| @@ -18,9 +18,9 @@ | ||
| 18 | 18 | * @return void |
| 19 | 19 | */ |
| 20 | 20 | public function __construct( $core ) { |
| 21 | 21 | parent::__construct( $core ); |
| 22 | - add_action( 'admin_init', array( $this, 'settings_init' ) ); | |
| 22 | + add_action( 'admin_init', [ $this, 'settings_init' ] ); | |
| 23 | 23 | } |
| 24 | 24 | |
| 25 | 25 | /** |
| 26 | 26 | * All options and their default values. |
| @@ -26,9 +26,9 @@ | ||
| 26 | 26 | * All options and their default values. |
| 27 | 27 | * |
| 28 | 28 | * @var array |
| 29 | 29 | */ |
| 30 | - public $options = array( | |
| 30 | + public $options = [ | |
| 31 | 31 | // Hardening options. |
| 32 | 32 | 'patchstack_pluginedit' => 1, |
| 33 | 33 | 'patchstack_userenum' => 1, |
| 34 | 34 | 'patchstack_basicscanblock' => 1, |
| @@ -52,21 +52,23 @@ | ||
| 52 | 52 | 'patchstack_captcha_on_comments' => 0, |
| 53 | 53 | 'patchstack_prevent_default_file_access' => 1, |
| 54 | 54 | 'patchstack_register_email_blacklist' => '', |
| 55 | 55 | 'patchstack_json_is_disabled' => 0, |
| 56 | - 'patchstack_auto_update' => array(), | |
| 56 | + 'patchstack_auto_update' => [], | |
| 57 | 57 | 'patchstack_application_passwords_disabled' => 1, |
| 58 | 58 | |
| 59 | 59 | // The firewall and whitelist rules. |
| 60 | 60 | 'patchstack_firewall_rules' => '', |
| 61 | + 'patchstack_firewall_rules_v3' => '[]', | |
| 61 | 62 | 'patchstack_whitelist_rules' => '', |
| 62 | - 'patchstack_custom_whitelist_rules' => '', | |
| 63 | + 'patchstack_whitelist_rules_v3' => '[]', | |
| 63 | 64 | 'patchstack_whitelist_keys_rules' => '', |
| 64 | 65 | |
| 65 | 66 | // Firewall options. |
| 66 | 67 | 'patchstack_basic_firewall' => 1, |
| 67 | - 'patchstack_basic_firewall_roles' => array( 'administrator', 'editor', 'author', 'contributor' ), | |
| 68 | + 'patchstack_basic_firewall_roles' => [ 'administrator', 'editor', 'author', 'contributor' ], | |
| 68 | 69 | 'patchstack_firewall_ip_header' => '', |
| 70 | + 'patchstack_ip_header_computed' => 0, | |
| 69 | 71 | 'patchstack_disable_htaccess' => 0, |
| 70 | 72 | 'patchstack_known_blacklist' => 0, |
| 71 | 73 | 'patchstack_block_debug_log_access' => 1, |
| 72 | 74 | 'patchstack_block_fake_bots' => 1, |
| @@ -83,14 +85,15 @@ | ||
| 83 | 85 | 'patchstack_blocked_attacks' => 0, |
| 84 | 86 | 'patchstack_ip_block_list' => '', |
| 85 | 87 | 'patchstack_geo_block_enabled' => 0, |
| 86 | 88 | 'patchstack_geo_block_inverse' => 0, |
| 87 | - 'patchstack_geo_block_countries' => array(), | |
| 89 | + 'patchstack_geo_block_countries' => [], | |
| 88 | 90 | |
| 89 | 91 | // Cookie notice options. |
| 92 | + 'patchstack_enable_cookie_notice_message' => 0, | |
| 90 | 93 | 'patchstack_cookie_notice_message' => 'We use cookies for various purposes including analytics and personalized marketing. By continuing to use the service, you agree to our use of cookies.', |
| 91 | - 'patchstack_cookie_notice_backgroundcolor' => '#222222', | |
| 92 | - 'patchstack_cookie_notice_textcolor' => '#ffffff', | |
| 94 | + 'patchstack_cookie_notice_backgroundcolor' => '222222', | |
| 95 | + 'patchstack_cookie_notice_textcolor' => 'ffffff', | |
| 93 | 96 | 'patchstack_cookie_notice_privacypolicy_enable' => 0, |
| 94 | 97 | 'patchstack_cookie_notice_privacypolicy_text' => 'Cookie Policy', |
| 95 | 98 | 'patchstack_cookie_notice_privacypolicy_link' => '#', |
| 96 | 99 | 'patchstack_cookie_notice_cookie_expiration' => 'after_exit', |
| @@ -115,19 +118,32 @@ | ||
| 115 | 118 | // General options. |
| 116 | 119 | 'patchstack_blackhole_log' => '', |
| 117 | 120 | 'patchstack_software_data_hash' => '', |
| 118 | 121 | 'patchstack_firewall_htaccess_hash' => '', |
| 122 | + 'patchstack_license_expiry' => '', | |
| 119 | 123 | 'patchstack_clientid' => false, |
| 120 | 124 | 'patchstack_secretkey' => false, |
| 125 | + 'patchstack_secretkey_nonce' => '', | |
| 121 | 126 | 'patchstack_license_free' => 0, |
| 122 | 127 | 'patchstack_api_token' => '', |
| 128 | + 'patchstack_subscription_class' => '', | |
| 129 | + 'patchstack_last_license_check' => 0, | |
| 123 | 130 | 'patchstack_whitelist' => '', |
| 124 | 131 | 'patchstack_show_settings' => 0, |
| 132 | + 'patchstack_firewall_log_lastid' => 0, | |
| 133 | + 'patchstack_eventlog_lastid' => 0, | |
| 134 | + 'patchstack_ott_action' => '', | |
| 135 | + 'patchstack_enc_nonce' => '', | |
| 136 | + 'patchstack_managed' => false, | |
| 137 | + 'patchstack_managed_text' => '', | |
| 138 | + 'patchstack_latest_vulnerable' => [], | |
| 139 | + 'patchstack_site_id' => 0, | |
| 125 | 140 | |
| 126 | 141 | // Admin page rename options. |
| 127 | 142 | 'patchstack_mv_wp_login' => 0, |
| 128 | 143 | 'patchstack_rename_wp_login' => 'swlogin', |
| 129 | - ); | |
| 144 | + 'patchstack_rename_wp_login_whitelist' => [] | |
| 145 | + ]; | |
| 130 | 146 | |
| 131 | 147 | /** |
| 132 | 148 | * Register all the options, if not set already. |
| 133 | 149 | * |
| @@ -147,16 +163,24 @@ | ||
| 147 | 163 | |
| 148 | 164 | // Multisite options |
| 149 | 165 | add_network_option( null, 'patchstack_multisite_installed', 0 ); |
| 150 | 166 | |
| 167 | + // Get the class value and convert. | |
| 168 | + $class = get_option( 'patchstack_subscription_class', '' ); | |
| 169 | + $is_community = $class != '' && (int) $class === 0; | |
| 170 | + | |
| 151 | 171 | // All (sub)sections that show up. |
| 152 | 172 | add_settings_section( 'patchstack_settings_section_hardening', __( 'Security Configurations', 'patchstack' ), false, 'patchstack_hardening_settings' ); |
| 153 | 173 | add_settings_section( 'patchstack_settings_section_hardening_captcha', __( '<hr style="height:1px;border:none;background-color: rgba(170, 189, 215, 0.1);"><br /> reCAPTCHA<br /><span style="font-size: 13px; color: #d0d0d0;">It should be noted that the reCAPTCHA feature only applies to WordPress its core features at this time. Not custom forms or of third party plugins.</span>', 'patchstack' ), false, 'patchstack_hardening_settings' ); |
| 154 | 174 | add_settings_section( 'patchstack_settings_section_firewall', __( 'Firewall settings', 'patchstack' ), false, 'patchstack_firewall_settings' ); |
| 155 | - if ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) { | |
| 175 | + if ( ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) && ! $is_community ) { | |
| 156 | 176 | add_settings_section( 'patchstack_settings_section_firewall_htaccess', __( '.htaccess Features', 'patchstack' ), false, 'patchstack_firewall_settings' ); |
| 157 | 177 | } |
| 158 | - add_settings_section( 'patchstack_settings_section_firewall_geo', __( 'Country Blocking', 'patchstack' ), false, 'patchstack_firewall_settings' ); | |
| 178 | + | |
| 179 | + if (! $is_community ) { | |
| 180 | + add_settings_section( 'patchstack_settings_section_firewall_geo', __( 'Country Blocking', 'patchstack' ), false, 'patchstack_firewall_settings' ); | |
| 181 | + } | |
| 182 | + | |
| 159 | 183 | add_settings_section( 'patchstack_settings_section_firewall_wlbl', __( 'IP Whitelist & Blacklist', 'patchstack' ), false, 'patchstack_firewall_settings' ); |
| 160 | 184 | add_settings_section( 'patchstack_settings_section_cookienotice', __( 'Cookie Notice Settings', 'patchstack' ), false, 'patchstack_cookienotice_settings' ); |
