API
2 years ago
Access
2 years ago
Application
2 years ago
Archive
2 years ago
ArchiveProcessor
2 years ago
Archiver
2 years ago
AssetManager
2 years ago
Auth
2 years ago
Category
2 years ago
Changes
2 years ago
CliMulti
2 years ago
Columns
2 years ago
Concurrency
2 years ago
Config
2 years ago
Container
2 years ago
CronArchive
2 years ago
DataAccess
2 years ago
DataFiles
2 years ago
DataTable
2 years ago
Db
2 years ago
DeviceDetector
2 years ago
Email
2 years ago
Exception
2 years ago
Http
2 years ago
Intl
2 years ago
Log
2 years ago
Mail
2 years ago
Measurable
2 years ago
Menu
2 years ago
Metrics
2 years ago
Notification
2 years ago
Period
2 years ago
Plugin
2 years ago
ProfessionalServices
2 years ago
Report
2 years ago
ReportRenderer
2 years ago
Scheduler
2 years ago
Segment
2 years ago
Session
2 years ago
Settings
2 years ago
Tracker
2 years ago
Translation
2 years ago
Twig
2 years ago
UpdateCheck
2 years ago
Updater
2 years ago
Updates
2 years ago
Validators
2 years ago
View
2 years ago
ViewDataTable
2 years ago
Visualization
2 years ago
Widget
2 years ago
.htaccess
2 years ago
Access.php
2 years ago
Archive.php
2 years ago
ArchiveProcessor.php
2 years ago
AssetManager.php
2 years ago
Auth.php
2 years ago
AuthResult.php
2 years ago
BaseFactory.php
2 years ago
Cache.php
2 years ago
CacheId.php
2 years ago
CliMulti.php
2 years ago
Common.php
2 years ago
Config.php
2 years ago
Console.php
2 years ago
Context.php
2 years ago
Cookie.php
2 years ago
CronArchive.php
2 years ago
DI.php
2 years ago
DataArray.php
2 years ago
DataTable.php
2 years ago
Date.php
2 years ago
Db.php
2 years ago
DbHelper.php
2 years ago
Development.php
2 years ago
ErrorHandler.php
2 years ago
EventDispatcher.php
2 years ago
ExceptionHandler.php
2 years ago
FileIntegrity.php
2 years ago
Filechecks.php
2 years ago
Filesystem.php
2 years ago
FrontController.php
2 years ago
Http.php
2 years ago
IP.php
2 years ago
Log.php
2 years ago
LogDeleter.php
2 years ago
Mail.php
2 years ago
Metrics.php
2 years ago
NoAccessException.php
2 years ago
Nonce.php
2 years ago
Notification.php
2 years ago
NumberFormatter.php
2 years ago
Option.php
2 years ago
Period.php
2 years ago
Piwik.php
2 years ago
Plugin.php
2 years ago
Profiler.php
2 years ago
ProxyHeaders.php
2 years ago
ProxyHttp.php
2 years ago
QuickForm2.php
2 years ago
RankingQuery.php
2 years ago
ReportRenderer.php
2 years ago
Request.php
2 years ago
Segment.php
2 years ago
Sequence.php
2 years ago
Session.php
2 years ago
SettingsPiwik.php
2 years ago
SettingsServer.php
2 years ago
Singleton.php
2 years ago
Site.php
2 years ago
SiteContentDetector.php
2 years ago
SupportedBrowser.php
2 years ago
TCPDF.php
2 years ago
Theme.php
2 years ago
Timer.php
2 years ago
Tracker.php
2 years ago
Twig.php
2 years ago
Unzip.php
2 years ago
UpdateCheck.php
2 years ago
Updater.php
2 years ago
UpdaterErrorException.php
2 years ago
Updates.php
2 years ago
Url.php
2 years ago
UrlHelper.php
2 years ago
Version.php
2 years ago
View.php
2 years ago
bootstrap.php
2 years ago
dispatch.php
2 years ago
testMinimumPhpVersion.php
2 years ago
IP.php
140 lines
| 1 | <?php |
| 2 | |
| 3 | /** |
| 4 | * Matomo - free/libre analytics platform |
| 5 | * |
| 6 | * @link https://matomo.org |
| 7 | * @license http://www.gnu.org/licenses/gpl-3.0.html GPL v3 or later |
| 8 | * |
| 9 | */ |
| 10 | namespace Piwik; |
| 11 | |
| 12 | use Matomo\Network\IPUtils; |
| 13 | /** |
| 14 | * Contains IP address helper functions (for both IPv4 and IPv6). |
| 15 | * |
| 16 | * As of Piwik 2.9, most methods in this class are deprecated. You are |
| 17 | * encouraged to use classes from the Piwik "Network" component: |
| 18 | * |
| 19 | * @see \Matomo\Network\IP |
| 20 | * @see \Matomo\Network\IPUtils |
| 21 | * @link https://github.com/matomo-org/component-network |
| 22 | * |
| 23 | * As of Piwik 1.3, IP addresses are stored in the DB has VARBINARY(16), |
| 24 | * and passed around in network address format which has the advantage of |
| 25 | * being in big-endian byte order. This allows for binary-safe string |
| 26 | * comparison of addresses (of the same length), even on Intel x86. |
| 27 | * |
| 28 | * As a matter of naming convention, we use `$ip` for the network address format |
| 29 | * and `$ipString` for the presentation format (i.e., human-readable form). |
| 30 | * |
