PluginProbe
Patchstack – WordPress & Plugins Security / 2.3.3
Patchstack – WordPress & Plugins Security v2.3.3
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
← All changes | includes/rules.php +62 -10 2.1.02.3.3 View file →
@@ -17,11 +17,11 @@
17 17 * @return void
18 18 */
19 19 public function __construct( $core ) {
20 20 parent::__construct( $core );
21 - add_action( 'patchstack_post_firewall_rules', array( $this, 'post_firewall_rules' ) );
22 - add_action( 'patchstack_post_firewall_htaccess_rules', array( $this, 'post_firewall_htaccess_rules' ) );
23 - add_action( 'patchstack_post_dynamic_firewall_rules', array( $this, 'dynamic_firewall_rules' ) );
21 + add_action( 'patchstack_post_firewall_rules', [ $this, 'post_firewall_rules' ] );
22 + add_action( 'patchstack_post_firewall_htaccess_rules', [ $this, 'post_firewall_htaccess_rules' ] );
23 + add_action( 'patchstack_post_dynamic_firewall_rules', [ $this, 'dynamic_firewall_rules' ] );
24 24 }
25 25
26 26 /**
27 27 * Pull the hardening .htaccess rules from the API.
@@ -35,9 +35,9 @@
35 35 }
36 36
37 37 $rules = $this->plugin->htaccess->get_firewall_rule_settings();
38 38 $settings = json_encode( $rules );
39 - $results = $this->plugin->api->post_firewall_rule( array( 'settings' => $settings ) );
39 + $results = $this->plugin->api->post_firewall_rule( [ 'settings' => $settings ] );
40 40
41 41 // If no rules returned, we assume all settings are turned off.
42 42 if ( empty( $results ) ) {
43 43 $results['rules'] = '';
@@ -89,16 +89,68 @@
89 89 if ( ! isset( $results['firewall'] ) ) {
90 90 return;
91 91 }
92 92
93 + // Separate the new firewall engine rules from the old ones.
94 + $newRules = [];
95 + $newRulesAP = [];
96 + $oldRules = [];
97 +
98 + // Counters for displaying purposes on the API key page.
99 + $vPatchCount = 0;
100 + $ruleCount = 0;
101 +
102 + // Parse the rules.
103 + foreach ( $results['firewall'] as $rule ) {
104 + if ( isset( $rule['rule_v2'] ) ) {
105 + $rule['rules'] = $rule['rule_v2'];
106 + unset( $rule['rule_v2'] );
107 +
108 + // Mark vPatches based on substring.
109 + if ( stripos( $rule['title'], ' vulnerabilit' ) !== false && stripos( $rule['title'], 'block ' ) !== false ) {
110 + $vPatchCount++;
111 + } else {
112 + $ruleCount++;
113 + }
114 +
115 + // Differentiate between auto prepend rules and regular ones.
116 + if ( isset( $rule['ap'] ) && !empty( $rule['ap'] ) ) {
117 + $newRulesAP[] = $rule;
118 + } else {
119 + $newRules[] = $rule;
120 + }
121 + } else {
122 + $ruleCount++;
123 + $oldRules[] = $rule;
124 + }
125 + }
126 +
93 127 // Update firewall rules.
94 - update_option( 'patchstack_firewall_rules', json_encode( $results['firewall'] ) );
128 + update_option( 'patchstack_firewall_rules', json_encode( $oldRules ), true );
129 + update_option( 'patchstack_firewall_rules_v3', json_encode( $newRules ), true );
130 + update_option( 'patchstack_firewall_rules_v3_ap', json_encode( $newRulesAP ), true );
95 131
132 + // Update the counters.
133 + update_option( 'patchstack_vpatches_present', $vPatchCount );
134 + update_option( 'patchstack_non_vpatches_present', $ruleCount );
135 +
136 + // Separate the new firewall engine rules from the old ones.
137 + $newRules = [];
138 + $oldRules = [];
139 + foreach ( $results['whitelists'] as $rule ) {
140 + if ( isset( $rule['rule_v2'] ) ) {
141 + $rule['rules'] = $rule['rule_v2'];
142 + unset( $rule['rule_v2'] );
143 + $newRules[] = $rule;
144 + } else {
145 + $oldRules[] = $rule;
146 + }
147 + }
148 +
96 149 // Update whitelist rules.
97 - update_option( 'patchstack_whitelist_rules', json_encode( $results['whitelists'] ) );
150 + update_option( 'patchstack_whitelist_rules', json_encode( $oldRules ), true );
151 + update_option( 'patchstack_whitelist_rules_v3', json_encode( $newRules ), true );
98 152
99 - // Update secondary whitelist rules.
100 - if ( isset( $results['whitelist_keys'] ) ) {
101 - update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ) );
102 - }
153 + // Update the whitelisted keys.
154 + update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ), true );
103 155 }
104 156 }