| 161 | 185 | add_settings_section( 'patchstack_settings_section_login', __( 'Login Protection', 'patchstack' ), false, 'patchstack_login_settings' ); |
| 162 | 186 | add_settings_section( 'patchstack_settings_section_login_2fa', __( '<hr style="height:1px;border:none;background-color: rgba(170, 189, 215, 0.1);"><br /> Two Factor Authentication', 'patchstack' ), false, 'patchstack_login_settings' ); |
| @@ -164,83 +188,89 @@ | ||
| 164 | 188 | add_settings_section( 'patchstack_settings_section_login_whitelist', __( '<hr style="height:1px;border:none;background-color: rgba(170, 189, 215, 0.1);"><br /> Whitelisted IP Addresses', 'patchstack' ), false, 'patchstack_login_settings' ); |
| 165 | 189 | |
| 166 | 190 | // Hardening. |
| 167 | 191 | if ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) { |
| 168 | - add_settings_field( 'patchstack_rm_readme', __( 'Remove readme.html', 'patchstack' ), array( $this, 'patchstack_rm_readme_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 169 | - add_settings_field( 'patchstack_auto_update', __( 'Auto Update Software', 'patchstack' ), array( $this, 'patchstack_auto_update_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 192 | + add_settings_field( 'patchstack_rm_readme', __( 'Remove readme.html', 'patchstack' ), [ $this, 'patchstack_rm_readme_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 193 | + add_settings_field( 'patchstack_auto_update', __( 'Auto Update Software', 'patchstack' ), [ $this, 'patchstack_auto_update_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 170 | 194 | } |
| 171 | - add_settings_field( 'patchstack_basicscanblock', __( 'Stop readme.txt Scans', 'patchstack' ), array( $this, 'patchstack_basicscanblock_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 172 | - add_settings_field( 'patchstack_userenum', __( 'Disable user enumeration', 'patchstack' ), array( $this, 'patchstack_userenum_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 173 | - add_settings_field( 'patchstack_hidewpversion', __( 'Hide WordPress version', 'patchstack' ), array( $this, 'patchstack_hidewpversion_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 174 | - add_settings_field( 'patchstack_activity_log_is_enabled', __( 'Enable activity log', 'patchstack' ), array( $this, 'patchstack_activity_log_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 175 | - add_settings_field( 'patchstack_activity_log_failed_logins', __( 'Log failed logins', 'patchstack' ), array( $this, 'patchstack_activity_log_failed_logins_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 176 | - add_settings_field( 'patchstack_activity_log_failed_logins_db', __( 'Upload failed logins to Patchstack', 'patchstack' ), array( $this, 'patchstack_activity_log_failed_logins_db_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 177 | - add_settings_field( 'patchstack_application_passwords_disabled', __( 'Block Application Passwords', 'patchstack' ), array( $this, 'patchstack_application_passwords_disabled_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 178 | - add_settings_field( 'patchstack_xmlrpc_is_disabled', __( 'Restrict XML-RPC Access', 'patchstack' ), array( $this, 'patchstack_xmlrpc_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 179 | - add_settings_field( 'patchstack_json_is_disabled', __( 'Restrict WP REST API Access', 'patchstack' ), array( $this, 'patchstack_json_is_disabled_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 180 | - add_settings_field( 'patchstack_register_email_blacklist', __( 'Registration Email Blacklist', 'patchstack' ), array( $this, 'patchstack_register_email_blacklist_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 195 | + add_settings_field( 'patchstack_basicscanblock', __( 'Stop readme.txt Scans', 'patchstack' ), [ $this, 'patchstack_basicscanblock_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 196 | + add_settings_field( 'patchstack_pluginedit', __( 'Disable theme editor', 'patchstack' ), [ $this, 'patchstack_pluginedit_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 197 | + add_settings_field( 'patchstack_userenum', __( 'Disable user enumeration', 'patchstack' ), [ $this, 'patchstack_userenum_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 198 | + add_settings_field( 'patchstack_hidewpversion', __( 'Hide WordPress version', 'patchstack' ), [ $this, 'patchstack_hidewpversion_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 199 | + add_settings_field( 'patchstack_activity_log_is_enabled', __( 'Enable activity log', 'patchstack' ), [ $this, 'patchstack_activity_log_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 200 | + add_settings_field( 'patchstack_activity_log_failed_logins', __( 'Log failed logins', 'patchstack' ), [ $this, 'patchstack_activity_log_failed_logins_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 201 | + add_settings_field( 'patchstack_activity_log_failed_logins_db', __( 'Upload failed logins to Patchstack', 'patchstack' ), [ $this, 'patchstack_activity_log_failed_logins_db_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 202 | + add_settings_field( 'patchstack_application_passwords_disabled', __( 'Block Application Passwords', 'patchstack' ), [ $this, 'patchstack_application_passwords_disabled_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 203 | + add_settings_field( 'patchstack_xmlrpc_is_disabled', __( 'Restrict XML-RPC Access', 'patchstack' ), [ $this, 'patchstack_xmlrpc_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 204 | + add_settings_field( 'patchstack_json_is_disabled', __( 'Restrict WP REST API Access', 'patchstack' ), [ $this, 'patchstack_json_is_disabled_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 205 | + add_settings_field( 'patchstack_register_email_blacklist', __( 'Registration Email Blacklist', 'patchstack' ), [ $this, 'patchstack_register_email_blacklist_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening' ); | |
| 181 | 206 | |
| 182 | 207 | // reCAPTCHA. |
| 183 | - add_settings_field( 'patchstack_captcha_on_comments', __( 'Post comments form', 'patchstack' ), array( $this, 'patchstack_captcha_on_comments_callback' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 184 | - add_settings_field( 'patchstack_captcha_login_form', __( 'Login form', 'patchstack' ), array( $this, 'patchstack_captcha_login_form_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 185 | - add_settings_field( 'patchstack_captcha_registration_form', __( 'Registration form', 'patchstack' ), array( $this, 'patchstack_captcha_registration_form_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 186 | - add_settings_field( 'patchstack_captcha_reset_pwd_form', __( 'Password reset form', 'patchstack' ), array( $this, 'patchstack_captcha_reset_pwd_form_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 187 | - add_settings_field( 'patchstack_captcha_type', __( 'reCAPTCHA version (invisible/normal)' ), array( $this, 'patchstack_captcha_type_callback' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 188 | - add_settings_field( 'patchstack_captcha_public_key', __( 'Site Key ', 'patchstack' ), array( $this, 'patchstack_captcha_public_key_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 189 | - add_settings_field( 'patchstack_captcha_private_key', __( 'Secret Key', 