PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-waf-initializer.php +93 -36 12.1.3 → 16.3 View file →
@@ -8,8 +8,9 @@
8 8 namespace Automattic\Jetpack\Waf;
9 9
10 10 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
11 11 use WP_Error;
12 +use WP_Upgrader;
12 13
13 14 /**
14 15 * Initializes the module
15 16 */
@@ -15,9 +16,9 @@
15 16 */
16 17 class Waf_Initializer {
17 18
18 19 /**
19 - * Option for storing whether or not the WAF files are potentially out of date.
20 + * Option for storing whether the WAF files are potentially out of date.
20 21 *
21 22 * @var string NEEDS_UPDATE_OPTION_NAME
22 23 */
23 24 const NEEDS_UPDATE_OPTION_NAME = 'jetpack_waf_needs_update';
@@ -29,28 +30,38 @@
29 30 */
30 31 public static function init() {
31 32 // Do not run in unsupported environments
32 33 add_action( 'jetpack_get_available_modules', __CLASS__ . '::remove_module_on_unsupported_environments' );
34 + add_action( 'jetpack_get_available_standalone_modules', __CLASS__ . '::remove_standalone_module_on_unsupported_environments' );
33 35
34 36 // Ensure backwards compatibility
35 37 Waf_Compatibility::add_compatibility_hooks();
36 38
37 - // Run the WAF on supported environments
38 - if ( Waf_Runner::is_supported_environment() ) {
39 - // Update the WAF after installing or upgrading a relevant Jetpack plugin
40 - add_action( 'upgrader_process_complete', __CLASS__ . '::update_waf_after_plugin_upgrade', 10, 2 );
41 - add_action( 'admin_init', __CLASS__ . '::check_for_waf_update' );
39 + // Register REST routes. Use a static callable so the controller class is not
40 + // loaded into memory/opcache on requests that never reach `rest_api_init`.
41 + add_action( 'rest_api_init', array( REST_Controller::class, 'register_rest_routes' ) );
42 42
43 - // Activation/Deactivation hooks
44 - add_action( 'jetpack_activate_module_waf', __CLASS__ . '::on_activation' );
45 - add_action( 'jetpack_deactivate_module_waf', __CLASS__ . '::on_deactivation' );
43 + // Update the WAF after installing or upgrading a relevant Jetpack plugin
44 + add_action( 'upgrader_process_complete', __CLASS__ . '::update_waf_after_plugin_upgrade', 10, 2 );
46 45
47 - // Run the WAF
48 - Waf_Runner::initialize();
49 - }
46 + // Check for compatibility updates
47 + add_action( 'admin_init', __CLASS__ . '::check_for_updates' );
50 48
49 + // WAF activation/deactivation hooks
50 + add_action( 'jetpack_activate_module_waf', __CLASS__ . '::on_waf_activation' );
51 + add_action( 'jetpack_deactivate_module_waf', __CLASS__ . '::on_waf_deactivation' );
52 +
53 + // Brute force protection activation/deactivation hooks
54 + add_action( 'jetpack_activate_module_protect', __CLASS__ . '::on_brute_force_protection_activation' );
55 + add_action( 'jetpack_deactivate_module_protect', __CLASS__ . '::on_brute_force_protection_deactivation' );
56 +
51 57 // Run brute force protection
52 58 Brute_Force_Protection::initialize();
59 +
60 + // Run the WAF
61 + if ( Waf_Runner::is_supported_environment() ) {
62 + Waf_Runner::initialize();
63 + }
53 64 }
54 65
55 66 /**
56 67 * Activate the WAF on module activation.
@@ -56,9 +67,9 @@
56 67 * Activate the WAF on module activation.
57 68 *
58 69 * @return bool|WP_Error True if the WAF activation is successful, WP_Error otherwise.
59 70 */
60 - public static function on_activation() {
71 + public static function on_waf_activation() {
61 72 update_option( Waf_Runner::MODE_OPTION_NAME, 'normal' );
62 73 add_option( Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, false );
63 74
64 75 try {
@@ -67,8 +78,17 @@
67 78 } catch ( Waf_Exception $e ) {
68 79 return $e->get_wp_error();
69 80 }
70 81
82 + return true;
83 + }
84 +
85 + /**
86 + * Activate the Brute force protection on module activation.
87 + *
88 + * @return bool True if the Brute force protection activation is successful
89 + */
90 + public static function on_brute_force_protection_activation() {
71 91 $brute_force_protection = Brute_Force_Protection::instance();
72 92 $brute_force_protection->on_activation();
73 93
74 94 return true;
@@ -78,9 +98,9 @@
78 98 * Deactivate the WAF on module deactivation.
79 99 *
80 100 * @return bool|WP_Error True if the WAF deactivation is successful, WP_Error otherwise.
81 101 */
82 - public static function on_deactivation() {
102 + public static function on_waf_deactivation() {
83 103 try {
84 104 Waf_Runner::deactivate();
85 105 } catch ( Waf_Exception $e ) {
86 106 return $e->get_wp_error();
@@ -85,8 +105,17 @@
85 105 } catch ( Waf_Exception $e ) {
86 106 return $e->get_wp_error();
87 107 }
88 108
109 + return true;
110 + }
111 +
112 + /**
113 + * Deactivate the Brute force protection on module deactivation.
114 + *
115 + * @return bool True if the Brute force protection deactivation is successful.
