| @@ -17,11 +17,10 @@ | ||
| 17 | 17 | * @return void |
| 18 | 18 | */ |
| 19 | 19 | public function __construct( $core ) { |
| 20 | 20 | parent::__construct( $core ); |
| 21 | - add_action( 'patchstack_post_firewall_rules', array( $this, 'post_firewall_rules' ) ); | |
| 22 | - add_action( 'patchstack_post_firewall_htaccess_rules', array( $this, 'post_firewall_htaccess_rules' ) ); | |
| 23 | - add_action( 'patchstack_post_dynamic_firewall_rules', array( $this, 'dynamic_firewall_rules' ) ); | |
| 21 | + add_action( 'patchstack_post_firewall_rules', [ $this, 'post_firewall_rules' ] ); | |
| 22 | + add_action( 'patchstack_post_dynamic_firewall_rules', [ $this, 'dynamic_firewall_rules' ] ); | |
| 24 | 23 | } |
| 25 | 24 | |
| 26 | 25 | /** |
| 27 | 26 | * Pull the hardening .htaccess rules from the API. |
| @@ -33,15 +32,22 @@ | ||
| 33 | 32 | if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) { |
| 34 | 33 | return; |
| 35 | 34 | } |
| 36 | 35 | |
| 36 | + // Check if server is supported and if htaccess modifications are disabled. | |
| 37 | + if ( get_site_option( 'patchstack_disable_htaccess', 0 ) || ( defined( 'PS_DISABLE_HTACCESS' ) && PS_DISABLE_HTACCESS ) ) { | |
| 38 | + return; | |
| 39 | + } | |
| 40 | + | |
| 37 | 41 | $rules = $this->plugin->htaccess->get_firewall_rule_settings(); |
| 38 | 42 | $settings = json_encode( $rules ); |
| 39 | - $results = $this->plugin->api->post_firewall_rule( array( 'settings' => $settings ) ); | |
| 43 | + $results = $this->plugin->api->post_firewall_rule( [ 'settings' => $settings ] ); | |
| 40 | 44 | |
| 41 | - // If no rules returned, we assume all settings are turned off. | |
| 42 | - if ( empty( $results ) ) { | |
| 43 | - $results['rules'] = ''; | |
| 45 | + // If no rules returned (empty, or a status code/null from a failed request), | |
| 46 | + // we assume all settings are turned off. Guard against assigning to a string | |
| 47 | + // offset, which is a fatal error on PHP 7.1+. | |
| 48 | + if ( ! is_array( $results ) ) { | |
| 49 | + $results = [ 'rules' => '' ]; | |
| 44 | 50 | } |
| 45 | 51 | |
| 46 | 52 | // We have rules so apply it to the .htaccess file. |
| 47 | 53 | if ( isset( $results['rules'] ) ) { |
| @@ -50,32 +56,8 @@ | ||
| 50 | 56 | } |
| 51 | 57 | } |
| 52 | 58 | |
| 53 | 59 | /** |
| 54 | - * Pull the firewall .htaccess rules from the API. | |
| 55 | - * Then apply it to the .htaccess file after we create a backup. | |
| 56 | - * | |
| 57 | - * @return void | |
| 58 | - */ | |
| 59 | - public function post_firewall_htaccess_rules() { | |
| 60 | - if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) { | |
| 61 | - return; | |
| 62 | - } | |
| 63 | - | |
| 64 | - $results = $this->plugin->api->post_firewall_htaccess_rule(); | |
| 65 | - $rules = ! isset( $results['rules'] ) || empty( $results ) ? '' : $results['rules']; | |
| 66 | - | |
| 67 | - // Check if we have to update anything at all. | |
| 68 | - $hash = sha1( $rules ); | |
| 69 | - if ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == $hash || ( get_option( 'patchstack_firewall_htaccess_hash', '' ) == '' && $rules == '' ) ) { | |
| 70 | - return; | |
| 71 | - } | |
| 72 | - | |
| 73 | - // We have rules so apply it to the .htaccess file. | |
| 74 | - update_option( 'patchstack_firewall_htaccess_hash', $hash ); | |
| 75 | - } | |
| 76 | - | |
| 77 | - /** | |
| 78 | 60 | * Pull the firewall/whitelist rules from the API. |
| 79 | 61 | * |
| 80 | 62 | * @return void |
| 81 | 63 | */ |
| @@ -89,16 +71,74 @@ | ||