'patchstack' ), array( $this, 'patchstack_captcha_private_key_input' ), 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 208 | + add_settings_field( 'patchstack_captcha_on_comments', __( 'Post comments form', 'patchstack' ), [ $this, 'patchstack_captcha_on_comments_callback' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 209 | + add_settings_field( 'patchstack_captcha_login_form', __( 'Login form', 'patchstack' ), [ $this, 'patchstack_captcha_login_form_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 210 | + add_settings_field( 'patchstack_captcha_registration_form', __( 'Registration form', 'patchstack' ), [ $this, 'patchstack_captcha_registration_form_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 211 | + add_settings_field( 'patchstack_captcha_reset_pwd_form', __( 'Password reset form', 'patchstack' ), [ $this, 'patchstack_captcha_reset_pwd_form_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 212 | + add_settings_field( 'patchstack_captcha_type', __( 'reCAPTCHA version (invisible/normal)' ), [ $this, 'patchstack_captcha_type_callback' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 213 | + add_settings_field( 'patchstack_captcha_public_key', __( 'Site Key ', 'patchstack' ), [ $this, 'patchstack_captcha_public_key_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 214 | + add_settings_field( 'patchstack_captcha_private_key', __( 'Secret Key', 'patchstack' ), [ $this, 'patchstack_captcha_private_key_input' ], 'patchstack_hardening_settings', 'patchstack_settings_section_hardening_captcha' ); | |
| 190 | 215 | |
| 191 | 216 | // Firewall. |
| 192 | - add_settings_field( 'patchstack_basic_firewall', __( 'Enable firewall', 'patchstack' ), array( $this, 'patchstack_basic_firewall_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 193 | - add_settings_field( 'patchstack_basic_firewall_roles', __( 'Firewall user role whitelist', 'patchstack' ), array( $this, 'patchstack_basic_firewall_roles_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 194 | - add_settings_field( 'patchstack_basic_firewall_geo_enabled', __( 'Country Blocking Enabled', 'patchstack' ), array( $this, 'patchstack_basic_firewall_geo_enabled_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 195 | - add_settings_field( 'patchstack_basic_firewall_geo_inverse', __( 'Inversed Check', 'patchstack' ), array( $this, 'patchstack_basic_firewall_geo_inverse_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 196 | - add_settings_field( 'patchstack_basic_firewall_geo_countries', __( 'Countries To Block', 'patchstack' ), array( $this, 'patchstack_basic_firewall_geo_countries_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 197 | - if ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) { | |
| 198 | - add_settings_field( 'patchstack_firewall_ip_header', __( 'IP Address Header Override', 'patchstack' ), array( $this, 'patchstack_firewall_ip_header_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 199 | - add_settings_field( 'patchstack_disable_htaccess', __( 'Disable .htaccess features', 'patchstack' ), array( $this, 'patchstack_disable_htaccess_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 200 | - add_settings_field( 'patchstack_add_security_headers', __( 'Add security headers', 'patchstack' ), array( $this, 'patchstack_add_security_headers_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 201 | - add_settings_field( 'patchstack_prevent_default_file_access', __( 'Prevent default WordPress file access', 'patchstack' ), array( $this, 'patchstack_prevent_default_file_access_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 202 | - add_settings_field( 'patchstack_block_debug_log_access', __( 'Block access to debug.log file', 'patchstack' ), array( $this, 'patchstack_block_debug_log_access_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 203 | - add_settings_field( 'patchstack_index_views', __( 'Disable index views', 'patchstack' ), array( $this, 'patchstack_index_views_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 204 | - add_settings_field( 'patchstack_proxy_comment_posting', __( 'Forbid proxy comment posting', 'patchstack' ), array( $this, 'patchstack_proxy_comment_posting_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 205 | - add_settings_field( 'patchstack_image_hotlinking', __( 'Prevent image hotlinking', 'patchstack' ), array( $this, 'patchstack_image_hotlinking_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 206 | - add_settings_field( 'patchstack_firewall_custom_rules', __( 'Add custom .htaccess rules here', 'patchstack' ), array( $this, 'patchstack_firewall_custom_rules_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 207 | - add_settings_field( 'patchstack_firewall_custom_rules_loc', __( 'Custom .htaccess rules location', 'patchstack' ), array( $this, 'patchstack_firewall_custom_rules_loc_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 217 | + add_settings_field( 'patchstack_basic_firewall', __( 'Enable firewall', 'patchstack' ), [ $this, 'patchstack_basic_firewall_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 218 | + add_settings_field( 'patchstack_basic_firewall_roles', __( 'Firewall user role whitelist', 'patchstack' ), [ $this, 'patchstack_basic_firewall_roles_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 219 | + | |
| 220 | + if ( ! $is_community ) { | |
| 221 | + add_settings_field( 'patchstack_basic_firewall_geo_enabled', __( 'Country Blocking Enabled', 'patchstack' ), [ $this, 'patchstack_basic_firewall_geo_enabled_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 222 | + add_settings_field( 'patchstack_basic_firewall_geo_inverse', __( 'Inversed Check', 'patchstack' ), [ $this, 'patchstack_basic_firewall_geo_inverse_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 223 | + add_settings_field( 'patchstack_basic_firewall_geo_countries', __( 'Countries To Block', 'patchstack' ), [ $this, 'patchstack_basic_firewall_geo_countries_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_geo' ); | |
| 208 | 224 | } |
| 209 | - add_settings_field( 'patchstack_blackhole_log', __( 'Block IP List', 'patchstack' ), array( $this, 'patchstack_blackhole_log_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_wlbl' ); | |
| 210 | - add_settings_field( 'patchstack_whitelist', __( 'Whitelist', 'patchstack' ), array( $this, 'patchstack_whitelist_input' ), 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_wlbl' ); | |
| 211 | 225 | |
| 226 | + add_settings_field( 'patchstack_firewall_ip_header', __( 'IP Address Header Override', 'patchstack' ), [ $this, 'patchstack_firewall_ip_header_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall' ); | |
| 227 | + | |
| 228 | + if ( ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) && ! $is_community ) { | |