116 + */
117 + public static function on_brute_force_protection_deactivation() {
89 118 $brute_force_protection = Brute_Force_Protection::instance();
90 119 $brute_force_protection->on_deactivation();
91 120
92 121 return true;
@@ -103,8 +132,12 @@
103 132 public static function update_waf_after_plugin_upgrade( $upgrader, $hook_extra ) {
104 133 $jetpack_text_domains_with_waf = array( 'jetpack', 'jetpack-protect' );
105 134 $jetpack_plugins_with_waf = array( 'jetpack/jetpack.php', 'jetpack-protect/jetpack-protect.php' );
106 135
136 + $hook_extra['type'] ??= null;
137 + $hook_extra['action'] ??= null;
138 + $hook_extra['plugins'] ??= array();
139 +
107 140 // Only run on upgrades affecting plugins
108 141 if ( 'plugin' !== $hook_extra['type'] ) {
109 142 return;
110 143 }
@@ -122,14 +155,14 @@
122 155 return;
123 156 }
124 157 if ( 'install' === $hook_extra['action'] &&
125 158 ! empty( $upgrader->new_plugin_data['TextDomain'] ) &&
126 - empty( in_array( $upgrader->new_plugin_data['TextDomain'], $jetpack_text_domains_with_waf, true ) )
159 + empty( in_array( $upgrader->new_plugin_data['TextDomain'] ?? null, $jetpack_text_domains_with_waf, true ) )
127 160 ) {
128 161 return;
129 162 }
130 163
131 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 1 );
164 + update_option( self::NEEDS_UPDATE_OPTION_NAME, true );
132 165 }
133 166
134 167 /**
135 168 * Check for WAF update
@@ -137,42 +170,44 @@
137 170 * Updates the WAF when the "needs update" option is enabled.
138 171 *
139 172 * @return bool|WP_Error True if the WAF is up-to-date or was sucessfully updated, WP_Error if the update failed.
140 173 */
141 - public static function check_for_waf_update() {
174 + public static function check_for_updates() {
142 175 if ( get_option( self::NEEDS_UPDATE_OPTION_NAME ) ) {
143 - // Compatiblity patch for cases where an outdated WAF_Constants class has been
144 - // autoloaded by the standalone bootstrap execution at the beginning of the current request.
145 - if ( ! method_exists( Waf_Constants::class, 'define_mode' ) ) {
176 + if ( Waf_Runner::is_supported_environment() ) {
177 + // Compatiblity patch for cases where an outdated WAF_Constants class has been
178 + // autoloaded by the standalone bootstrap execution at the beginning of the current request.
179 + if ( ! method_exists( Waf_Constants::class, 'define_mode' ) ) {
180 + try {
181 + ( new Waf_Standalone_Bootstrap() )->generate();
182 + } catch ( Waf_Exception $e ) {
183 + return $e->get_wp_error();
184 + }
185 + }
186 +
187 + Waf_Compatibility::run_compatibility_migrations();
188 +
146 189 try {
190 + Waf_Rules_Manager::generate_ip_rules();
191 + Waf_Rules_Manager::generate_rules();
147 192 ( new Waf_Standalone_Bootstrap() )->generate();
148 193 } catch ( Waf_Exception $e ) {
149 194 return $e->get_wp_error();
150 195 }
196 + } else {
197 + // If the site doesn't support the request firewall,
198 + // just migrate the IP allow list used by brute force protection.
199 + Waf_Compatibility::migrate_brute_force_protection_ip_allow_list();
151 200 }
152 201
153 - Waf_Compatibility::run_compatibility_migrations();
154 -
155 - Waf_Constants::define_mode();
156 - if ( ! Waf_Runner::is_allowed_mode( JETPACK_WAF_MODE ) ) {
157 - return new WP_Error( 'waf_mode_invalid', 'Invalid firewall mode.' );
158 - }
159 -
160 - try {
161 - Waf_Rules_Manager::generate_ip_rules();
162 - Waf_Rules_Manager::generate_rules();
163 - ( new Waf_Standalone_Bootstrap() )->generate();
164 - } catch ( Waf_Exception $e ) {
165 - return $e->get_wp_error();
166 - }
202 + update_option( self::NEEDS_UPDATE_OPTION_NAME, false );
167 203 }
168 204
169 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 0 );
170 205 return true;
171 206 }
172 207
173 208 /**
174 - * Disables the WAF module when on an supported platform.
209 + * Disables the WAF module when on an unsupported platform in Jetpack.
175 210 *
176 211 * @param array $modules Filterable value for `jetpack_get_available_modules`.
177 212 *
178 213 * @return array Array of module slugs.
@@ -180,8 +215,30 @@
180 215 public static function remove_module_on_unsupported_environments( $modules ) {
181 216 if ( ! Waf_Runner::is_supported_environment() ) {
182 217 // WAF should never be available on unsupported platforms.
183 218 unset( $modules['waf'] );
219 + }
220 +
221 + return $modules;
222 + }
223 +
224 + /**
225 + * Disables the WAF module when on an unsupported platform in a standalone plugin.
226 + *
227 + * @param array $modules Filterable value for `jetpack_get_available_standalone_modules`.
228 + *
229 + * @return array Array of module slugs.
230 + */
231 + public static function remove_standalone_module_on_unsupported_environments( $modules ) {
232 + if ( ! Waf_Runner::is_supported_environment() ) {
233 + // WAF should never be available on unsupported platforms.
234 + $modules = array_filter(
235 + $modules,
236 + function ( $module ) {
237 + return $module !== 'waf';
238 + }
239 + );
240 +
184 241 }
185 242
186 243 return $modules;
187 244 }