| @@ -22,12 +22,13 @@ | ||
| 22 | 22 | |
| 23 | 23 | // Add admin and network notices. |
| 24 | 24 | add_action( 'admin_notices', [ $this, 'file_error_notice' ] ); |
| 25 | 25 | add_action( 'network_admin_notices', [ $this, 'file_error_notice' ] ); |
| 26 | + | |
| 27 | + add_action( 'wp_loaded', [ $this, 'update_rules' ] ); | |
| 26 | 28 | add_action( 'update_option_siteurl', [ $this, 'update_option_url' ], 10, 2 ); |
| 27 | - // Use updated_option (fires after the value is written) so auto_prepend_injection() | |
| 28 | - // re-reads the new value; update_option fires before the write and sees the old value. | |
| 29 | - add_action( 'updated_option', [ $this, 'update_option_ap' ], 10, 3 ); | |
| 29 | + add_action( 'admin_init', [ $this, 'alter_ips' ] ); | |
| 30 | + add_action( 'admin_init', [ $this, 'enable_settings' ] ); | |
| 30 | 31 | |
| 31 | 32 | // If the firewall or whitelist rules do not exist, attempt to pull fresh. |
| 32 | 33 | $token = get_option( 'patchstack_api_token', false ); |
| 33 | 34 | if ( ! empty( $token ) && ( get_option( 'patchstack_firewall_rules', '' ) == '' || get_option( 'patchstack_whitelist_keys_rules' ) == '' ) && get_option( 'patchstack_license_free', 0 ) != 1 ) { |
| @@ -41,22 +42,12 @@ | ||
| 41 | 42 | * @return void |
| 42 | 43 | */ |
| 43 | 44 | public function file_error_notice() { |
| 44 | 45 | // No need to display this error if the .htaccess functionality has been disabled. |
| 45 | - if ( get_site_option( 'patchstack_disable_htaccess', 0 ) || ( defined( 'PS_DISABLE_HTACCESS' ) && PS_DISABLE_HTACCESS ) ) { | |
| 46 | + if ( get_site_option( 'patchstack_disable_htaccess', 0 ) ) { | |
| 46 | 47 | return; |
| 47 | 48 | } |
| 48 | 49 | |
| 49 | - // No need to display if a free user without protection. | |
| 50 | - if ( get_option( 'patchstack_license_free', 0 ) == 1 ) { | |
| 51 | - return; | |
| 52 | - } | |
| 53 | - | |
| 54 | - // No need to display on nginx. | |
| 55 | - if ( isset( $_SERVER['SERVER_SOFTWARE'] ) && stripos( $_SERVER['SERVER_SOFTWARE'], 'nginx' ) !== false ) { | |
| 56 | - return; | |
| 57 | - } | |
| 58 | - | |
| 59 | 50 | // Check root .htaccess file and data folder writability. |
| 60 | 51 | $files = []; |
| 61 | 52 | if ( file_exists( ABSPATH . '.htaccess' ) && ! wp_is_writable( ABSPATH . '.htaccess' ) ) { |
| 62 | 53 | array_push( $files, ABSPATH . '.htaccess' ); |
| @@ -69,12 +60,12 @@ | ||
| 69 | 60 | <h2>Patchstack File Permission Error</h2> |
| 70 | 61 | <p><?php esc_html_e( 'The following file/folder could not be written to:<br />' . implode( '<br />', $files ), 'patchstack' ); ?></p> |
| 71 | 62 | <?php |
| 72 | 63 | foreach ( $files as $file ) { |
| 73 | - echo wp_kses( '<p><b>Debug info: </b>' . $file . ' chmod permissions: <b>' . substr( decoct( fileperms( $file ) ), -3 ) . '</b>, owned by <b>' . $this->get_file_owner_name( $file ) . '</b></p>', $this->allowed_html ); | |
| 64 | + echo wp_kses( '<p><b>Debug info: </b>' . $file . ' chmod permissions: <b>' . substr( decoct( fileperms( $file ) ), -3 ) . '</b>, owned by <b>' . posix_getpwuid( fileowner( $file ) )['name'] . '</b></p>', $this->allowed_html ); | |
| 74 | 65 | } |
| 75 | 66 | ?> |
| 76 | - <p><?php esc_html_e( '<strong>How to fix?</strong><br />CHMOD the file/folder to <strong>755</strong> through a <a href="http://www.dummies.com/web-design-development/wordpress/navigation-customization/how-to-change-file-permissions-using-filezilla-on-your-ftp-site/" target="_blank">FTP client</a>, <a href="http://support.hostgator.com/articles/cpanel/how-to-change-permissions-chmod-of-a-file" target="_blank">CPanel</a>, <a href="https://www.inmotionhosting.com/support/website/managing-files/change-file-permissions" target="_blank">WHM</a> or ask your hosting provider. Make sure file or folder ownership is set to <b>' . $this->get_file_owner_name( ABSPATH . 'index.php' ) . '</b> user .', 'patchstack_file_error_notice' ); ?></p> | |