| 31 | * We're not using the network address format (in_addr) for socket functions, |
| 32 | * so we don't have to worry about incompatibility with Windows UNICODE |
| 33 | * and inetPtonW(). |
| 34 | * |
| 35 | * @api |
| 36 | */ |
| 37 | class IP |
| 38 | { |
| 39 | /** |
| 40 | * Returns the most accurate IP address available for the current user, in |
| 41 | * IPv4 format. This could be the proxy client's IP address. |
| 42 | * |
| 43 | * @return string IP address in presentation format. |
| 44 | */ |
| 45 | public static function getIpFromHeader() |
| 46 | { |
| 47 | $general = \Piwik\Config::getInstance()->General; |
| 48 | $clientHeaders = @$general['proxy_client_headers']; |
| 49 | if (!is_array($clientHeaders)) { |
| 50 | $clientHeaders = array(); |
| 51 | } |
| 52 | $default = '0.0.0.0'; |
| 53 | if (isset($_SERVER['REMOTE_ADDR'])) { |
| 54 | $default = $_SERVER['REMOTE_ADDR']; |
| 55 | } |
| 56 | $ipString = self::getNonProxyIpFromHeader($default, $clientHeaders); |
| 57 | return IPUtils::sanitizeIp($ipString); |
| 58 | } |
| 59 | /** |
| 60 | * Returns a non-proxy IP address from header. |
| 61 | * |
| 62 | * @param string $default Default value to return if there no matching proxy header. |
| 63 | * @param array $proxyHeaders List of proxy headers. |
| 64 | * @return string |
| 65 | */ |
| 66 | public static function getNonProxyIpFromHeader($default, $proxyHeaders) |
| 67 | { |
| 68 | $proxyIps = array(); |
| 69 | $config = \Piwik\Config::getInstance()->General; |
| 70 | if (isset($config['proxy_ips'])) { |
| 71 | $proxyIps = $config['proxy_ips']; |
| 72 | } |
| 73 | if (!is_array($proxyIps)) { |
| 74 | $proxyIps = array(); |
| 75 | } |
| 76 | $shouldReadLastProxyIp = \Piwik\Config::getInstance()->General['proxy_ip_read_last_in_list'] == 1; |
| 77 | if (!$shouldReadLastProxyIp) { |
| 78 | $proxyIps[] = $default; |
| 79 | } |
| 80 | // examine proxy headers |
| 81 | foreach ($proxyHeaders as $proxyHeader) { |
| 82 | if (!empty($_SERVER[$proxyHeader])) { |
| 83 | // this may be buggy if someone has proxy IPs and proxy host headers configured as |
| 84 | // `$_SERVER[$proxyHeader]` could be eg $_SERVER['HTTP_X_FORWARDED_HOST'] and |
| 85 | // include an actual host name, not an IP |
| 86 | if ($shouldReadLastProxyIp) { |
| 87 | $proxyIp = self::getLastIpFromList($_SERVER[$proxyHeader], $proxyIps); |
| 88 | } else { |
| 89 | $proxyIp = self::getFirstIpFromList($_SERVER[$proxyHeader], $proxyIps); |
| 90 | } |
| 91 | if (strlen($proxyIp) && stripos($proxyIp, 'unknown') === false) { |
| 92 | return $proxyIp; |
| 93 | } |
| 94 | } |
| 95 | } |
| 96 | return $default; |
| 97 | } |
| 98 | /** |
| 99 | * Returns the last IP address in a comma separated list, subject to an optional exclusion list. |
| 100 | * |
| 101 | * @param string $csv Comma separated list of elements. |
| 102 | * @param array $excludedIps Optional list of excluded IP addresses (or IP address ranges). |
| 103 | * @return string Last (non-excluded) IP address in the list or an empty string if all given IPs are excluded. |
| 104 | */ |
| 105 | public static function getFirstIpFromList($csv, $excludedIps = null) |
| 106 | { |
| 107 | $p = strrpos($csv, ','); |
| 108 | if ($p !== false) { |
| 109 | $elements = self::getIpsFromList($csv, $excludedIps); |
| 110 | return reset($elements) ?: ''; |
| 111 | } |
| 112 | return trim(\Piwik\Common::sanitizeInputValue($csv)); |
| 113 | } |
| 114 | public static function getLastIpFromList($csv, $excludedIps = null) |
| 115 | { |
| 116 | $p = strrpos($csv, ','); |
| 117 | if ($p !== false) { |
| 118 | $elements = self::getIpsFromList($csv, $excludedIps); |
| 119 | return end($elements) ?: ''; |
| 120 | } |
| 121 | return trim(\Piwik\Common::sanitizeInputValue($csv)); |
| 122 | } |
| 123 | private static function getIpsFromList(string $csv, ?array $excludedIps) |
| 124 | { |
| 125 | $result = []; |
| 126 | $elements = explode(',', $csv); |
| 127 | foreach ($elements as $ipString) { |
| 128 | $element = trim(\Piwik\Common::sanitizeInputValue($ipString)); |
| 129 | if (empty($element)) { |
| 130 | continue; |
| 131 | } |
| 132 | $ip = \Matomo\Network\IP::fromStringIP(IPUtils::sanitizeIp($element)); |
| 133 | if (empty($excludedIps) || !in_array($element, $excludedIps) && !$ip->isInRanges($excludedIps)) { |
| 134 | $result[] = $element; |
| 135 | } |
| 136 | } |
| 137 | return $result; |
| 138 | } |
| 139 | } |
| 140 |