| @@ -17,10 +17,11 @@ | ||
| 17 | 17 | * @return void |
| 18 | 18 | */ |
| 19 | 19 | public function __construct( $core ) { |
| 20 | 20 | parent::__construct( $core ); |
| 21 | - add_action( 'patchstack_post_firewall_rules', [ $this, 'post_firewall_rules' ] ); | |
| 22 | - add_action( 'patchstack_post_dynamic_firewall_rules', [ $this, 'dynamic_firewall_rules' ] ); | |
| 21 | + add_action( 'patchstack_post_firewall_rules', array( $this, 'post_firewall_rules' ) ); | |
| 22 | + add_action( 'patchstack_post_firewall_htaccess_rules', array( $this, 'post_firewall_htaccess_rules' ) ); | |
| 23 | + add_action( 'patchstack_post_dynamic_firewall_rules', array( $this, 'dynamic_firewall_rules' ) ); | |
| 23 | 24 | } |
| 24 | 25 | |
| 25 | 26 | /** |
| 26 | 27 | * Pull the hardening .htaccess rules from the API. |
| @@ -32,22 +33,15 @@ | ||
| 32 | 33 | if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) { |
| 33 | 34 | return; |
| 34 | 35 | } |
| 35 | 36 | |
| 36 | - // Check if server is supported and if htaccess modifications are disabled. | |
| 37 | - if ( get_site_option( 'patchstack_disable_htaccess', 0 ) || ( defined( 'PS_DISABLE_HTACCESS' ) && PS_DISABLE_HTACCESS ) ) { | |
| 38 | - return; | |
| 39 | - } | |
| 40 | - | |
| 41 | 37 | $rules = $this->plugin->htaccess->get_firewall_rule_settings(); |
| 42 | 38 | $settings = json_encode( $rules ); |
| 43 | - $results = $this->plugin->api->post_firewall_rule( [ 'settings' => $settings ] ); | |
| 39 | + $results = $this->plugin->api->post_firewall_rule( array( 'settings' => $settings ) ); | |
| 44 | 40 | |
| 45 | - // If no rules returned (empty, or a status code/null from a failed request), | |
| 46 | - // we assume all settings are turned off. Guard against assigning to a string | |
| 47 | - // offset, which is a fatal error on PHP 7.1+. | |
| 48 | - if ( ! is_array( $results ) ) { | |
| 49 | - $results = [ 'rules' => '' ]; | |
| 41 | + // If no rules returned, we assume all settings are turned off. | |
| 42 | + if ( empty( $results ) ) { | |
| 43 | + $results['rules'] = ''; | |
| 50 | 44 | } |
| 51 | 45 | |
| 52 | 46 | // We have rules so apply it to the .htaccess file. |
| 53 | 47 | if ( isset( $results['rules'] ) ) { |
| @@ -56,8 +50,32 @@ | ||
| 56 | 50 | } |
| 57 | 51 | } |
| 58 | 52 | |
| 59 | 53 | /** |
| 54 | + * Pull the firewall .htaccess rules from the API. | |
| 55 | + * Then apply it to the .htaccess file after we create a backup. | |
| 56 | + * | |
| 57 | + * @return void | |
| 58 | + */ | |
| 59 | + public function post_firewall_htaccess_rules() { | |
| 60 | + if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) { | |
| 61 | + return; | |
| 62 | + } | |
| 63 | + | |
| 64 | + $results = $this->plugin->api->post_firewall_htaccess_rule(); | |
| 65 | + $rules = ! isset( $results['rules'] ) || empty( $results ) ? '' : $results['rules']; | |
| 66 | + | |
| 67 | + // Check if we have to update anything at all. | |
| 68 | + $hash = sha1( $rules ); | |
| 69 | + if ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == $hash || ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == '' && $rules == '' ) ) { | |
| 70 | + return; | |
| 71 | + } | |
| 72 | + | |
| 73 | + // We have rules so apply it to the .htaccess file. | |
| 74 | + update_option( 'patchstack_firewall_htaccess_hash', $hash ); | |
| 75 | + } | |
| 76 | + | |
| 77 | + /** | |
| 60 | 78 | * Pull the firewall/whitelist rules from the API. |
| 61 | 79 | * |
| 62 | 80 | * @return void |
| 63 | 81 | */ |
| @@ -71,74 +89,16 @@ | ||