| 67 | + <p><?php esc_html_e( '<strong>How to fix?</strong><br />CHMOD the file/folder to <strong>755</strong> through a <a href="http://www.dummies.com/web-design-development/wordpress/navigation-customization/how-to-change-file-permissions-using-filezilla-on-your-ftp-site/" target="_blank">FTP client</a>, <a href="http://support.hostgator.com/articles/cpanel/how-to-change-permissions-chmod-of-a-file" target="_blank">CPanel</a>, <a href="https://www.inmotionhosting.com/support/website/managing-files/change-file-permissions" target="_blank">WHM</a> or ask your hosting provider. Make sure file or folder ownership is set to <b>' . posix_getpwuid( fileowner( ABSPATH . 'index.php' ) )['name'] . '</b> user .', 'patchstack_file_error_notice' ); ?></p> | |
| 77 | 68 | <p><?php esc_html_e( '<strong>CHMOD properly set but still not working?</strong><br />Make sure the group/owner (chown) settings of the /wp-content/plugins/patchstack/ folder is properly setup, you may have to ask your host to fix this.', 'patchstack_file_error_notice' ); ?></p> |
| 78 | 69 | </div> |
| 79 | 70 | <?php |
| 80 | 71 | } |
| @@ -80,21 +71,25 @@ | ||
| 80 | 71 | } |
| 81 | 72 | } |
| 82 | 73 | |
| 83 | 74 | /** |
| 84 | - * Resolve the owning system user name for a file, guarding the POSIX extension | |
| 85 | - * which is not available on Windows or some hardened hosts. | |
| 75 | + * When the user changes Patchstack plugin settings, update the firewall rules. | |
| 86 | 76 | * |
| 87 | - * @param string $file | |
| 88 | - * @return string | |
| 77 | + * @return void | |
| 89 | 78 | */ |
| 90 | - private function get_file_owner_name( $file ) { | |
| 91 | - if ( ! function_exists( 'posix_getpwuid' ) || ! function_exists( 'fileowner' ) ) { | |
| 92 | - return ''; | |
| 79 | + public function update_rules() { | |
| 80 | + if ( isset( $_GET['settings-updated'], $_GET['page'] ) && strpos( $_GET['page'], 'patchstack' ) !== false && current_user_can( 'administrator' ) ) { | |
| 81 | + $this->plugin->rules->post_firewall_rules(); | |
| 82 | + $this->plugin->rules->dynamic_firewall_rules(); | |
| 83 | + | |
| 84 | + // Update firewall status after settings saved | |
| 85 | + $token = $this->plugin->api->get_access_token(); | |
| 86 | + | |
| 87 | + // Update the firewall status. | |
| 88 | + if ( ! empty( $token ) ) { | |
| 89 | + $this->plugin->api->update_firewall_status( [ 'status' => $this->get_option( 'patchstack_basic_firewall' ) == 1 ] ); | |
| 90 | + } | |
| 93 | 91 | } |
| 94 | - | |
| 95 | - $owner = posix_getpwuid( fileowner( $file ) ); | |
| 96 | - return isset( $owner['name'] ) ? $owner['name'] : ''; | |
| 97 | 92 | } |
| 98 | 93 | |
| 99 | 94 | /** |
| 100 | 95 | * When the user updates the site URL, update it on the API side as well. |
| @@ -110,28 +105,75 @@ | ||
| 110 | 105 | } |
| 111 | 106 | } |
| 112 | 107 | |
| 113 | 108 | /** |
| 114 | - * When the firewall auto prepend option value is changed, ensure that we prepare the environment or remove it from the environment. | |
| 115 | - * | |
| 116 | - * @param mixed $option_name | |
| 117 | - * @param mixed $old_value | |
| 118 | - * @param mixed $new_value | |
| 109 | + * Executed when the user modifies the blocked or whitelisted IP addresses on the | |
| 110 | + * login protection settings page. | |
| 111 | + * | |
| 119 | 112 | * @return void |
| 120 | 113 | */ |
| 121 | - public function update_option_ap( $option_name, $old_value, $new_value ) { | |
| 122 | - if ( $option_name != 'patchstack_firewall_ap_enabled' ) { | |
| 114 | + public function alter_ips() { | |
