PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-waf-initializer.php +13 -11 12.4.2 → 16.3 View file →
@@ -8,8 +8,9 @@
8 8 namespace Automattic\Jetpack\Waf;
9 9
10 10 use Automattic\Jetpack\Waf\Brute_Force_Protection\Brute_Force_Protection;
11 11 use WP_Error;
12 +use WP_Upgrader;
12 13
13 14 /**
14 15 * Initializes the module
15 16 */
@@ -15,9 +16,9 @@
15 16 */
16 17 class Waf_Initializer {
17 18
18 19 /**
19 - * Option for storing whether or not the WAF files are potentially out of date.
20 + * Option for storing whether the WAF files are potentially out of date.
20 21 *
21 22 * @var string NEEDS_UPDATE_OPTION_NAME
22 23 */
23 24 const NEEDS_UPDATE_OPTION_NAME = 'jetpack_waf_needs_update';
@@ -34,10 +35,11 @@
34 35
35 36 // Ensure backwards compatibility
36 37 Waf_Compatibility::add_compatibility_hooks();
37 38
38 - // Register REST routes
39 - add_action( 'rest_api_init', array( new REST_Controller(), 'register_rest_routes' ) );
39 + // Register REST routes. Use a static callable so the controller class is not
40 + // loaded into memory/opcache on requests that never reach `rest_api_init`.
41 + add_action( 'rest_api_init', array( REST_Controller::class, 'register_rest_routes' ) );
40 42
41 43 // Update the WAF after installing or upgrading a relevant Jetpack plugin
42 44 add_action( 'upgrader_process_complete', __CLASS__ . '::update_waf_after_plugin_upgrade', 10, 2 );
43 45
@@ -130,8 +132,12 @@
130 132 public static function update_waf_after_plugin_upgrade( $upgrader, $hook_extra ) {
131 133 $jetpack_text_domains_with_waf = array( 'jetpack', 'jetpack-protect' );
132 134 $jetpack_plugins_with_waf = array( 'jetpack/jetpack.php', 'jetpack-protect/jetpack-protect.php' );
133 135
136 + $hook_extra['type'] ??= null;
137 + $hook_extra['action'] ??= null;
138 + $hook_extra['plugins'] ??= array();
139 +
134 140 // Only run on upgrades affecting plugins
135 141 if ( 'plugin' !== $hook_extra['type'] ) {
136 142 return;
137 143 }
@@ -149,14 +155,14 @@
149 155 return;
150 156 }
151 157 if ( 'install' === $hook_extra['action'] &&
152 158 ! empty( $upgrader->new_plugin_data['TextDomain'] ) &&
153 - empty( in_array( $upgrader->new_plugin_data['TextDomain'], $jetpack_text_domains_with_waf, true ) )
159 + empty( in_array( $upgrader->new_plugin_data['TextDomain'] ?? null, $jetpack_text_domains_with_waf, true ) )
154 160 ) {
155 161 return;
156 162 }
157 163
158 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 1 );
164 + update_option( self::NEEDS_UPDATE_OPTION_NAME, true );
159 165 }
160 166
161 167 /**
162 168 * Check for WAF update
@@ -179,13 +185,8 @@
179 185 }
180 186
181 187 Waf_Compatibility::run_compatibility_migrations();
182 188
183 - Waf_Constants::define_mode();
184 - if ( ! Waf_Runner::is_allowed_mode( JETPACK_WAF_MODE ) ) {
185 - return new WP_Error( 'waf_mode_invalid', 'Invalid firewall mode.' );
186 - }
187 -
188 189 try {
189 190 Waf_Rules_Manager::generate_ip_rules();
190 191 Waf_Rules_Manager::generate_rules();
191 192 ( new Waf_Standalone_Bootstrap() )->generate();
@@ -196,11 +197,12 @@
196 197 // If the site doesn't support the request firewall,
197 198 // just migrate the IP allow list used by brute force protection.
198 199 Waf_Compatibility::migrate_brute_force_protection_ip_allow_list();
199 200 }
201 +
202 + update_option( self::NEEDS_UPDATE_OPTION_NAME, false );
200 203 }
201 204
202 - update_option( self::NEEDS_UPDATE_OPTION_NAME, 0 );
203 205 return true;
204 206 }
205 207
206 208 /**