpack\Constants as Jetpack_Constants;
11 11 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
12 12
13 +if ( ! defined( 'ABSPATH' ) ) {
14 + exit( 0 );
15 +}
16 +
13 17 /**
14 18 * Class to handle sync for Protect.
15 19 * Logs BruteProtect failed logins via sync.
16 20 */
@@ -38,8 +42,25 @@
38 42 add_action( 'jetpack_valid_failed_login_attempt', $callback );
39 43 }
40 44
41 45 /**
46 + * Provide a fallback value for has_login_ability.
47 + *
48 + * @access private
49 + */
50 + private function has_login_ability_fallback() {
51 + // Fall back to the Brute Force Protection class if it is available.
52 + if ( class_exists( 'Brute_Force_Protection' ) ) {
53 + $brute_force_protection = Brute_Force_Protection::instance();
54 + return $brute_force_protection->has_login_ability();
55 + }
56 +
57 + // If the login ability cannot be determined, the feature is not active,
58 + // or something is wrong, default to not syncing failed login attempts.
59 + return false;
60 + }
61 +
62 + /**
42 63 * Maybe log a failed login attempt.
43 64 *
44 65 * @access public
45 66 *
@@ -45,10 +66,22 @@
45 66 *
46 67 * @param array $failed_attempt Failed attempt data.
47 68 */
48 69 public function maybe_log_failed_login_attempt( $failed_attempt ) {
49 - $brute_force_protection = Brute_Force_Protection::instance();
50 - if ( $brute_force_protection->has_login_ability() && ! Jetpack_Constants::is_true( 'XMLRPC_REQUEST' ) ) {
70 + /**
71 + * Filter which provides Jetpack's decision as to whether the current requestor can attempt logging in.
72 + *
73 + * Example: When Jetpack's Brute Force Login Protection is active, this filter will return false if the user is currently locked out.
74 + *
75 + * @since 3.5.1
76 + *
77 + * @package sync
78 + *
79 + * @return bool True if the user should be allowed to attempt logging in, false otherwise.
80 + */
81 + $has_login_ability = apply_filters( 'jetpack_has_login_ability', $this->has_login_ability_fallback() );
82 +
83 + if ( $has_login_ability && ! Jetpack_Constants::is_true( 'XMLRPC_REQUEST' ) ) {
51 84 do_action( 'jetpack_valid_failed_login_attempt', $failed_attempt );
52 85 }
53 86 }
54 87 }