PluginProbe
Patchstack – WordPress & Plugins Security / 2.1.8
Patchstack – WordPress & Plugins Security v2.1.8
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
← All changes | includes/multisite.php +109 -27 trunk2.1.8 View file →
@@ -8,9 +8,17 @@
8 8 /**
9 9 * This class is used to handle anything multisite related.
10 10 */
11 11 class P_Multisite extends P_Core {
12 +
12 13 /**
14 + * Stores any license activation errors.
15 + *
16 + * @var string
17 + */
18 + public $error = '';
19 +
20 + /**
13 21 * Add the actions required for the multisite functionality.
14 22 *
15 23 * @param Patchstack $core
16 24 * @return void
@@ -20,15 +28,97 @@
20 28 if ( ! is_super_admin() ) {
21 29 return;
22 30 }
23 31
24 - // When we need to re-run the migration of a specific site.
25 - if ( isset( $_GET['site'], $_GET['PatchstackNonce'] ) && wp_verify_nonce( $_GET['PatchstackNonce'], 'patchstack-migration' ) ) {
26 - $this->run_migration();
32 + // When settings are saved.
33 + if ( isset( $_POST['option_page'], $_POST['PatchstackNonce'] ) && wp_verify_nonce( $_POST['PatchstackNonce'], 'patchstack-option-page' ) ) {
34 + $this->save_settings();
27 35 }
36 +
37 + // When sites are activated.
38 + if ( isset( $_POST['patchstack_do'], $_POST['PatchstackNonce'], $_POST['sites'] ) && $_POST['patchstack_do'] == 'do_licenses' && wp_verify_nonce( $_POST['PatchstackNonce'], 'patchstack-multisite-activation' ) ) {
39 + $this->activate_licenses();
40 + }
28 41 }
29 42
30 43 /**
44 + * When a user selects sites that need to be activated.
45 + *
46 + * @return string
47 + */
48 + private function activate_licenses() {
49 + if ( empty( $_POST['sites'] ) ) {
50 + $this->error = '<span style="color: #ff6262;">Please select at least 1 site to be activated.</span><br /><br />';
51 + return;
52 + }
53 +
54 + // Determine which sites are already activated and skip those.
55 + $activate = array();
56 + $sites = get_sites();
57 + foreach ( $sites as $site ) {
58 + if ( in_array( $site->siteurl, $_POST['sites'] ) && get_blog_option( $site->id, 'patchstack_clientid' ) == '' ) {
59 + array_push( $activate, $site->siteurl );
60 + }
61 + }
62 +
63 + // Make sure there is a site that can be activated.
64 + if ( count( $activate ) == 0 ) {
65 + $this->error = '<span style="color: #ff6262;">None of the selected sites need activation.</span><br /><br />';
66 + return;
67 + }
68 +
69 + // Add the site to the app and retrieve the license for each site.
70 + $licenses = $this->plugin->api->get_site_licenses( array( 'sites' => $activate ) );
71 +
72 + // Did an error happen during the multisite license activation?
73 + if ( isset( $licenses['error'] ) ) {
74 + $this->error = '<span style="color: #ff6262;">' . $licenses['error'] . '</span><br /><br />';
75 + return;
76 + }
77 +
78 + // Activate licenses on given sites
79 + $sites = get_sites();
80 + foreach ( $sites as $site ) {
81 + if ( isset( $licenses[ $site->siteurl ] ) ) {
82 + $this->plugin->activation->activate_multisite_license( $site, $licenses[ $site->siteurl ] );
83 + }
84 + }
85 + }
86 +
87 + /**
88 + * When the individual or global settings are saved.