| 229 | + add_settings_field( 'patchstack_disable_htaccess', __( 'Disable .htaccess features', 'patchstack' ), [ $this, 'patchstack_disable_htaccess_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 230 | + add_settings_field( 'patchstack_add_security_headers', __( 'Add security headers', 'patchstack' ), [ $this, 'patchstack_add_security_headers_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 231 | + add_settings_field( 'patchstack_prevent_default_file_access', __( 'Prevent default WordPress file access', 'patchstack' ), [ $this, 'patchstack_prevent_default_file_access_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 232 | + add_settings_field( 'patchstack_block_debug_log_access', __( 'Block access to debug.log file', 'patchstack' ), [ $this, 'patchstack_block_debug_log_access_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 233 | + add_settings_field( 'patchstack_index_views', __( 'Disable index views', 'patchstack' ), [ $this, 'patchstack_index_views_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 234 | + add_settings_field( 'patchstack_proxy_comment_posting', __( 'Forbid proxy comment posting', 'patchstack' ), [ $this, 'patchstack_proxy_comment_posting_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 235 | + add_settings_field( 'patchstack_image_hotlinking', __( 'Prevent image hotlinking', 'patchstack' ), [ $this, 'patchstack_image_hotlinking_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 236 | + add_settings_field( 'patchstack_firewall_custom_rules', __( 'Add custom .htaccess rules here', 'patchstack' ), [ $this, 'patchstack_firewall_custom_rules_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 237 | + add_settings_field( 'patchstack_firewall_custom_rules_loc', __( 'Custom .htaccess rules location', 'patchstack' ), [ $this, 'patchstack_firewall_custom_rules_loc_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_htaccess' ); | |
| 238 | + } | |
| 239 | + add_settings_field( 'patchstack_blackhole_log', __( 'Block IP List', 'patchstack' ), [ $this, 'patchstack_blackhole_log_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_wlbl' ); | |
| 240 | + add_settings_field( 'patchstack_whitelist', __( 'Whitelist', 'patchstack' ), [ $this, 'patchstack_whitelist_input' ], 'patchstack_firewall_settings', 'patchstack_settings_section_firewall_wlbl' ); | |
| 241 | + | |
| 212 | 242 | // Login protection. |
| 213 | 243 | if ( ( ! is_multisite() || ( isset( $_GET['page'] ) && $_GET['page'] == 'patchstack-multisite-settings' ) ) && floatval( substr( phpversion(), 0, 5 ) ) > 5.5 ) { |
| 214 | - add_settings_field( 'patchstack_mv_wp_login', __( 'Move and rename login page', 'patchstack' ), array( $this, 'patchstack_hidewplogin_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 215 | - add_settings_field( 'patchstack_rename_wp_login', '', array( $this, 'patchstack_hidewplogin_rename_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 244 | + add_settings_field( 'patchstack_mv_wp_login', __( 'Block access to wp-login.php', 'patchstack' ), [ $this, 'patchstack_hidewplogin_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 245 | + add_settings_field( 'patchstack_rename_wp_login', '', [ $this, 'patchstack_hidewplogin_rename_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 216 | 246 | } |
| 217 | - add_settings_field( 'patchstack_block_bruteforce_ips', __( 'Automatic brute-force IP ban', 'patchstack' ), array( $this, 'patchstack_block_bruteforce_ips_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 218 | - add_settings_field( 'patchstack_login_time_block', __( 'Logon hours', 'patchstack' ), array( $this, 'patchstack_login_time_block_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 219 | - add_settings_field( 'patchstack_login_2fa', __( 'Two Factor Authentication', 'patchstack' ), array( $this, 'patchstack_login_2fa_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login_2fa' ); | |
| 220 | - add_settings_field( 'patchstack_login_blocked', __( 'Blocked', 'patchstack' ), array( $this, 'patchstack_login_blocked_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login_blocked' ); | |
| 221 | - add_settings_field( 'patchstack_login_whitelist', __( 'Whitelist', 'patchstack' ), array( $this, 'patchstack_login_whitelist_input' ), 'patchstack_login_settings', 'patchstack_settings_section_login_whitelist' ); | |
| 247 | + add_settings_field( 'patchstack_block_bruteforce_ips', __( 'Automatic brute-force IP ban', 'patchstack' ), [ $this, 'patchstack_block_bruteforce_ips_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 248 | + add_settings_field( 'patchstack_login_time_block', __( 'Logon hours', 'patchstack' ), [ $this, 'patchstack_login_time_block_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login' ); | |
| 249 | + add_settings_field( 'patchstack_login_2fa', __( 'Two Factor Authentication', 'patchstack' ), [ $this, 'patchstack_login_2fa_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login_2fa' ); | |
| 250 | + add_settings_field( 'patchstack_login_blocked', __( 'Blocked', 'patchstack' ), [ $this, 'patchstack_login_blocked_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login_blocked' ); | |
| 251 | + add_settings_field( 'patchstack_login_whitelist', __( 'Whitelist', 'patchstack' ), [ $this, 'patchstack_login_whitelist_input' ], 'patchstack_login_settings', 'patchstack_settings_section_login_whitelist' ); | |
| 222 | 252 | |
| 223 | 253 | // Cookie notice. |
| 224 | - add_settings_field( 'patchstack_enable_cookie_notice_message', 'Enable Cookie Notice', array( $this, 'patchstack_enable_cookie_notice_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 225 | - add_settings_field( 'patchstack_cookie_notice_message', 'Enter message for displaying', array( $this, 'patchstack_cookie_notice_message_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 226 | - add_settings_field( 'patchstack_cookie_notice_accept_text', 'Cookie acceptance button text', array( $this, 'patchstack_cookie_notice_accept_text_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 227 | - add_settings_field( 'patchstack_cookie_notice_backgroundcolor', 'Background color (HEX)', array( $this, 'patchstack_cookie_notice_backgroundcolor_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 228 | - add_settings_field( 'patchstack_cookie_notice_textcolor', 'Text color (HEX)', array( $this, 'patchstack_cookie_notice_textcolor_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 229 | - add_settings_field( 'patchstack_cookie_notice_privacypolicy_enable', 'Enable Policy Link', array( $this, 'patchstack_cookie_notice_privacypolicy_enable_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 230 | - add_settings_field( 'patchstack_cookie_notice_privacypolicy_text', 'Enter Policy Text', array( $this, 'patchstack_cookie_notice_privacypolicy_text_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 231 | - add_settings_field( 'patchstack_cookie_notice_privacypolicy_link', 'Enter Policy Link', array( $this, 'patchstack_cookie_notice_privacypolicy_link_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 232 | - add_settings_field( 'patchstack_cookie_notice_cookie_expiration', 'When to ask user permission again', array( $this, 'patchstack_cookie_notice_cookie_expiration_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 233 | - add_settings_field( 'patchstack_cookie_notice_opacity', 'Background opacity (in percentage)', array( $this, 'patchstack_cookie_notice_opacity_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 234 | - add_settings_field( 'patchstack_cookie_notice_credits', 'Display Patchstack credits', array( $this, 'patchstack_cookie_notice_credits_callback' ), 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 254 | + add_settings_field( 