PluginProbe
Patchstack – WordPress & Plugins Security / 2.1.12
Patchstack – WordPress & Plugins Security v2.1.12
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
patchstack / includes / admin / ajax.php

ajax.php in Patchstack – WordPress & Plugins Security 2.1.12, at includes/admin/ajax.php

170 lines 5.1 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 // Do not allow the file to be called directly.
4 if ( ! defined( 'ABSPATH' ) ) {
5 exit;
6 }
7
8 /**
9 * This class is used for any admin AJAX interactions.
10 */
11 class P_Admin_Ajax extends P_Core {
12
13 /**
14 * Add the actions required for AJAX interactions.
15 *
16 * @param Patchstack $core
17 * @return void
18 */
19 public function __construct( $core ) {
20 parent::__construct( $core );
21 if ( isset( $_POST['PatchstackNonce'] ) && current_user_can( 'manage_options' ) && wp_verify_nonce( $_POST['PatchstackNonce'], 'patchstack-nonce' ) ) {
22 // Log tables actions.
23 add_action( 'wp_ajax_users_log_table', array( $this, 'users_log_table' ) );
24 add_action( 'wp_ajax_firewall_log_table', array( $this, 'firewall_log_table' ) );
25
26 // License related actions.
27 add_action( 'wp_ajax_activate_license', array( $this, 'activate_license' ) );
28 }
29 }
30
31 /**
32 * Firewall logs pagination.
33 *
34 * @return array
35 */
36 public function firewall_log_table() {
37 if ( ! isset( $_POST['start'], $_POST['length'] ) || !ctype_digit( $_POST['start'] ) || !ctype_digit( $_POST['length'] ) ) {
38 exit;
39 }
40
41 // Pull all entries, given parameters.
42 global $wpdb;
43 $entries = $wpdb->get_results(
44 $wpdb->prepare(
45 "SELECT a.id, a.ip, a.flag, a.method, a.log_date, case when a.referer IS NULL or a.referer = '' then a.request_uri else a.referer end as referer, a.fid, b.description
46 FROM " . $wpdb->prefix . 'patchstack_firewall_log AS a
47 LEFT JOIN ' . $wpdb->prefix . 'patchstack_logic AS b ON b.id = a.fid
48 ORDER BY a.id DESC
49 LIMIT %d, %d
50 ',
51 array( wp_filter_nohtml_kses( $_POST['start'] ), wp_filter_nohtml_kses( $_POST['length'] ) )
52 )
53 );
54
55 // Get total amount of rows.
56 $count = $wpdb->get_var( 'SELECT COUNT(id) FROM ' . $wpdb->prefix . 'patchstack_firewall_log' );
57 $firewall_rules = json_decode( get_option( 'patchstack_firewall_rules', '' ), true );
58
59 // Modify data if necessary.
60 $list = array();
61 foreach ( $entries as $entry ) {
62 foreach ( $entry as $key => $value ) {
63 if ( ! in_array( $key, array( 'referer' ) ) ) {
64 $entry->$key = sanitize_textarea_field( $value );
65 }
66 }
67
68 // Attempt to find the block reason.
69 $reason = $wpdb->get_var( $wpdb->prepare( 'SELECT cname FROM ' . $wpdb->prefix . 'patchstack_logic WHERE id = %d LIMIT 1', array( $entry->fid ) ) );
70 if ( $reason ) {
71 $entry->fid = $reason;
72 } elseif ( $firewall_rules != '' ) {
73 foreach ( $firewall_rules as $rule ) {
74 if ( isset( $rule['title'], $rule['cat'] ) && '55' . $rule['id'] == $entry->fid ) {
75 $entry->fid = $rule['cat'];
76 $entry->description = $rule['title'];
77 }
78 }
79 } else {
80 $entry->fid = 'Unknown';
81 }
82
83 $list[] = $entry;
84 }
85
86 // Return output.
87 wp_send_json(
88 array(
89 'data' => $list,
90 'recordsFiltered' => $count,
91 'recordsTotal' => $count
92 )
93 );
94 }
95
96 /**
97 * Activity logs pagination.
98 *
99 * @return void
100 */
101 public function users_log_table() {
102 if ( ! isset( $_POST['start'], $_POST['length'] ) || !ctype_digit( $_POST['start'] ) || !ctype_digit( $_POST['length'] ) ) {
103 exit;
104 }
105
106 // Determine if searching?
107 global $wpdb;
108 $searching = false;
109 $likes = array();
110 if ( isset( $_POST['search'], $_POST['search']['value'] ) && $_POST['search']['value'] != '' ) {
111 $val = wp_filter_nohtml_kses( $_POST['search']['value'] );
112 $searching = true;
113 $columns = array( 'author', 'ip', 'object', 'object_name', 'action' );
114 $search = 'WHERE 1=2 ';
115 foreach ( $columns as $column ) {
116 array_push( $likes, '%' . $wpdb->esc_like( $val ) . '%' );
117 $search .= 'OR ' . $column . ' LIKE %s';
118 }
119 }
120
121 $logs = $wpdb->get_results(
122 $wpdb->prepare(
123 'SELECT *
124 FROM ' . $wpdb->prefix . 'patchstack_event_log ' . ( $searching ? $search : '' ) . '
125 ORDER BY id DESC
126 LIMIT %d, %d
127 ',
128 array_merge( $likes, array( wp_filter_nohtml_kses( $_POST['start'] ), wp_filter_nohtml_kses( $_POST['length'] ) ) )
129 )
130 );
131
132 $count = $wpdb->get_var( $wpdb->prepare( 'SELECT COUNT(id) FROM ' . $wpdb->prefix . 'patchstack_event_log ' . ( $searching ? $search : '' ), $likes ) );
133
134 // Modify data if necessary.
135 $list = array();
136 foreach ( $logs as $log ) {
137 $list[] = $log;
138 }
139
140 // Return output.
141 wp_send_json(
142 array(
143 'data' => $list,
144 'recordsFiltered' => $count,
145 'recordsTotal' => $count
146 )
147 );
148 }
149
150 /**
151 * Test and activate a new license.
152 *
153 * @return void
154 */
155 public function activate_license() {
156 if ( ! isset( $_POST['clientid'], $_POST['secretkey'] ) || !ctype_digit( $_POST['clientid'] ) ) {
157 return;
158 }
159
160 // Test the new keys.
161 update_option( 'patchstack_api_token', '' );
162 $results = $this->plugin->activation->alter_license( wp_filter_nohtml_kses( $_POST['clientid'] ), wp_filter_nohtml_kses( $_POST['secretkey'] ), 'activate' );
163 if ( $results ) {
164 $response = $this->plugin->api->update_license_status();
165 $results['response'] = $response;
166 wp_send_json( $results );
167 }
168 }
169 }
170