← All changes
|
jetpack_vendor/automattic/jetpack-waf/src/class-waf-request.php
+48
-14
13.6.2
→
16.3
View file →
| @@ -8,9 +8,9 @@ | ||
| 8 | 8 | namespace Automattic\Jetpack\Waf; |
| 9 | 9 | |
| 10 | 10 | require_once __DIR__ . '/functions.php'; |
| 11 | 11 | |
| 12 | -<<<PHAN | |
| 12 | +<<<'PHAN' | |
| 13 | 13 | @phan-type RequestFile = array{ name: string, filename: string } |
| 14 | 14 | PHAN; |
| 15 | 15 | |
| 16 | 16 | /** |
| @@ -122,9 +122,8 @@ | ||
| 122 | 122 | * @return array{0: string, 1: scalar}[] |
| 123 | 123 | */ |
| 124 | 124 | public function get_headers() { |
| 125 | 125 | $value = array(); |
| 126 | - $has_content_type = false; | |
| 127 | 126 | $has_content_length = false; |
| 128 | 127 | foreach ( $_SERVER as $k => $v ) { |
| 129 | 128 | $k = strtolower( $k ); |
| 130 | 129 | if ( 'http_' === substr( $k, 0, 5 ) ) { |
| @@ -129,19 +128,14 @@ | ||
| 129 | 128 | $k = strtolower( $k ); |
| 130 | 129 | if ( 'http_' === substr( $k, 0, 5 ) ) { |
| 131 | 130 | $value[] = array( $this->normalize_header_name( substr( $k, 5 ) ), $v ); |
| 132 | 131 | } elseif ( 'content_type' === $k && '' !== $v ) { |
| 133 | - $has_content_type = true; | |
| 134 | - $value[] = array( 'content-type', $v ); | |
| 132 | + $value[] = array( 'content-type', $v ); | |
| 135 | 133 | } elseif ( 'content_length' === $k && '' !== $v ) { |
| 136 | 134 | $has_content_length = true; |
| 137 | 135 | $value[] = array( 'content-length', $v ); |
| 138 | 136 | } |
| 139 | 137 | } |
| 140 | - if ( ! $has_content_type ) { | |
| 141 | - // default Content-Type per RFC 7231 section 3.1.5.5. | |
| 142 | - $value[] = array( 'content-type', 'application/octet-stream' ); | |
| 143 | - } | |
| 144 | 138 | if ( ! $has_content_length ) { |
| 145 | 139 | $value[] = array( 'content-length', '0' ); |
| 146 | 140 | } |
| 147 | 141 | |
| @@ -328,20 +322,60 @@ | ||
| 328 | 322 | return flatten_array( $_GET ); |
| 329 | 323 | } |
| 330 | 324 | |
| 331 | 325 | /** |
| 326 | + * Returns the POST variables from a JSON body | |
| 327 | + * | |
| 328 | + * @return array{string, scalar}[] | |
| 329 | + */ | |
| 330 | + private function get_json_post_vars() { | |
| 331 | + $decoded_json = json_decode( $this->get_body(), true ) ?? array(); | |
| 332 | + return flatten_array( $decoded_json, 'json', true ); | |
| 333 | + } | |
| 334 | + | |
| 335 | + /** | |
| 336 | + * Returns the POST variables from a urlencoded body | |
| 337 | + * | |
| 338 | + * @return array{string, scalar}[] | |
| 339 | + */ | |
| 340 | + private function get_urlencoded_post_vars() { | |
| 341 | + parse_str( $this->get_body(), $params ); | |
| 342 | + return flatten_array( $params ); | |
| 343 | + } | |
| 344 | + | |
| 345 | + /** | |
| 332 | 346 | * Returns the POST variables |
| 333 | 347 | * |
| 348 | + * @param string $body_processor Manually specifiy the method to use to process the body. Options are 'URLENCODED' and 'JSON'. | |
| 349 | + * | |
| 334 | 350 | * @return array{string, scalar}[] |
| 335 | 351 | */ |
| 336 | - public function get_post_vars() { | |
| 337 | - // Attempt to decode JSON requests. | |
| 338 | - if ( strpos( $this->get_header( 'content-type' ), 'application/json' ) !== false ) { | |
| 339 | - $decoded_json = json_decode( $this->get_body(), true ) ?? array(); | |
| 340 | - return flatten_array( $decoded_json, 'json', true ); | |
| 352 | + public function get_post_vars( string $body_processor = '' ) { | |
| 353 | + $content_type = $this->get_header( 'content-type' ); | |
| 354 | + | |
| 355 | + // If the body processor is specified by the rules file, trust it. | |
| 356 | + if ( 'URLENCODED' === $body_processor ) { | |
| 357 | + return $this->get_urlencoded_post_vars(); | |
| 341 | 358 | } |
| 359 | + if ( 'JSON' === $body_processor ) { | |
| 360 | + return $this->get_json_post_vars(); | |
| 361 | + } | |
| 342 | 362 | |
| 343 | - return flatten_array( $_POST ); | |
| 363 | + // Otherwise, use $_POST if it's not empty. | |
| 364 | + if ( ! empty( $_POST ) ) { | |
| 365 | + return flatten_array( $_POST ); | |
| 366 | + } | |
| 367 | + | |
| 368 | + // Lastly, try to parse the body based on the content type. | |
| 369 | + if ( strpos( $content_type, 'application/json' ) !== false ) { | |
| 370 | + return $this->get_json_post_vars(); | |
| 371 | + } | |
| 372 | + if ( strpos( $content_type, 'application/x-www-form-urlencoded' ) !== false ) { | |
| 373 | + return $this->get_urlencoded_post_vars(); | |
| 374 | + } | |
| 375 | + | |
| 376 | + // Don't try to parse any other content types. | |
| 377 | + return array(); | |
| 344 | 378 | } |
| 345 | 379 | |
| 346 | 380 | /** |
| 347 | 381 | * Returns the files that were uploaded with this request (i.e. what's in the $_FILES superglobal) |