'patchstack_enable_cookie_notice_message', 'Enable Cookie Notice', [ $this, 'patchstack_enable_cookie_notice_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 255 | + add_settings_field( 'patchstack_cookie_notice_message', 'Enter message for displaying', [ $this, 'patchstack_cookie_notice_message_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 256 | + add_settings_field( 'patchstack_cookie_notice_accept_text', 'Cookie acceptance button text', [ $this, 'patchstack_cookie_notice_accept_text_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 257 | + add_settings_field( 'patchstack_cookie_notice_backgroundcolor', 'Background color (HEX)', [ $this, 'patchstack_cookie_notice_backgroundcolor_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 258 | + add_settings_field( 'patchstack_cookie_notice_textcolor', 'Text color (HEX)', [ $this, 'patchstack_cookie_notice_textcolor_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 259 | + add_settings_field( 'patchstack_cookie_notice_privacypolicy_enable', 'Enable Policy Link', [ $this, 'patchstack_cookie_notice_privacypolicy_enable_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 260 | + add_settings_field( 'patchstack_cookie_notice_privacypolicy_text', 'Enter Policy Text', [ $this, 'patchstack_cookie_notice_privacypolicy_text_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 261 | + add_settings_field( 'patchstack_cookie_notice_privacypolicy_link', 'Enter Policy Link', [ $this, 'patchstack_cookie_notice_privacypolicy_link_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 262 | + add_settings_field( 'patchstack_cookie_notice_cookie_expiration', 'When to ask user permission again', [ $this, 'patchstack_cookie_notice_cookie_expiration_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 263 | + add_settings_field( 'patchstack_cookie_notice_opacity', 'Background opacity (in percentage)', [ $this, 'patchstack_cookie_notice_opacity_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 264 | + add_settings_field( 'patchstack_cookie_notice_credits', 'Display Patchstack credits', [ $this, 'patchstack_cookie_notice_credits_callback' ], 'patchstack_cookienotice_settings', 'patchstack_settings_section_cookienotice' ); | |
| 235 | 265 | |
| 236 | 266 | // Register the group settings. |
| 237 | - $settings = array( | |
| 238 | - 'hardening' => array( 'patchstack_auto_update', 'patchstack_json_is_disabled', 'patchstack_register_email_blacklist', 'patchstack_pluginedit', 'patchstack_basicscanblock', 'patchstack_userenum', 'patchstack_rm_readme', 'patchstack_hidewpcontent', 'patchstack_hidewpversion', 'patchstack_activity_log_is_enabled', 'patchstack_activity_log_failed_logins', 'patchstack_activity_log_failed_logins_db', 'patchstack_movewpconfig', 'patchstack_captcha_on_comments', 'patchstack_captcha_login_form', 'patchstack_captcha_registration_form', 'patchstack_captcha_reset_pwd_form', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_captcha_type', 'patchstack_captcha_public_key_v3', 'patchstack_captcha_private_key_v3', 'patchstack_captcha_public_key_v3_new', 'patchstack_captcha_private_key_v3_new', 'patchstack_xmlrpc_is_disabled', 'patchstack_application_passwords_disabled' ), | |
| 239 | - 'firewall' => array( 'patchstack_geo_block_enabled', 'patchstack_geo_block_inverse', 'patchstack_basic_firewall_geo_countries', 'patchstack_ip_block_list', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_firewall_ip_header', 'patchstack_basic_firewall_roles', 'patchstack_disable_htaccess', 'patchstack_add_security_headers', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_firewall_custom_rules', 'patchstack_firewall_custom_rules_loc', 'patchstack_blackhole_log', 'patchstack_whitelist', 'patchstack_autoblock_blocktime', 'patchstack_autoblock_attempts', 'patchstack_autoblock_minutes' ), | |
| 240 | - 'cookienotice' => array( 'patchstack_enable_cookie_notice_message', 'patchstack_cookie_notice_message', 'patchstack_cookie_notice_backgroundcolor', 'patchstack_cookie_notice_textcolor', 'patchstack_cookie_notice_privacypolicy_enable', 'patchstack_cookie_notice_privacypolicy_text', 'patchstack_cookie_notice_privacypolicy_link', 'patchstack_cookie_notice_cookie_expiration', 'patchstack_cookie_notice_opacity', 'patchstack_cookie_notice_accept_text', 'patchstack_cookie_notice_credits' ), | |
| 241 | - 'login' => array( 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_block_bruteforce_ips', 'patchstack_anti_bruteforce_attempts', 'patchstack_anti_bruteforce_minutes', 'patchstack_anti_bruteforce_blocktime', 'patchstack_login_time_block', 'patchstack_login_time_start', 'patchstack_login_time_end', 'patchstack_login_2fa', 'patchstack_login_blocked', 'patchstack_login_whitelist' ), | |
| 242 | - ); | |
| 267 | + $settings = [ | |
| 268 | + 'hardening' => [ 'patchstack_auto_update', 'patchstack_json_is_disabled', 'patchstack_register_email_blacklist', 'patchstack_pluginedit', 'patchstack_basicscanblock', 'patchstack_userenum', 'patchstack_rm_readme', 'patchstack_hidewpcontent', 'patchstack_hidewpversion', 'patchstack_activity_log_is_enabled', 'patchstack_activity_log_failed_logins', 'patchstack_activity_log_failed_logins_db', 'patchstack_movewpconfig', 'patchstack_captcha_on_comments', 'patchstack_captcha_login_form', 'patchstack_captcha_registration_form', 'patchstack_captcha_reset_pwd_form', 'patchstack_captcha_public_key', 'patchstack_captcha_private_key', 'patchstack_captcha_type', 'patchstack_captcha_public_key_v3', 'patchstack_captcha_private_key_v3', 'patchstack_captcha_public_key_v3_new', 'patchstack_captcha_private_key_v3_new', 'patchstack_xmlrpc_is_disabled', 'patchstack_application_passwords_disabled' ], | |
| 269 | + 'firewall' => [ 'patchstack_geo_block_enabled', 'patchstack_geo_block_inverse', 'patchstack_basic_firewall_geo_countries', 'patchstack_ip_block_list', 'patchstack_prevent_default_file_access', 'patchstack_basic_firewall', 'patchstack_firewall_ip_header', 'patchstack_basic_firewall_roles', 'patchstack_disable_htaccess', 'patchstack_add_security_headers', 'patchstack_known_blacklist', 'patchstack_block_debug_log_access', 'patchstack_block_fake_bots', 'patchstack_index_views', 'patchstack_proxy_comment_posting', 'patchstack_bad_query_strings', 'patchstack_advanced_character_string_filter', 'patchstack_advanced_blacklist_firewall', 'patchstack_forbid_rfi', 'patchstack_image_hotlinking', 'patchstack_firewall_custom_rules', 'patchstack_firewall_custom_rules_loc', 'patchstack_blackhole_log', 'patchstack_whitelist', 'patchstack_autoblock_blocktime', 'patchstack_autoblock_attempts', 'patchstack_autoblock_minutes' ], | |
| 270 | + 'cookienotice' => [ 'patchstack_enable_cookie_notice_message', 'patchstack_cookie_notice_message', 'patchstack_cookie_notice_backgroundcolor', 'patchstack_cookie_notice_textcolor', 'patchstack_cookie_notice_privacypolicy_enable', 'patchstack_cookie_notice_privacypolicy_text', 'patchstack_cookie_notice_privacypolicy_link', 'patchstack_cookie_notice_cookie_expiration', 'patchstack_cookie_notice_opacity', 'patchstack_cookie_notice_accept_text', 'patchstack_cookie_notice_credits' ], | |
