PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-beta
Jetpack – WP Security, Backup, Speed, & Growth v16.3-beta
16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 All 507 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-rest-controller.php +33 -12 13.3.3 → 16.3-beta View file →
@@ -9,8 +9,10 @@
9 9
10 10 use Automattic\Jetpack\Connection\REST_Connector;
11 11 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
12 12 use WP_Error;
13 +use WP_REST_Request;
14 +use WP_REST_Response;
13 15 use WP_REST_Server;
14 16
15 17 /**
16 18 * Defines our endponts.
@@ -76,9 +78,9 @@
76 78
77 79 return rest_ensure_response(
78 80 array(
79 81 'success' => true,
80 - 'message' => __( 'Rules updated succesfully', 'jetpack-waf' ),
82 + 'message' => __( 'Rules updated successfully', 'jetpack-waf' ),
81 83 )
82 84 );
83 85 }
84 86
@@ -87,9 +89,17 @@
87 89 *
88 90 * @return WP_REST_Response
89 91 */
90 92 public static function waf() {
91 - return rest_ensure_response( Waf_Runner::get_config() );
93 + return rest_ensure_response(
94 + array_merge(
95 + Waf_Runner::get_config(),
96 + array(
97 + 'waf_supported' => Waf_Runner::is_supported_environment(),
98 + 'automatic_rules_last_updated' => Waf_Stats::get_automatic_rules_last_updated(),
99 + )
100 + )
101 + );
92 102 }
93 103
94 104 /**
95 105 * Update WAF Endpoint
@@ -100,14 +110,19 @@
100 110 */
101 111 public static function update_waf( $request ) {
102 112 // Automatic Rules Enabled
103 113 if ( isset( $request[ Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ] ) ) {
104 - update_option( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, (bool) $request->get_param( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ) );
114 + update_option( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, $request->get_param( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME ) ? '1' : '' );
105 115 }
106 116
107 - // IP Lists Enabled
108 - if ( isset( $request[ Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME ] ) ) {
109 - update_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, (bool) $request->get_param( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME ) );
117 + /**
118 + * IP Lists Enabled
119 + *
120 + * @deprecated 0.17.0 This is a legacy option maintained here for backwards compatibility.
121 + */
122 + if ( isset( $request['jetpack_waf_ip_list'] ) ) {
123 + update_option( Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME, $request['jetpack_waf_ip_list'] ? '1' : '' );
124 + update_option( Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME, $request['jetpack_waf_ip_list'] ? '1' : '' );
110 125 }
111 126
112 127 // IP Block List
113 128 if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] ) ) {
@@ -112,32 +127,38 @@
112 127 // IP Block List
113 128 if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] ) ) {
114 129 update_option( Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME, $request[ Waf_Rules_Manager::IP_BLOCK_LIST_OPTION_NAME ] );
115 130 }
131 + if ( isset( $request[ Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME ] ) ) {
132 + update_option( Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME, $request[ Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME ] ? '1' : '' );
133 + }
116 134
117 135 // IP Allow List
118 136 if ( isset( $request[ Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ] ) ) {
119 137 update_option( Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, $request[ Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ] );
120 138 }
139 + if ( isset( $request[ Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME ] ) ) {
140 + update_option( Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME, $request[ Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME ] ? '1' : '' );
141 + }
121 142
122 143 // Share Data
123 144 if ( isset( $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ) ) {
124 145 // If a user disabled the regular share we should disable the debug share data option.
125 - if ( false === $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ) {
126 - update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, false );
146 + if ( ! $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ) {
147 + update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, '' );
127 148 }
128 149
129 - update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, (bool) $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] );
150 + update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, $request[ Waf_Runner::SHARE_DATA_OPTION_NAME ] ? '1' : '' );
130 151 }
131 152
132 153 // Share Debug Data
133 154 if ( isset( $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ) ) {
134 155 // If a user toggles the debug share we should enable the regular share data option.
135 - if ( true === $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ) {
136 - update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, true );
156 + if ( $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ) {
157 + update_option( Waf_Runner::SHARE_DATA_OPTION_NAME, 1 );
137 158 }
138 159
139 - update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, (bool) $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] );
160 + update_option( Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME, $request[ Waf_Runner::SHARE_DEBUG_DATA_OPTION_NAME ] ? '1' : '' );
140 161 }
141 162
142 163 // Brute Force Protection
143 164 if ( isset( $request['brute_force_protection'] ) ) {