| 115 | + if ( ! isset( $_GET['action'], $_GET['PatchstackNonce'] ) || ! wp_verify_nonce( $_GET['PatchstackNonce'], 'patchstack-nonce-alter-ips' ) || ! current_user_can( 'administrator' ) || ! in_array( $_GET['action'], [ 'patchstack_unblock', 'patchstack_unblock_whitelist', 'patchstack_whitelist' ] ) ) { | |
| 123 | 116 | return; |
| 124 | 117 | } |
| 125 | 118 | |
| 126 | - // No need to perform if user is on free plan. | |
| 127 | - if ( get_option( 'patchstack_license_activated', 0 ) != 1 ) { | |
| 119 | + global $wpdb; | |
| 120 | + | |
| 121 | + // Unblock the IP; delete the logs of the IP. | |
| 122 | + if ( $_GET['action'] == 'patchstack_unblock' && isset( $_GET['id'] ) && ctype_digit( $_GET['id'] ) ) { | |
| 123 | + // First get the IP address to unblock. | |
| 124 | + $result = $wpdb->get_results( | |
| 125 | + $wpdb->prepare( 'SELECT ip FROM ' . $wpdb->prefix . 'patchstack_event_log WHERE id = %d', [ (int) $_GET['id'] ] ) | |
| 126 | + ); | |
| 127 | + | |
| 128 | + // Unblock the IP address. | |
| 129 | + if ( isset( $result[0], $result[0]->ip ) ) { | |
| 130 | + $wpdb->query( | |
| 131 | + $wpdb->prepare( 'DELETE FROM ' . $wpdb->prefix . 'patchstack_event_log WHERE ip = %s', [ $result[0]->ip ] ) | |
| 132 | + ); | |
| 133 | + } | |
| 134 | + } | |
| 135 | + | |
| 136 | + // Unblock and whitelist the IP. | |
| 137 | + if ( $_GET['action'] == 'patchstack_unblock_whitelist' && isset( $_GET['id'] ) && ctype_digit( $_GET['id'] ) ) { | |
| 138 | + // First get the IP address to whitelist. | |
| 139 | + $result = $wpdb->get_results( | |
| 140 | + $wpdb->prepare( 'SELECT ip FROM ' . $wpdb->prefix . 'patchstack_event_log WHERE id = %d', [ (int) $_GET['id'] ] ) | |
| 141 | + ); | |
| 142 | + | |
| 143 | + // Whitelist and unblock the IP address. | |
| 144 | + if ( isset( $result[0], $result[0]->ip ) && filter_var( $result[0]->ip, FILTER_VALIDATE_IP ) ) { | |
| 145 | + update_option( 'patchstack_login_whitelist', $this->get_option( 'patchstack_login_whitelist', '' ) . "\n" . $result[0]->ip ); | |
| 146 | + $wpdb->query( | |
| 147 | + $wpdb->prepare( 'DELETE FROM ' . $wpdb->prefix . 'patchstack_event_log WHERE ip = %s', [ $result[0]->ip ] ) | |
| 148 | + ); | |
| 149 | + } | |
| 150 | + } | |
| 151 | + | |
| 152 | + // Whitelist an IP address. | |
| 153 | + if ( $_GET['action'] == 'patchstack_whitelist' && isset( $_GET['ip'] ) && filter_var( $_GET['ip'], FILTER_VALIDATE_IP ) ) { | |
| 154 | + update_option( 'patchstack_login_whitelist', $this->get_option( 'patchstack_login_whitelist', '' ) . "\n" . $_GET['ip'] ); | |
| 155 | + } | |
| 156 | + | |
| 157 | + // Redirect the user back to the login tab. | |
| 158 | + wp_safe_redirect( admin_url( 'admin.php?page=' . $this->plugin->name . '&tab=login' ) ); | |
| 159 | + exit; | |
| 160 | + } | |
| 161 | + | |
| 162 | + /** | |
| 163 | + * Turn on the Patchstack settings feature on WordPress. | |
| 164 | + * | |
| 165 | + * @return void | |
| 166 | + */ | |
| 167 | + public function enable_settings() { | |
| 168 | + if ( ! isset( $_GET['action'], $_GET['patchstack_settings_nonce'] ) || ! wp_verify_nonce( $_GET['patchstack_settings_nonce'], 'patchstack_settings_nonce' ) || ! current_user_can( 'administrator' ) || $_GET['action'] != 'enable_settings' ) { | |
| 128 | 169 | return; |
| 129 | 170 | } |
| 130 | 171 | |
| 131 | - if ( $new_value && (int) get_option( 'patchstack_license_free', 0 ) == 0 ) { | |
| 132 | - $this->plugin->activation->auto_prepend_injection(); | |
| 133 | - } else { | |
| 134 | - $this->plugin->activation->auto_prepend_removal(); | |
| 135 | - } | |
| 172 | + // Turn it on. | |
| 173 | + update_option( 'patchstack_show_settings', 1 ); | |
| 174 | + | |
| 175 | + // Redirect the user back to the license page. | |
| 176 | + wp_safe_redirect( admin_url( 'admin.php?page=' . $this->plugin->name ) ); | |
| 177 | + exit; | |
| 136 | 178 | } |
| 137 | 179 | } |