| 271 | + 'login' => [ 'patchstack_mv_wp_login', 'patchstack_rename_wp_login', 'patchstack_block_bruteforce_ips', 'patchstack_anti_bruteforce_attempts', 'patchstack_anti_bruteforce_minutes', 'patchstack_anti_bruteforce_blocktime', 'patchstack_login_time_block', 'patchstack_login_time_start', 'patchstack_login_time_end', 'patchstack_login_2fa', 'patchstack_login_blocked', 'patchstack_login_whitelist' ], | |
| 272 | + ]; | |
| 243 | 273 | |
| 244 | 274 | foreach ( $settings as $key => $setting ) { |
| 245 | 275 | foreach ( $setting as $option ) { |
| 246 | 276 | register_setting( 'patchstack_' . $key . '_settings_group', $option ); |
| @@ -253,16 +283,16 @@ | ||
| 253 | 283 | echo wp_kses( '<p style="color: red;">The auto update feature cannot be enabled because a plugin or code change forces automatic updates to be disabled. (AUTOMATIC_UPDATER_DISABLED)</p>', $this->allowed_html ); |
| 254 | 284 | return; |
| 255 | 285 | } |
| 256 | 286 | |
| 257 | - $selected = get_site_option( 'patchstack_auto_update', array() ); | |
| 258 | - $selected = ! is_array( $selected ) ? array() : $selected; | |
| 259 | - $options = array( | |
| 287 | + $selected = get_site_option( 'patchstack_auto_update', [] ); | |
| 288 | + $selected = ! is_array( $selected ) ? [] : $selected; | |
| 289 | + $options = [ | |
| 260 | 290 | 'core' => 'WordPress Core', |
| 261 | 291 | 'plugin' => 'Plugins', |
| 262 | 292 | 'theme' => 'Themes', |
| 263 | 293 | 'vulnerable' => 'Vulnerable Plugins', |
| 264 | - ); | |
| 294 | + ]; | |
| 265 | 295 | $out = ''; |
| 266 | 296 | foreach ( $options as $option => $text ) { |
| 267 | 297 | $out .= '<input type="checkbox" id="patchstack_auto_update_' . $option . '" name="patchstack_auto_update[]" value="' . $option . '" ' . checked( 1, in_array( $option, $selected ), false ) . '/>' |
| 268 | 298 | . '<label for="patchstack_auto_update_' . $option . '"><i>' . $text . '</i></label><br>'; |
| @@ -283,9 +313,9 @@ | ||
| 283 | 313 | } |
| 284 | 314 | |
| 285 | 315 | public function patchstack_basic_firewall_geo_countries_input() { |
| 286 | 316 | $string1 = __( 'Specify which countries should be blocked.<br />Note that this will also block any type of (legitimate) bot traffic coming from this country. IP to country resolution might also not be 100% accurate.', 'patchstack' ); |
| 287 | - $countries = $this->get_option( 'patchstack_geo_block_countries', array() ); | |
| 317 | + $countries = $this->get_option( 'patchstack_geo_block_countries', [] ); | |
| 288 | 318 | $country_list = ''; |
| 289 | 319 | if ( ! empty( $countries ) ) { |
| 290 | 320 | foreach ( $countries as $country ) { |
| 291 | 321 | $country_list .= esc_attr( $country ) . ","; |
| @@ -315,9 +345,9 @@ | ||
| 315 | 345 | echo wp_kses( '<input type="text" name="patchstack_register_email_blacklist" id="patchstack_register_email_blacklist" value="' . esc_attr( $this->get_option( 'patchstack_register_email_blacklist', '' ) ) . '"/><label for="patchstack_register_email_blacklist"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 316 | 346 | } |
| 317 | 347 | |
| 318 | 348 | public function patchstack_activity_log_input() { |
| 319 | - $string1 = __( 'If enabled, every user action will be recorded and put to activity logs', 'patchstack' ); | |
| 349 | + $string1 = __( 'If enabled, a large number of user related activities will be logged.', 'patchstack' ); | |
| 320 | 350 | echo wp_kses( '<input type="checkbox" name="patchstack_activity_log_is_enabled" id="patchstack_activity_log_is_enabled" value="1" ' . checked( 1, $this->get_option( 'patchstack_activity_log_is_enabled' ), false ) . '/><label for="patchstack_activity_log_is_enabled"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 321 | 351 | } |
| 322 | 352 | |
| 323 | 353 | public function patchstack_activity_log_failed_logins_input() { |
| @@ -391,30 +421,26 @@ | ||
| 391 | 421 | echo wp_kses( '<br /><label for="patchstack_cookie_notice_opacity"><i>min: 1 - max: 99 - no opacity: 100</i></label>', $this->allowed_html ); |
| 392 | 422 | } |
| 393 | 423 | |
| 394 | 424 | public function patchstack_hidewplogin_input() { |
| 395 | - $string1 = __( 'Move login page to hide it from hackers and seekers.', 'patchstack' ); | |
| 396 | - $string1 = __( 'Hide wp-login and wp-admin page from attackers.', 'patchstack' ); | |
| 425 | + $string1 = __( 'Block access to the default wp-login.php page. This will require you to visit the URL below which will whitelist your IP address for 10 minutes to login.', 'patchstack' ); | |
| 397 | 426 | echo wp_kses( '<input type="checkbox" name="patchstack_mv_wp_login" id="patchstack_mv_wp_login" value="1" ' . checked( 1, $this->get_option( 'patchstack_mv_wp_login' ), false ) . '/><label for="patchstack_mv_wp_login"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 398 | 427 | } |
| 399 | 428 | |
| 400 | 429 | public function patchstack_hidewplogin_rename_input() { |
| 401 | - echo wp_kses( '<label><i style="color:red;">We do not recommend enabling this when you already have renamed your admin folder or when you make use of a system that allows regular users to login.</i></label><br /><br /><label style="font-weight: 300; color: #d0d0d0;"> ' . get_site_url() . '/ </label><input type="text" name="patchstack_rename_wp_login" id="patchstack_rename_wp_login" value="' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '" /> <i style="color: #fff">New login page</i>' , $this->allowed_html ); | |
| 430 | + if ( $this->get_option( 'patchstack_mv_wp_login' ) == 0 && $this->get_option( 'patchstack_rename_wp_login' ) == 'swlogin' ) { | |
| 431 | + update_site_option( 'patchstack_rename_wp_login', md5( wp_generate_password( 32, true, true ) ) ); | |
| 432 | + } | |
| 433 | + | |
| 434 | + echo wp_kses( '<label><i style="color:red;">This feature should not be used if you have renamed your login page already or when you make use of a system that allows regular users to login.</i></label><br /><br /><label style="font-weight: 300; color: #d0d0d0;"> ' . get_site_url() . '/ </label><input type="text" style="width: 350px;" name="patchstack_rename_wp_login" id="patchstack_rename_wp_login" value="' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '" />' , $this->allowed_html ); | |
| 402 | 435 | if ( $this->get_option( 'patchstack_mv_wp_login' ) && $this->get_option( 'patchstack_rename_wp_login' ) ) { |
| 403 | - $request = wp_remote_get( get_site_url() . '/' . $this->get_option( 'patchstack_rename_wp_login' ), array( 'sslverify' => false ) ); | |
| 404 | - $response = wp_remote_retrieve_body( $request ); | |
| 405 | - if ( ! strpos( $response, $this->get_option( 'patchstack_rename_wp_login' ) ) ) { | |
| 406 | - update_site_option( 'patchstack_mv_wp_login', 0 ); | |
| 407 | - echo wp_kses( '<div class="error notice is-dismissible" style="margin-left: 0px );"><p style="color: #000000;">' . __( 'Patchstack custom login page could not be activated due to your environment setup, it may be conflict with other plugin or specific .htaccess rules.', 'patchstack' ) . '</p></div>', $this->allowed_html ); | |
| 408 | - } else { | |
| 409 | - echo wp_kses( '<br /><br /><div style="font-weight: 300; color: #d0d0d0;">Your login page is now here: <a href="' . get_site_url() . '/' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '">' . get_site_url() . '/' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '</div></a>', $this->allowed_html ); | |
