PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-waf-initializer.php +44 -35 12.2.3 → 16.3 View file →
@@ -8,8 +8,9 @@
8 8 namespace Automattic\Jetpack\Waf;
9 9
10 10 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
11 11 use WP_Error;
12 +use WP_Upgrader;
12 13
13 14 /**
14 15 * Initializes the module
15 16 */
@@ -15,9 +16,9 @@
15 16 */
16 17 class Waf_Initializer {
17 18
18 19 /**
19 - * Option for storing whether or not the WAF files are potentially out of date.
20 + * Option for storing whether the WAF files are potentially out of date.
20 21 *
21 22 * @var string NEEDS_UPDATE_OPTION_NAME
22 23 */
23 24 const NEEDS_UPDATE_OPTION_NAME = 'jetpack_waf_needs_update';
@@ -34,24 +35,21 @@
34 35
35 36 // Ensure backwards compatibility
36 37 Waf_Compatibility::add_compatibility_hooks();
37 38
38 - // Register REST routes.
39 - add_action( 'rest_api_init', array( new REST_Controller(), 'register_rest_routes' ) );
39 + // Register REST routes. Use a static callable so the controller class is not
40 + // loaded into memory/opcache on requests that never reach `rest_api_init`.
41 + add_action( 'rest_api_init', array( REST_Controller::class, 'register_rest_routes' ) );
40 42
41 - // Run the WAF on supported environments
42 - if ( Waf_Runner::is_supported_environment() ) {
43 - // Update the WAF after installing or upgrading a relevant Jetpack plugin
44 - add_action( 'upgrader_process_complete', __CLASS__ . '::update_waf_after_plugin_upgrade', 10, 2 );
45 - add_action( 'admin_init', __CLASS__ . '::check_for_waf_update' );
43 + // Update the WAF after installing or upgrading a relevant Jetpack plugin
44 + add_action( 'upgrader_process_complete', __CLASS__ . '::update_waf_after_plugin_upgrade', 10, 2 );
46 45
47 - // WAF activation/deactivation hooks
48 - add_action( 'jetpack_activate_module_waf', __CLASS__ . '::on_waf_activation' );
49 - add_action( 'jetpack_deactivate_module_waf', __CLASS__ . '::on_waf_deactivation' );
46 + // Check for compatibility updates
47 + add_action( 'admin_init', __CLASS__ . '::check_for_updates' );
50 48
51 - // Run the WAF
52 - Waf_Runner::initialize();
53 - }
49 + // WAF activation/deactivation hooks
50 + add_action( 'jetpack_activate_module_waf', __CLASS__ . '::on_waf_activation' );
51 + add_action( 'jetpack_deactivate_module_waf', __CLASS__ . '::on_waf_deactivation' );
54 52
55 53 // Brute force protection activation/deactivation hooks
56 54 add_action( 'jetpack_activate_module_protect', __CLASS__ . '::on_brute_force_protection_activation' );
57 55 add_action( 'jetpack_deactivate_module_protect', __CLASS__ . '::on_brute_force_protection_deactivation' );
@@ -57,8 +55,13 @@
57 55 add_action( 'jetpack_deactivate_module_protect', __CLASS__ . '::on_brute_force_protection_deactivation' );
58 56
59 57 // Run brute force protection
60 58 Brute_Force_Protection::initialize();
59 +
60 + // Run the WAF
61 + if ( Waf_Runner::is_supported_environment() ) {
62 + Waf_Runner::initialize();
63 + }
61 64 }
62 65
63 66 /**
64 67 * Activate the WAF on module activation.
@@ -129,8 +132,12 @@
129 132 public static function update_waf_after_plugin_upgrade( $upgrader, $hook_extra ) {
130 133 $jetpack_text_domains_with_waf = array( 'jetpack', 'jetpack-protect' );
131 134 $jetpack_plugins_with_waf = array( 'jetpack/jetpack.php', 'jetpack-protect/jetpack-protect.php' );
132 135
136 + $hook_extra['type'] ??= null;
137 + $hook_extra['action'] ??= null;
138 + $hook_extra['plugins'] ??= array();
139 +
133 140 // Only run on upgrades affecting plugins
134 141 if ( 'plugin' !== $hook_extra['type'] ) {
135 142 return;
136 143 }
@@ -148,14 +155,14 @@
148 155 return;
149 156 }
150 157 if ( 'install' === $hook_extra['action'] &&
151 158 ! empty( $upgrader->new_plugin_data['TextDomain'] ) &&
152 - empty( in_array( $upgrader->new_plugin_data['TextDomain'], $jetpack_text_domains_with_waf, true ) )
159 + empty( in_array( $upgrader->new_plugin_data['TextDomain'] ?? null, $jetpack_text_domains_with_waf, true ) )
153 160 ) {
154 161 return;
155 162 }
156 163
157 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 1 );
164 + update_option( self::NEEDS_UPDATE_OPTION_NAME, true );
158 165 }
159 166
160 167 /**
161 168 * Check for WAF update
@@ -163,37 +170,39 @@
163 170 * Updates the WAF when the "needs update" option is enabled.
164 171 *
165 172 * @return bool|WP_Error True if the WAF is up-to-date or was sucessfully updated, WP_Error if the update failed.
166 173 */
167 - public static function check_for_waf_update() {
174 + public static function check_for_updates() {
168 175 if ( get_option( self::NEEDS_UPDATE_OPTION_NAME ) ) {
169 - // Compatiblity patch for cases where an outdated WAF_Constants class has been
170 - // autoloaded by the standalone bootstrap execution at the beginning of the current request.
171 - if ( ! method_exists( Waf_Constants::class, 'define_mode' ) ) {
176 + if ( Waf_Runner::is_supported_environment() ) {
177 + // Compatiblity patch for cases where an outdated WAF_Constants class has been
178 + // autoloaded by the standalone bootstrap execution at the beginning of the current request.
179 + if ( ! method_exists( Waf_Constants::class, 'define_mode' ) ) {
180 + try {
181 + ( new Waf_Standalone_Bootstrap() )->generate();
182 + } catch ( Waf_Exception $e ) {
183 + return $e->get_wp_error();
184 + }
185 + }
186 +
187 + Waf_Compatibility::run_compatibility_migrations();
188 +
172 189 try {
190 + Waf_Rules_Manager::generate_ip_rules();
191 + Waf_Rules_Manager::generate_rules();
173 192 ( new Waf_Standalone_Bootstrap() )->generate();
174 193 } catch ( Waf_Exception $e ) {
175 194 return $e->get_wp_error();
176 195 }
196 + } else {
197 + // If the site doesn't support the request firewall,
198 + // just migrate the IP allow list used by brute force protection.
199 + Waf_Compatibility::migrate_brute_force_protection_ip_allow_list();
177 200 }
178 201
179 - Waf_Compatibility::run_compatibility_migrations();
180 -
181 - Waf_Constants::define_mode();
182 - if ( ! Waf_Runner::is_allowed_mode( JETPACK_WAF_MODE ) ) {
183 - return new WP_Error( 'waf_mode_invalid', 'Invalid firewall mode.' );
184 - }
185 -
186 - try {
187 - Waf_Rules_Manager::generate_ip_rules();
188 - Waf_Rules_Manager::generate_rules();
189 - ( new Waf_Standalone_Bootstrap() )->generate();
190 - } catch ( Waf_Exception $e ) {
191 - return $e->get_wp_error();
192 - }
202 + update_option( self::NEEDS_UPDATE_OPTION_NAME, false );
193 203 }
194 204
195 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 0 );
196 205 return true;
197 206 }
198 207
199 208 /**