89 + *
90 + * @return void
91 + */
92 + private function save_settings() {
93 + switch ( $_POST['option_page'] ) {
94 + // Save hardening options
95 + case 'patchstack_hardening_settings_group':
96 + $options = array( 'patchstack_auto_update', 'patchstack_json_is_disabled', 'patchstack_register_email_blacklist', 'patchstack_move_logs', 'patchstack_basicscanblock', 'patchstack_userenum', 'patchstack_hidewpversion', 'patchstack_activity_log_is_enabled', 'patchstack_activity_log_failed_logins', 'patchstack_xmlrpc_is_disabled', 'patchstack_captcha_on_comments', 'patchstack_captcha_login_form', 'patchstack_captcha_registration_form', 'patchstack_captcha_reset_pwd_form', 'patchstack_captcha_type', 'patchstack_captcha_public_key', 'patchstack_captcha_public_key_v3', 'patchstack_captcha_public_key_v3_new', 'patchstack_captcha_private_key', 'patchstack_captcha_private_key_v3', 'patchstack_captcha_private_key_v3_new', 'patchstack_application_passwords_disabled' );
97 + $this->save_options( $options );
98 + break;
99 +
100 + // Save firewall settings
101 + case 'patchstack_firewall_settings_group':
102 + $options = array( 'patchstack_geo_block_countries', 'patchstack_geo_block_enabled', 'patchstack_geo_block_inverse', 'patchstack_ip_block_list', 'patchstack_basic_firewall', 'patchstack_autoblock_blocktime', 'patchstack_autoblock_attempts', 'patchstack_autoblock_minutes', 'patchstack_basic_firewall_roles', 'patchstack_disable_htaccess', 'patchstack_add_security_headers', 'patchstack_prevent_default_file_access', 'patchstack_block_debug_log_access', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_image_hotlinking', 'patchstack_firewall_custom_rules', 'patchstack_firewall_custom_rules_loc', 'patchstack_blackhole_log', 'patchstack_whitelist' );
103 + $this->save_options( $options );
104 + break;
105 +
106 + // Save login settings
107 + case 'patchstack_login_settings_group':
108 + $options = array( 'patchstack_block_bruteforce_ips', 'patchstack_anti_bruteforce_blocktime', 'patchstack_anti_bruteforce_attempts', 'patchstack_anti_bruteforce_minutes', 'patchstack_login_time_block', 'patchstack_login_time_start', 'patchstack_login_time_end', 'patchstack_login_2fa', 'patchstack_login_whitelist' );
109 + $this->save_options( $options );
110 + break;
111 +
112 + // Save cookie notice settings
113 + case 'patchstack_cookienotice_settings_group':
114 + $options = array( 'patchstack_enable_cookie_notice_message', 'patchstack_cookie_notice_message', 'patchstack_cookie_notice_accept_text', 'patchstack_cookie_notice_backgroundcolor', 'patchstack_cookie_notice_textcolor', 'patchstack_cookie_notice_privacypolicy_enable', 'patchstack_cookie_notice_privacypolicy_text', 'patchstack_cookie_notice_privacypolicy_link', 'patchstack_cookie_notice_cookie_expiration', 'patchstack_cookie_notice_opacity', 'patchstack_cookie_notice_credits' );
115 + $this->save_options( $options );
116 + break;
117 + }
118 + }
119 +
120 + /**
31 121 * This will be called when the network admin clicks on the "Sites" button.
32 122 * It will show all sites.
33 123 *
34 124 * @return void
@@ -37,33 +127,25 @@
37 127 require_once dirname( __FILE__ ) . '/views/pages/multisite-table.php';
38 128 }
39 129
40 130 /**
41 - * Re-run the migration for a specific multisite site.
42 - *
131 + * Save an array of options on a specific site.
132 + *
133 + * @param array $options
43 134 * @return void
44 135 */
45 - private function run_migration( ) {
46 - // Must be a number.
47 - if ( ! isset( $_GET['site'] ) || ! is_scalar( $_GET['site'] ) || ! ctype_digit( (string) $_GET['site'] ) ) {
48 - exit;
136 + private function save_options( $options ) {
137 + if ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) {
138 + foreach ( $options as $option ) {
139 + $value = isset( $_POST[ $option ] ) ? $_POST[ $option ] : 0;
140 + $value = map_deep($value, 'wp_filter_nohtml_kses');
141 + update_site_option( $option, $value );
142 + }
143 + } else {
144 + foreach ( $options as $option ) {
145 + $value = isset( $_POST[ $option ] ) ? $_POST[ $option ] : 0;
146 + $value = map_deep($value, 'wp_filter_nohtml_kses');
147 + update_option( $option, $value );
148 + }
49 149 }
50 -
51 - // Site must be valid and exists.
52 - $site = function_exists( 'get_site' ) ? get_site( $_GET['site'] ) : null;
53 - if ( is_null( $site ) ) {
54 - exit;
55 - }
56 -
57 - // Perform base migration.
58 - $this->plugin->activation->migrate( null, $site->id );
59 -
60 - // Perform specific version migrations.
61 - $versions = array('3.0.1', '3.0.2');
62 - foreach ( $versions as $version ) {
63 - $this->plugin->activation->migrate( $version, $site->id );
64 - }
65 -
66 - wp_safe_redirect( add_query_arg( [ 'success' => '1', 'site' => $site->id ], remove_query_arg( [ 'PatchstackNonce', 'site' ] ) ) );
67 - exit;
68 150 }
69 151 }