| 410 | - echo wp_kses( '<br /><input type="submit" id="patchstack_send_mail_url" name="patchstack_send_mail_url" value="Send the link to your admin email." class="button-primary" />', $this->allowed_html ); | |
| 411 | - } | |
| 436 | + echo wp_kses( '<br /><br /><div style="font-weight: 300; color: #d0d0d0;">Your login access page is here: <a href="' . get_site_url() . '/' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '">' . get_site_url() . '/' . esc_attr( $this->get_option( 'patchstack_rename_wp_login' ) ) . '</div></a>', $this->allowed_html ); | |
| 437 | + echo wp_kses( '<br /><input type="submit" id="patchstack_send_mail_url" name="patchstack_send_mail_url" value="Send the link to your admin email." class="button-primary" />', $this->allowed_html ); | |
| 412 | 438 | } |
| 413 | 439 | } |
| 414 | 440 | |
| 415 | 441 | public function patchstack_pluginedit_input() { |
| 416 | - $string1 = __( 'Disable direct editing of themes or plugins code from WordPress admin view.', 'patchstack' ); | |
| 442 | + $string1 = __( 'Disable the theme editor. This could protect you from potential automated attacks that involve the theme editor.', 'patchstack' ); | |
| 417 | 443 | echo wp_kses( '<input type="checkbox" name="patchstack_pluginedit" id="patchstack_pluginedit" value="1" ' . checked( 1, $this->get_option( 'patchstack_pluginedit' ), false ) . '/><label for="patchstack_pluginedit"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 418 | 444 | } |
| 419 | 445 | |
| 420 | 446 | public function patchstack_add_security_headers_input() { |
| @@ -422,25 +448,19 @@ | ||
| 422 | 448 | echo wp_kses( '<input type="checkbox" name="patchstack_add_security_headers" id="patchstack_add_security_headers" value="1" ' . checked( 1, $this->get_option( 'patchstack_add_security_headers' ), false ) . '/><label for="patchstack_add_security_headers"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 423 | 449 | } |
| 424 | 450 | |
| 425 | 451 | public function patchstack_basicscanblock_input() { |
| 426 | - $string1 = __( 'This will attempt to stop basic readme.txt scans. These scans are generally used to determine the version of the installed software on the site.', 'patchstack' ); | |
| 452 | + $string1 = __( 'This will attempt to stop basic readme.txt scans. These scans are generally used to determine the version of installed plugins on the site.', 'patchstack' ); | |
| 427 | 453 | echo wp_kses( '<input type="checkbox" name="patchstack_basicscanblock" id="patchstack_basicscanblock" value="1" ' . checked( 1, $this->get_option( 'patchstack_basicscanblock' ), false ) . '/><label for="patchstack_basicscanblock"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 428 | 454 | } |
| 429 | 455 | |
| 430 | 456 | public function patchstack_userenum_input() { |
| 431 | - $string1 = __( 'Disable user enumeration to block hackers from getting your usernames.', 'patchstack' ); | |
| 457 | + $string1 = __( 'Make it harder for malicious people to find your WordPress username.', 'patchstack' ); | |
| 432 | 458 | echo wp_kses( '<input type="checkbox" name="patchstack_userenum" id="patchstack_userenum" value="1" ' . checked( 1, $this->get_option( 'patchstack_userenum' ), false ) . '/><label for="patchstack_userenum"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 433 | 459 | } |
| 434 | 460 | |
| 435 | - public function patchstack_hidewpcontent_input() { | |
| 436 | - $string1 = __( 'Move wp-content folder into facebook.com folder and link to it in wp-config.php. saving settings after ticking this will take more time than usual. Just let it reload the page on its own and be patient.', 'patchstack' ); | |
| 437 | - $string2 = __( 'If this setting brakes your website then go to your server files through FTP, rename facebook.com folder to wp-content and erase Patchstack section from the top of wp-config.php file.', 'patchstack' ); | |
| 438 | - echo wp_kses( '<input type="checkbox" name="patchstack_hidewpcontent" id="patchstack_hidewpcontent" value="1" ' . checked( 1, $this->get_option( 'patchstack_hidewpcontent' ), false ) . '/><label for="patchstack_hidewpcontent"><i>' . $string1 . '</i></br><span style="color: red; font-weight: bold">' . $string2 . '</span></label>' , $this->allowed_html ); | |
| 439 | - } | |
| 440 | - | |
| 441 | 461 | public function patchstack_hidewpversion_input() { |
| 442 | - $string1 = __( 'Removes the WordPress version in the <meta> tag in the HTML output.', 'patchstack' ); | |
| 462 | + $string1 = __( 'Removes the WordPress version in the meta tag in the HTML output.', 'patchstack' ); | |
| 443 | 463 | echo wp_kses( '<input type="checkbox" name="patchstack_hidewpversion" id="patchstack_hidewpversion" value="1" ' . checked( 1, $this->get_option( 'patchstack_hidewpversion' ), false ) . '/><label for="patchstack_hidewpversion"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 444 | 464 | } |
| 445 | 465 | |
| 446 | 466 | public function patchstack_rm_readme_input() { |
| @@ -448,9 +468,9 @@ | ||
| 448 | 468 | echo wp_kses( '<input type="checkbox" name="patchstack_rm_readme" id="patchstack_rm_readme" value="1" ' . checked( 1, $this->get_option( 'patchstack_rm_readme' ), false ) . '/><label for="patchstack_rm_readme"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 449 | 469 | } |
| 450 | 470 | |
| 451 | 471 | public function patchstack_prevent_default_file_access_input() { |
| 452 | - $string1 = __( 'Prevent access to such files as license.txt, readme.html and wp-config-sample.php', 'patchstack' ); | |
| 472 | + $string1 = __( 'Prevent direct access to files such as license.txt, readme.html and wp-config.php', 'patchstack' ); | |
| 453 | 473 | echo wp_kses( '<input type="checkbox" name="patchstack_prevent_default_file_access" id="patchstack_prevent_default_file_access" value="1" ' . checked( 1, $this->get_option( 'patchstack_prevent_default_file_access' ), false ) . '/><label for="patchstack_prevent_default_file_access"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 454 | 474 | } |
| 455 | 475 | |
| 456 | 476 | public function patchstack_basic_firewall_input() { |
| @@ -458,10 +478,10 @@ | ||
| 458 | 478 | echo wp_kses( '<input type="checkbox" name="patchstack_basic_firewall" id="patchstack_basic_firewall" value="1" ' . checked( 1, $this->get_option( 'patchstack_basic_firewall' ), false ) . '/><label for="patchstack_basic_firewall"><i>' . $string1 . '</i></label><br /><br /><i style="color:#d0d0d0">Block IP for <input style="width: 50px;" type="number" name="patchstack_autoblock_blocktime" value="' . esc_attr( $this->get_option( 'patchstack_autoblock_blocktime', 60 ) ) . '" id="patchstack_autoblock_blocktime"> minutes after <input style="width: 50px;" type="number" name="patchstack_autoblock_attempts" value="' . esc_attr( $this->get_option( 'patchstack_autoblock_attempts', 10 ) ) . '" id="patchstack_autoblock_attempts"> blocked requests over a period of <input style="width: 50px;" type="number" name="patchstack_autoblock_minutes" value="' . esc_attr( $this->get_option( 'patchstack_autoblock_minutes', 30 ) ) . '" id="patchstack_autoblock_minutes"> minutes</i>', $this->allowed_html); |
| 459 | 479 | } |
| 460 | 480 | |
| 461 | 481 | public function patchstack_basic_firewall_roles_input() { |
