PluginProbe
Patchstack – WordPress & Plugins Security / 2.2.13
Patchstack – WordPress & Plugins Security v2.2.13
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
patchstack / includes / rules.php

rules.php in Patchstack – WordPress & Plugins Security 2.2.13, at includes/rules.php

144 lines 4.2 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 // Do not allow the file to be called directly.
4 if ( ! defined( 'ABSPATH' ) ) {
5 exit;
6 }
7
8 /**
9 * This class is used to pull the firewall/whitelist rules from our API.
10 */
11 class P_Rules extends P_Core {
12
13 /**
14 * Add the actions required to pull the rules.
15 *
16 * @param Patchstack $core
17 * @return void
18 */
19 public function __construct( $core ) {
20 parent::__construct( $core );
21 add_action( 'patchstack_post_firewall_rules', [ $this, 'post_firewall_rules' ] );
22 add_action( 'patchstack_post_firewall_htaccess_rules', [ $this, 'post_firewall_htaccess_rules' ] );
23 add_action( 'patchstack_post_dynamic_firewall_rules', [ $this, 'dynamic_firewall_rules' ] );
24 }
25
26 /**
27 * Pull the hardening .htaccess rules from the API.
28 * Then apply it to the .htaccess file after we create a backup.
29 *
30 * @return void
31 */
32 public function post_firewall_rules() {
33 if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) {
34 return;
35 }
36
37 $rules = $this->plugin->htaccess->get_firewall_rule_settings();
38 $settings = json_encode( $rules );
39 $results = $this->plugin->api->post_firewall_rule( [ 'settings' => $settings ] );
40
41 // If no rules returned, we assume all settings are turned off.
42 if ( empty( $results ) ) {
43 $results['rules'] = '';
44 }
45
46 // We have rules so apply it to the .htaccess file.
47 if ( isset( $results['rules'] ) ) {
48 $this->plugin->htaccess->write_to_htaccess( $results['rules'] );
49 return;
50 }
51 }
52
53 /**
54 * Pull the firewall .htaccess rules from the API.
55 * Then apply it to the .htaccess file after we create a backup.
56 *
57 * @return void
58 */
59 public function post_firewall_htaccess_rules() {
60 if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) {
61 return;
62 }
63
64 $results = $this->plugin->api->post_firewall_htaccess_rule();
65 $rules = ! isset( $results['rules'] ) || empty( $results ) ? '' : $results['rules'];
66
67 // Check if we have to update anything at all.
68 $hash = sha1( $rules );
69 if ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == $hash || ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == '' && $rules == '' ) ) {
70 return;
71 }
72
73 // We have rules so apply it to the .htaccess file.
74 update_option( 'patchstack_firewall_htaccess_hash', $hash );
75 }
76
77 /**
78 * Pull the firewall/whitelist rules from the API.
79 *
80 * @return void
81 */
82 public function dynamic_firewall_rules() {
83 if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) {
84 return;
85 }
86
87 // Get the firewall and whitelist rules.
88 $results = $this->plugin->api->post_firewall_rule_json();
89 if ( ! isset( $results['firewall'] ) ) {
90 return;
91 }
92
93 // Separate the new firewall engine rules from the old ones.
94 $rules = $results['firewall'];
95 $newRules = [];
96 $oldRules = [];
97 $vPatchCount = 0;
98 $ruleCount = 0;
99 foreach ( $rules as $rule ) {
100 if ( isset( $rule['rule_v2'] ) ) {
101 $rule['rules'] = $rule['rule_v2'];
102 unset($rule['rule_v2']);
103 $newRules[] = $rule;
104
105 if (stripos($rule['title'], ' vulnerabilit') !== false && stripos($rule['title'], 'block ') !== false) {
106 $vPatchCount++;
107 } else {
108 $ruleCount++;
109 }
110 } else {
111 $ruleCount++;
112 $oldRules[] = $rule;
113 }
114 }
115
116 // Update firewall rules.
117 update_option( 'patchstack_firewall_rules', json_encode( $oldRules ), true );
118 update_option( 'patchstack_firewall_rules_v3', json_encode( $newRules ), true );
119 update_option( 'patchstack_vpatches_present', $vPatchCount );
120 update_option( 'patchstack_non_vpatches_present', $ruleCount );
121
122 // Separate the new firewall engine rules from the old ones.
123 $rules = $results['whitelists'];
124 $newRules = [];
125 $oldRules = [];
126 foreach ( $rules as $rule ) {
127 if ( isset( $rule['rule_v2'] ) ) {
128 $rule['rules'] = $rule['rule_v2'];
129 unset($rule['rule_v2']);
130 $newRules[] = $rule;
131 } else {
132 $oldRules[] = $rule;
133 }
134 }
135
136 // Update whitelist rules.
137 update_option( 'patchstack_whitelist_rules', json_encode( $oldRules ), true );
138 update_option( 'patchstack_whitelist_rules_v3', json_encode( $newRules ), true );
139
140 // Update the whitelisted keys.
141 update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ), true );
142 }
143 }
144