PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-compatibility.php +105 -2 12.3.2 → 16.3 View file →
@@ -16,8 +16,48 @@
16 16 */
17 17 class Waf_Compatibility {
18 18
19 19 /**
20 + * Returns the name for the IP allow list enabled/disabled option.
21 + *
22 + * @since 0.22.0
23 + *
24 + * @return string
25 + */
26 + private static function get_ip_allow_list_enabled_option_name() {
27 + /**
28 + * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution.
29 + *
30 + * @see peb6dq-2HL-p2
31 + */
32 + if ( ! defined( 'Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME' ) ) {
33 + return 'jetpack_waf_ip_allow_list_enabled';
34 + }
35 +
36 + return Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME;
37 + }
38 +
39 + /**
40 + * Returns the name for the IP block list enabled/disabled option.
41 + *
42 + * @since 0.22.0
43 + *
44 + * @return string
45 + */
46 + private static function get_ip_block_list_enabled_option_name() {
47 + /**
48 + * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution.
49 + *
50 + * @see peb6dq-2HL-p2
51 + */
52 + if ( ! defined( 'Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME' ) ) {
53 + return 'jetpack_waf_ip_block_list_enabled';
54 + }
55 +
56 + return Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME;
57 + }
58 +
59 + /**
20 60 * Add compatibilty hooks
21 61 *
22 62 * @since 0.8.0
23 63 *
@@ -27,13 +67,20 @@
27 67 add_filter( 'default_option_' . Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, __CLASS__ . '::default_option_waf_automatic_rules', 10, 3 );
28 68 add_filter( 'default_option_' . Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, __CLASS__ . '::default_option_waf_needs_update', 10, 3 );
29 69 add_filter( 'default_option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::default_option_waf_ip_allow_list', 10, 3 );
30 70 add_filter( 'option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::filter_option_waf_ip_allow_list', 10, 1 );
71 + add_filter( 'default_option_' . self::get_ip_allow_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_allow_list_enabled', 10, 3 );
72 + add_filter( 'default_option_' . self::get_ip_block_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_block_list_enabled', 10, 3 );
31 73 }
32 74
33 75 /**
34 76 * Run compatibility migrations.
35 77 *
78 + * Note that this method should be compatible with sites where
79 + * the request firewall is not active or not supported.
80 + *
81 + * @see Waf_Runner::is_supported_environment().
82 + *
36 83 * @since 0.11.0
37 84 *
38 85 * @return void
39 86 */
@@ -107,8 +154,11 @@
107 154 * @return string The merged IP allow list.
108 155 */
109 156 public static function merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list ) {
110 157
158 + // Drop malformed entries.
159 + $brute_force_allow_list = is_array( $brute_force_allow_list ) ? array_filter( $brute_force_allow_list, 'is_object' ) : array();
160 +
111 161 if ( empty( $brute_force_allow_list ) ) {
112 162 return $waf_allow_list;
113 163 }
114 164
@@ -180,9 +230,9 @@
180 230 public static function filter_option_waf_ip_allow_list( $waf_allow_list ) {
181 231 $brute_force_allow_list = Jetpack_Options::get_raw_option( 'jetpack_protect_whitelist', false );
182 232 if ( false !== $brute_force_allow_list ) {
183 233 $waf_allow_list = self::merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list );
184 - update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, 1 );
234 + update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, true );
185 235 }
186 236
187 237 return $waf_allow_list;
188 238 }
@@ -207,9 +257,9 @@
207 257 // If the brute force option exists, use that and flag that the WAF needs to be updated.
208 258 $brute_force_allow_list = Jetpack_Options::get_raw_option( 'jetpack_protect_whitelist', false );
209 259 if ( false !== $brute_force_allow_list ) {
210 260 $waf_allow_list = self::merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list );
211 - update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, 1 );
261 + update_option( Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, true );
212 262 }
213 263
214 264 return $waf_allow_list;
215 265 }
@@ -224,5 +274,58 @@
224 274 public static function is_brute_force_running_in_jetpack() {
225 275 return defined( 'JETPACK__VERSION' ) && version_compare( JETPACK__VERSION, '12', '<' );
226 276 }
227 277
278 + /**
279 + * Default the allow list enabled option to the value of the generic IP lists enabled option it replaced.
280 + *
281 + * @since 0.17.0
282 + *
283 + * @param mixed $default The default value to return if the option does not exist in the database.
284 + * @param string $option Option name.
285 + * @param bool $passed_default Was get_option() passed a default value.
286 + *
287 + * @return mixed The default value to return if the option does not exist in the database.
288 + */
289 + public static function default_option_waf_ip_allow_list_enabled( $default, $option, $passed_default ) {
290 + // Allow get_option() to override this default value
291 + if ( $passed_default ) {
292 + return $default;
293 + }
294 +
295 + // If the deprecated IP lists option was set to false, disable the allow list.
296 + // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility.
297 + $deprecated_option = Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, true );
298 + if ( ! $deprecated_option ) {
299 + return false;
300 + }
301 +
302 + // If the allow list is empty, disable the allow list.
303 + if ( ! Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ) ) {
304 + return false;
305 + }
306 +
307 + // Default to enabling the allow list.
308 + return true;
309 + }
310 +
311 + /**
312 + * Default the block list enabled option to the value of the generic IP lists enabled option it replaced.
313 + *
314 + * @since 0.17.0
315 + *
316 + * @param mixed $default The default value to return if the option does not exist in the database.
317 + * @param string $option Option name.
318 + * @param bool $passed_default Was get_option() passed a default value.
319 + *
320 + * @return mixed The default value to return if the option does not exist in the database.
321 + */
322 + public static function default_option_waf_ip_block_list_enabled( $default, $option, $passed_default ) {
323 + // Allow get_option() to override this default value
324 + if ( $passed_default ) {
325 + return $default;
326 + }
327 +
328 + // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility.
329 + return Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, false );
330 + }
228 331 }