| 462 | - $selected = $this->get_option( 'patchstack_basic_firewall_roles', array( 'administrator', 'editor', 'author' ) ); | |
| 463 | - $selected = ! is_array( $selected ) ? array() : $selected; | |
| 482 | + $selected = $this->get_option( 'patchstack_basic_firewall_roles', [ 'administrator', 'editor', 'author' ] ); | |
| 483 | + $selected = ! is_array( $selected ) ? [] : $selected; | |
| 464 | 484 | $roles = wp_roles(); |
| 465 | 485 | $roles = $roles->get_names(); |
| 466 | 486 | $text = ''; |
| 467 | 487 | foreach ( $roles as $key => $val ) { |
| @@ -517,13 +537,21 @@ | ||
| 517 | 537 | echo wp_kses( '<input type="checkbox" name="patchstack_login_2fa" id="patchstack_login_2fa" value="1" ' . checked( 1, $this->get_option( 'patchstack_login_2fa' ), false ) . '/><label for="patchstack_login_2fa"><i>' . $string1 . '<br />Once enabled, users can configure 2FA on the "Edit My Profile" page which is located <a href="' . admin_url( 'profile.php' ) . '">here</a>.</i></label><br />' , $this->allowed_html ); |
| 518 | 538 | } |
| 519 | 539 | |
| 520 | 540 | public function patchstack_login_blocked_input() { |
| 521 | - global $wpdb; | |
| 541 | + // Calculate block time. | |
| 542 | + $minutes = (int) $this->get_option( 'patchstack_anti_bruteforce_minutes', 30 ); | |
| 543 | + $timeout = (int) $this->get_option( 'patchstack_anti_bruteforce_blocktime', 60 ); | |
| 544 | + if ( empty( $minutes ) || empty( $timeout ) ) { | |
| 545 | + $time = 30 + 60; | |
| 546 | + } else { | |
| 547 | + $time = $minutes + $timeout; | |
| 548 | + } | |
| 522 | 549 | |
| 523 | 550 | // Check if X failed login attempts were made. |
| 551 | + global $wpdb; | |
| 524 | 552 | $results = $wpdb->get_results( |
| 525 | - $wpdb->prepare( 'SELECT id, ip, date FROM ' . $wpdb->prefix . "patchstack_event_log WHERE action = 'failed login' AND date >= ('" . current_time( 'mysql' ) . "' - INTERVAL %d MINUTE) GROUP BY ip HAVING COUNT(ip) >= %d ORDER BY date DESC", array( ( $this->get_option( 'patchstack_anti_bruteforce_blocktime', 60 ) + $this->get_option( 'patchstack_anti_bruteforce_minutes', 5 ) ), $this->get_option( 'patchstack_anti_bruteforce_attempts', 10 ) ) ), | |
| 553 | + $wpdb->prepare( 'SELECT id, ip, date FROM ' . $wpdb->prefix . "patchstack_event_log WHERE action = 'failed login' AND date >= ('" . current_time( 'mysql' ) . "' - INTERVAL %d MINUTE) GROUP BY ip HAVING COUNT(ip) >= %d ORDER BY date DESC", [ $time, $this->get_option( 'patchstack_anti_bruteforce_attempts', 10 ) ] ), | |
| 526 | 554 | OBJECT |
| 527 | 555 | ); |
| 528 | 556 | |
| 529 | 557 | // Render the rows. |
| @@ -532,21 +560,21 @@ | ||
| 532 | 560 | $rows = '<tr><td>No blocked IP addresses.</td><td></td><td></td><td></td></tr>'; |
| 533 | 561 | } else { |
| 534 | 562 | $nonce = wp_create_nonce( 'patchstack-nonce-alter-ips' ); |
| 535 | 563 | foreach ( $results as $result ) { |
| 536 | - $rows .= '<tr><td>' . esc_html( $result->ip ) . '</td><td>' . ( isset( $result->log_date ) ? $result->log_date : $result->date ) . '</td><td><a href="' . add_query_arg( | |
| 537 | - array( | |
| 564 | + $rows .= '<tr><td>' . esc_html( $result->ip ) . '</td><td>' . ( isset( $result->log_date ) ? $result->log_date : $result->date ) . '</td><td><a href="' . esc_url( add_query_arg( | |
| 565 | + [ | |
| 538 | 566 | 'PatchstackNonce' => $nonce, |
| 539 | 567 | 'action' => 'patchstack_unblock', |
| 540 | 568 | 'id' => $result->id, |
| 541 | - ) | |
| 542 | - ) . '">Unblock</a></td><td><a href="' . add_query_arg( | |
| 543 | - array( | |
| 569 | + ] | |
| 570 | + ) ) . '">Unblock</a></td><td><a href="' . esc_url( add_query_arg( | |
| 571 | + [ | |
| 544 | 572 | 'PatchstackNonce' => $nonce, |
| 545 | 573 | 'action' => 'patchstack_unblock_whitelist', |
| 546 | 574 | 'id' => $result->id, |
| 547 | - ) | |
| 548 | - ) . '">Unblock & Whitelist</a></td></tr>'; | |
| 575 | + ] | |
| 576 | + ) ) . '">Unblock & Whitelist</a></td></tr>'; | |
| 549 | 577 | } |
| 550 | 578 | } |
| 551 | 579 | |
| 552 | 580 | $string1 = __( 'These are the IP addresses that are currently blocked because of too many failed login attempts.<br />These are not the IP addresses banned by the firewall itself.<br /><br />', 'patchstack' ); |
| @@ -609,14 +637,14 @@ | ||
| 609 | 637 | </select>', $this->allowed_html ); |
| 610 | 638 | } |
| 611 | 639 | |
| 612 | 640 | public function patchstack_captcha_public_key_input() { |
| 613 | - $string1 = __( '<br /><br />Enter the reCAPTCHA site key here.<br />Click <a href="https://docs.patchstack.com/technical-support-and-troubleshooting/plugin/how-to-get-the-site-and-secret-key-for-the-recaptcha-feature" target="_blank">here</a> for a guide on how to get the site / secret key.', 'patchstack' ); | |
| 641 | + $string1 = __( '<br /><br />Enter the reCAPTCHA site key here.<br />Click <a href="https://docs.patchstack.com/discuss/62e286cf7040390013b73bf7" target="_blank">here</a> for a guide on how to get the site / secret key.', 'patchstack' ); | |
| 614 | 642 | echo wp_kses( '<input style="display:none;" type="text" name="patchstack_captcha_public_key" id="patchstack_captcha_public_key" value="' . esc_attr( $this->get_option( 'patchstack_captcha_public_key', '' ) ) . '"/><input style="display:none;" type="text" name="patchstack_captcha_public_key_v3" id="patchstack_captcha_public_key_v3" value="' . esc_attr( $this->get_option( 'patchstack_captcha_public_key_v3', '' ) ) . '"/><input style="display:none;" type="text" name="patchstack_captcha_public_key_v3_new" id="patchstack_captcha_public_key_v3_new" value="' . esc_attr( $this->get_option( 'patchstack_captcha_public_key_v3_new', '' ) ) . '"/><label for="patchstack_captcha_public_key"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 615 | 643 | } |
| 616 | 644 | |
| 617 | 645 | public function patchstack_captcha_private_key_input() { |
| 618 | - $string1 = __( '<br /><br />Enter the reCAPTCHA secret key here.<br />Click <a href="https://docs.patchstack.com/technical-support-and-troubleshooting/plugin/how-to-get-the-site-and-secret-key-for-the-recaptcha-feature" target="_blank">here</a> for a guide on how to get the site / secret key.', 'patchstack' ); | |
| 646 | + $string1 = __( '<br /><br />Enter the reCAPTCHA secret key here.<br />Click <a href="https://docs.patchstack.com/discuss/62e286cf7040390013b73bf7" target="_blank">here</a> for a guide on how to get the site / secret key.', 'patchstack' ); | |
| 619 | 647 | echo wp_kses( '<input style="display:none;" type="text" name="patchstack_captcha_private_key" id="patchstack_captcha_private_key" value="' . esc_attr( $this->get_option( 'patchstack_captcha_private_key', '' ) ) . '"/><input style="display:none;" type="text" name="patchstack_captcha_private_key_v3" id="patchstack_captcha_private_key_v3" value="' . esc_attr( $this->get_option( 'patchstack_captcha_private_key_v3', '' ) ) . '"/><input style="display:none;" type="text" name="patchstack_captcha_private_key_v3_new" id="patchstack_captcha_private_key_v3_new" value="' . esc_attr( $this->get_option( 'patchstack_captcha_private_key_v3_new', '' ) ) . '"/><label for="patchstack_captcha_private_key"><i>' . $string1 . '</i></label>' , $this->allowed_html ); |
| 620 | 648 | } |
| 621 | 649 | |
| 622 | 650 | public function patchstack_blackhole_log_input() { |