| 71 | 89 | if ( ! isset( $results['firewall'] ) ) { |
| 72 | 90 | return; |
| 73 | 91 | } |
| 74 | 92 | |
| 75 | - // Separate the new firewall engine rules from the old ones. | |
| 76 | - $newRules = []; | |
| 77 | - $newRulesAP = []; | |
| 78 | - $oldRules = []; | |
| 79 | - | |
| 80 | - // Counters for displaying purposes on the API key page. | |
| 81 | - $vPatchCount = 0; | |
| 82 | - $ruleCount = 0; | |
| 83 | - | |
| 84 | - // Parse the rules. | |
| 85 | - foreach ( $results['firewall'] as $rule ) { | |
| 86 | - if ( isset( $rule['rule_v2'] ) ) { | |
| 87 | - $rule['rules'] = $rule['rule_v2']; | |
| 88 | - unset( $rule['rule_v2'] ); | |
| 89 | - | |
| 90 | - // Mark vPatches based on substring. | |
| 91 | - if ( stripos( $rule['title'], ' vulnerabilit' ) !== false && stripos( $rule['title'], 'block ' ) !== false ) { | |
| 92 | - $vPatchCount++; | |
| 93 | - } else { | |
| 94 | - $ruleCount++; | |
| 95 | - } | |
| 96 | - | |
| 97 | - // Differentiate between auto prepend rules and regular ones. | |
| 98 | - if ( isset( $rule['ap'] ) && !empty( $rule['ap'] ) ) { | |
| 99 | - $newRulesAP[] = $rule; | |
| 100 | - } else { | |
| 101 | - $newRules[] = $rule; | |
| 102 | - } | |
| 103 | - } else { | |
| 104 | - $ruleCount++; | |
| 105 | - $oldRules[] = $rule; | |
| 106 | - } | |
| 107 | - } | |
| 108 | - | |
| 109 | 93 | // Update firewall rules. |
| 110 | - update_option( 'patchstack_firewall_rules', json_encode( $oldRules ), true ); | |
| 111 | - update_option( 'patchstack_firewall_rules_v3', json_encode( $newRules ), true ); | |
| 112 | - update_option( 'patchstack_firewall_rules_v3_ap', json_encode( $newRulesAP ), true ); | |
| 94 | + update_option( 'patchstack_firewall_rules', json_encode( $results['firewall'] ) ); | |
| 113 | 95 | |
| 114 | - // Update the counters. | |
| 115 | - update_option( 'patchstack_vpatches_present', $vPatchCount ); | |
| 116 | - update_option( 'patchstack_non_vpatches_present', $ruleCount ); | |
| 96 | + // Update whitelist rules. | |
| 97 | + update_option( 'patchstack_whitelist_rules', json_encode( $results['whitelists'] ) ); | |
| 117 | 98 | |
| 118 | - // Separate the new firewall engine rules from the old ones. Only touch the | |
| 119 | - // stored whitelists when the API actually returned them, otherwise a partial | |
| 120 | - // response would wipe the existing whitelist rules. | |
| 121 | - if ( isset( $results['whitelists'] ) && is_array( $results['whitelists'] ) ) { | |
| 122 | - $newRules = []; | |
| 123 | - $oldRules = []; | |
| 124 | - foreach ( $results['whitelists'] as $rule ) { | |
| 125 | - if ( isset( $rule['rule_v2'] ) ) { | |
| 126 | - $rule['rules'] = $rule['rule_v2']; | |
| 127 | - unset( $rule['rule_v2'] ); | |
| 128 | - $newRules[] = $rule; | |
| 129 | - } else { | |
| 130 | - $oldRules[] = $rule; | |
| 131 | - } | |
| 132 | - } | |
| 133 | - | |
| 134 | - // Update whitelist rules. | |
| 135 | - update_option( 'patchstack_whitelist_rules', json_encode( $oldRules ), true ); | |
| 136 | - update_option( 'patchstack_whitelist_rules_v3', json_encode( $newRules ), true ); | |
| 137 | - } | |
| 138 | - | |
| 139 | - // Update the whitelisted keys. | |
| 99 | + // Update secondary whitelist rules. | |
| 140 | 100 | if ( isset( $results['whitelist_keys'] ) ) { |
| 141 | - update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ), true ); | |
| 101 | + update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ) ); | |
| 142 | 102 | } |
| 143 | 103 | } |
| 144 | 104 | } |