| 89 | 71 | if ( ! isset( $results['firewall'] ) ) { |
| 90 | 72 | return; |
| 91 | 73 | } |
| 92 | 74 | |
| 75 | + // Separate the new firewall engine rules from the old ones. | |
| 76 | + $newRules = []; | |
| 77 | + $newRulesAP = []; | |
| 78 | + $oldRules = []; | |
| 79 | + | |
| 80 | + // Counters for displaying purposes on the API key page. | |
| 81 | + $vPatchCount = 0; | |
| 82 | + $ruleCount = 0; | |
| 83 | + | |
| 84 | + // Parse the rules. | |
| 85 | + foreach ( $results['firewall'] as $rule ) { | |
| 86 | + if ( isset( $rule['rule_v2'] ) ) { | |
| 87 | + $rule['rules'] = $rule['rule_v2']; | |
| 88 | + unset( $rule['rule_v2'] ); | |
| 89 | + | |
| 90 | + // Mark vPatches based on substring. | |
| 91 | + if ( stripos( $rule['title'], ' vulnerabilit' ) !== false && stripos( $rule['title'], 'block ' ) !== false ) { | |
| 92 | + $vPatchCount++; | |
| 93 | + } else { | |
| 94 | + $ruleCount++; | |
| 95 | + } | |
| 96 | + | |
| 97 | + // Differentiate between auto prepend rules and regular ones. | |
| 98 | + if ( isset( $rule['ap'] ) && !empty( $rule['ap'] ) ) { | |
| 99 | + $newRulesAP[] = $rule; | |
| 100 | + } else { | |
| 101 | + $newRules[] = $rule; | |
| 102 | + } | |
| 103 | + } else { | |
| 104 | + $ruleCount++; | |
| 105 | + $oldRules[] = $rule; | |
| 106 | + } | |
| 107 | + } | |
| 108 | + | |
| 93 | 109 | // Update firewall rules. |
| 94 | - update_option( 'patchstack_firewall_rules', json_encode( $results['firewall'] ) ); | |
| 110 | + update_option( 'patchstack_firewall_rules', json_encode( $oldRules ), true ); | |
| 111 | + update_option( 'patchstack_firewall_rules_v3', json_encode( $newRules ), true ); | |
| 112 | + update_option( 'patchstack_firewall_rules_v3_ap', json_encode( $newRulesAP ), true ); | |
| 95 | 113 | |
| 96 | - // Update whitelist rules. | |
| 97 | - update_option( 'patchstack_whitelist_rules', json_encode( $results['whitelists'] ) ); | |
| 114 | + // Update the counters. | |
| 115 | + update_option( 'patchstack_vpatches_present', $vPatchCount ); | |
| 116 | + update_option( 'patchstack_non_vpatches_present', $ruleCount ); | |
| 98 | 117 | |
| 99 | - // Update secondary whitelist rules. | |
| 118 | + // Separate the new firewall engine rules from the old ones. Only touch the | |
| 119 | + // stored whitelists when the API actually returned them, otherwise a partial | |
| 120 | + // response would wipe the existing whitelist rules. | |
| 121 | + if ( isset( $results['whitelists'] ) && is_array( $results['whitelists'] ) ) { | |
| 122 | + $newRules = []; | |
| 123 | + $oldRules = []; | |
| 124 | + foreach ( $results['whitelists'] as $rule ) { | |
| 125 | + if ( isset( $rule['rule_v2'] ) ) { | |
| 126 | + $rule['rules'] = $rule['rule_v2']; | |
| 127 | + unset( $rule['rule_v2'] ); | |
| 128 | + $newRules[] = $rule; | |
| 129 | + } else { | |
| 130 | + $oldRules[] = $rule; | |
| 131 | + } | |
| 132 | + } | |
| 133 | + | |
| 134 | + // Update whitelist rules. | |
| 135 | + update_option( 'patchstack_whitelist_rules', json_encode( $oldRules ), true ); | |
| 136 | + update_option( 'patchstack_whitelist_rules_v3', json_encode( $newRules ), true ); | |
| 137 | + } | |
| 138 | + | |
| 139 | + // Update the whitelisted keys. | |
| 100 | 140 | if ( isset( $results['whitelist_keys'] ) ) { |
| 101 | - update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ) ); | |
| 141 | + update_option( 'patchstack_whitelist_keys_rules', json_encode( $results['whitelist_keys'] ), true ); | |
| 102 | 142 | } |
| 103 | 143 | } |
| 104 | 144 | } |