PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3
Jetpack – WP Security, Backup, Speed, & Growth v16.3
16.3 16.3-beta 16.3-a.5 16.3-a.7 16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 All 508 releases
← All changes | jetpack_vendor/automattic/jetpack-waf/src/class-waf-request.php +48 -14 13.4.5 → 16.3 View file →
@@ -8,9 +8,9 @@
8 8 namespace Automattic\Jetpack\Waf;
9 9
10 10 require_once __DIR__ . '/functions.php';
11 11
12 -<<<PHAN
12 +<<<'PHAN'
13 13 @phan-type RequestFile = array{ name: string, filename: string }
14 14 PHAN;
15 15
16 16 /**
@@ -122,9 +122,8 @@
122 122 * @return array{0: string, 1: scalar}[]
123 123 */
124 124 public function get_headers() {
125 125 $value = array();
126 - $has_content_type = false;
127 126 $has_content_length = false;
128 127 foreach ( $_SERVER as $k => $v ) {
129 128 $k = strtolower( $k );
130 129 if ( 'http_' === substr( $k, 0, 5 ) ) {
@@ -129,19 +128,14 @@
129 128 $k = strtolower( $k );
130 129 if ( 'http_' === substr( $k, 0, 5 ) ) {
131 130 $value[] = array( $this->normalize_header_name( substr( $k, 5 ) ), $v );
132 131 } elseif ( 'content_type' === $k && '' !== $v ) {
133 - $has_content_type = true;
134 - $value[] = array( 'content-type', $v );
132 + $value[] = array( 'content-type', $v );
135 133 } elseif ( 'content_length' === $k && '' !== $v ) {
136 134 $has_content_length = true;
137 135 $value[] = array( 'content-length', $v );
138 136 }
139 137 }
140 - if ( ! $has_content_type ) {
141 - // default Content-Type per RFC 7231 section 3.1.5.5.
142 - $value[] = array( 'content-type', 'application/octet-stream' );
143 - }
144 138 if ( ! $has_content_length ) {
145 139 $value[] = array( 'content-length', '0' );
146 140 }
147 141
@@ -328,20 +322,60 @@
328 322 return flatten_array( $_GET );
329 323 }
330 324
331 325 /**
326 + * Returns the POST variables from a JSON body
327 + *
328 + * @return array{string, scalar}[]
329 + */
330 + private function get_json_post_vars() {
331 + $decoded_json = json_decode( $this->get_body(), true ) ?? array();
332 + return flatten_array( $decoded_json, 'json', true );
333 + }
334 +
335 + /**
336 + * Returns the POST variables from a urlencoded body
337 + *
338 + * @return array{string, scalar}[]
339 + */
340 + private function get_urlencoded_post_vars() {
341 + parse_str( $this->get_body(), $params );
342 + return flatten_array( $params );
343 + }
344 +
345 + /**
332 346 * Returns the POST variables
333 347 *
348 + * @param string $body_processor Manually specifiy the method to use to process the body. Options are 'URLENCODED' and 'JSON'.
349 + *
334 350 * @return array{string, scalar}[]
335 351 */
336 - public function get_post_vars() {
337 - // Attempt to decode JSON requests.
338 - if ( strpos( $this->get_header( 'content-type' ), 'application/json' ) !== false ) {
339 - $decoded_json = json_decode( $this->get_body(), true ) ?? array();
340 - return flatten_array( $decoded_json, 'json', true );
352 + public function get_post_vars( string $body_processor = '' ) {
353 + $content_type = $this->get_header( 'content-type' );
354 +
355 + // If the body processor is specified by the rules file, trust it.
356 + if ( 'URLENCODED' === $body_processor ) {
357 + return $this->get_urlencoded_post_vars();
341 358 }
359 + if ( 'JSON' === $body_processor ) {
360 + return $this->get_json_post_vars();
361 + }
342 362
343 - return flatten_array( $_POST );
363 + // Otherwise, use $_POST if it's not empty.
364 + if ( ! empty( $_POST ) ) {
365 + return flatten_array( $_POST );
366 + }
367 +
368 + // Lastly, try to parse the body based on the content type.
369 + if ( strpos( $content_type, 'application/json' ) !== false ) {
370 + return $this->get_json_post_vars();
371 + }
372 + if ( strpos( $content_type, 'application/x-www-form-urlencoded' ) !== false ) {
373 + return $this->get_urlencoded_post_vars();
374 + }
375 +
376 + // Don't try to parse any other content types.
377 + return array();
344 378 }
345 379
346 380 /**
347 381 * Returns the files that were uploaded with this request (i.e. what's in the $_FILES superglobal)