← All changes
|
jetpack_vendor/automattic/jetpack-waf/src/class-compatibility.php
+99
-0
13.2.4
→
16.3
View file →
| @@ -16,8 +16,48 @@ | ||
| 16 | 16 | */ |
| 17 | 17 | class Waf_Compatibility { |
| 18 | 18 | |
| 19 | 19 | /** |
| 20 | + * Returns the name for the IP allow list enabled/disabled option. | |
| 21 | + * | |
| 22 | + * @since 0.22.0 | |
| 23 | + * | |
| 24 | + * @return string | |
| 25 | + */ | |
| 26 | + private static function get_ip_allow_list_enabled_option_name() { | |
| 27 | + /** | |
| 28 | + * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution. | |
| 29 | + * | |
| 30 | + * @see peb6dq-2HL-p2 | |
| 31 | + */ | |
| 32 | + if ( ! defined( 'Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME' ) ) { | |
| 33 | + return 'jetpack_waf_ip_allow_list_enabled'; | |
| 34 | + } | |
| 35 | + | |
| 36 | + return Waf_Rules_Manager::IP_ALLOW_LIST_ENABLED_OPTION_NAME; | |
| 37 | + } | |
| 38 | + | |
| 39 | + /** | |
| 40 | + * Returns the name for the IP block list enabled/disabled option. | |
| 41 | + * | |
| 42 | + * @since 0.22.0 | |
| 43 | + * | |
| 44 | + * @return string | |
| 45 | + */ | |
| 46 | + private static function get_ip_block_list_enabled_option_name() { | |
| 47 | + /** | |
| 48 | + * Patch: bootstrap script generated prior to 0.17.0 may have autoloaded Waf_Rules_Manager class during standalone mode execution. | |
| 49 | + * | |
| 50 | + * @see peb6dq-2HL-p2 | |
| 51 | + */ | |
| 52 | + if ( ! defined( 'Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME' ) ) { | |
| 53 | + return 'jetpack_waf_ip_block_list_enabled'; | |
| 54 | + } | |
| 55 | + | |
| 56 | + return Waf_Rules_Manager::IP_BLOCK_LIST_ENABLED_OPTION_NAME; | |
| 57 | + } | |
| 58 | + | |
| 59 | + /** | |
| 20 | 60 | * Add compatibilty hooks |
| 21 | 61 | * |
| 22 | 62 | * @since 0.8.0 |
| 23 | 63 | * |
| @@ -27,8 +67,10 @@ | ||
| 27 | 67 | add_filter( 'default_option_' . Waf_Rules_Manager::AUTOMATIC_RULES_ENABLED_OPTION_NAME, __CLASS__ . '::default_option_waf_automatic_rules', 10, 3 ); |
| 28 | 68 | add_filter( 'default_option_' . Waf_Initializer::NEEDS_UPDATE_OPTION_NAME, __CLASS__ . '::default_option_waf_needs_update', 10, 3 ); |
| 29 | 69 | add_filter( 'default_option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::default_option_waf_ip_allow_list', 10, 3 ); |
| 30 | 70 | add_filter( 'option_' . Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME, __CLASS__ . '::filter_option_waf_ip_allow_list', 10, 1 ); |
| 71 | + add_filter( 'default_option_' . self::get_ip_allow_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_allow_list_enabled', 10, 3 ); | |
| 72 | + add_filter( 'default_option_' . self::get_ip_block_list_enabled_option_name(), __CLASS__ . '::default_option_waf_ip_block_list_enabled', 10, 3 ); | |
| 31 | 73 | } |
| 32 | 74 | |
| 33 | 75 | /** |
| 34 | 76 | * Run compatibility migrations. |
| @@ -112,8 +154,11 @@ | ||
| 112 | 154 | * @return string The merged IP allow list. |
| 113 | 155 | */ |
| 114 | 156 | public static function merge_ip_allow_lists( $waf_allow_list, $brute_force_allow_list ) { |
| 115 | 157 | |
| 158 | + // Drop malformed entries. | |
| 159 | + $brute_force_allow_list = is_array( $brute_force_allow_list ) ? array_filter( $brute_force_allow_list, 'is_object' ) : array(); | |
| 160 | + | |
| 116 | 161 | if ( empty( $brute_force_allow_list ) ) { |
| 117 | 162 | return $waf_allow_list; |
| 118 | 163 | } |
| 119 | 164 | |
| @@ -227,6 +272,60 @@ | ||
| 227 | 272 | * @return bool |
| 228 | 273 | */ |
| 229 | 274 | public static function is_brute_force_running_in_jetpack() { |
| 230 | 275 | return defined( 'JETPACK__VERSION' ) && version_compare( JETPACK__VERSION, '12', '<' ); |
| 276 | + } | |
| 277 | + | |
| 278 | + /** | |
| 279 | + * Default the allow list enabled option to the value of the generic IP lists enabled option it replaced. | |
| 280 | + * | |
| 281 | + * @since 0.17.0 | |
| 282 | + * | |
| 283 | + * @param mixed $default The default value to return if the option does not exist in the database. | |
| 284 | + * @param string $option Option name. | |
| 285 | + * @param bool $passed_default Was get_option() passed a default value. | |
| 286 | + * | |
| 287 | + * @return mixed The default value to return if the option does not exist in the database. | |
| 288 | + */ | |
| 289 | + public static function default_option_waf_ip_allow_list_enabled( $default, $option, $passed_default ) { | |
| 290 | + // Allow get_option() to override this default value | |
| 291 | + if ( $passed_default ) { | |
| 292 | + return $default; | |
| 293 | + } | |
| 294 | + | |
| 295 | + // If the deprecated IP lists option was set to false, disable the allow list. | |
| 296 | + // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility. | |
| 297 | + $deprecated_option = Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, true ); | |
| 298 | + if ( ! $deprecated_option ) { | |
| 299 | + return false; | |
| 300 | + } | |
| 301 | + | |
| 302 | + // If the allow list is empty, disable the allow list. | |
| 303 | + if ( ! Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_ALLOW_LIST_OPTION_NAME ) ) { | |
| 304 | + return false; | |
| 305 | + } | |
| 306 | + | |
| 307 | + // Default to enabling the allow list. | |
| 308 | + return true; | |
| 309 | + } | |
| 310 | + | |
| 311 | + /** | |
| 312 | + * Default the block list enabled option to the value of the generic IP lists enabled option it replaced. | |
| 313 | + * | |
| 314 | + * @since 0.17.0 | |
| 315 | + * | |
| 316 | + * @param mixed $default The default value to return if the option does not exist in the database. | |
| 317 | + * @param string $option Option name. | |
| 318 | + * @param bool $passed_default Was get_option() passed a default value. | |
| 319 | + * | |
| 320 | + * @return mixed The default value to return if the option does not exist in the database. | |
| 321 | + */ | |
| 322 | + public static function default_option_waf_ip_block_list_enabled( $default, $option, $passed_default ) { | |
| 323 | + // Allow get_option() to override this default value | |
| 324 | + if ( $passed_default ) { | |
| 325 | + return $default; | |
| 326 | + } | |
| 327 | + | |
| 328 | + // @phan-suppress-next-line PhanDeprecatedClassConstant -- Needed for backwards compatibility. | |
| 329 | + return Jetpack_Options::get_raw_option( Waf_Rules_Manager::IP_LISTS_ENABLED_OPTION_NAME, false ); | |
| 231 | 330 | } |
| 232 | 331 | } |