PluginProbe
WCPOS – Point of Sale (POS) plugin for WooCommerce / 1.10.7
WCPOS – Point of Sale (POS) plugin for WooCommerce v1.10.7
1.10.22 1.10.21 1.10.20 1.10.19 1.10.18 1.10.17 1.10.16 1.10.15 1.10.13 1.10.14 1.10.12 1.10.11 1.10.10 1.10.9 1.10.8 untagged-3d9b7ccddc54df87c672 1.10.7 1.10.6 1.10.5 1.10.3 1.10.4 1.10.2 1.10.1 1.10.0 1.9.17 All 166 releases
woocommerce-pos / vendor / ramsey / uuid / src / Provider / Dce / SystemDceSecurityProvider.php

SystemDceSecurityProvider.php in WCPOS – Point of Sale (POS) plugin for WooCommerce 1.10.7, at vendor/ramsey/uuid/src/Provider/Dce/SystemDceSecurityProvider.php

235 lines 6.5 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 /**
4 * This file is part of the ramsey/uuid library
5 *
6 * For the full copyright and license information, please view the LICENSE
7 * file that was distributed with this source code.
8 *
9 * @copyright Copyright (c) Ben Ramsey <[email protected]>
10 * @license http://opensource.org/licenses/MIT MIT
11 */
12
13 declare(strict_types=1);
14
15 namespace Ramsey\Uuid\Provider\Dce;
16
17 use Ramsey\Uuid\Exception\DceSecurityException;
18 use Ramsey\Uuid\Provider\DceSecurityProviderInterface;
19 use Ramsey\Uuid\Type\Integer as IntegerObject;
20
21 use function escapeshellarg;
22 use function preg_split;
23 use function str_getcsv;
24 use function strpos;
25 use function strrpos;
26 use function strtolower;
27 use function strtoupper;
28 use function substr;
29 use function trim;
30
31 use const PREG_SPLIT_NO_EMPTY;
32
33 /**
34 * SystemDceSecurityProvider retrieves the user or group identifiers from the system
35 */
36 class SystemDceSecurityProvider implements DceSecurityProviderInterface
37 {
38 /**
39 * @throws DceSecurityException if unable to get a user identifier
40 *
41 * @inheritDoc
42 */
43 public function getUid(): IntegerObject
44 {
45 static $uid = null;
46
47 if ($uid instanceof IntegerObject) {
48 return $uid;
49 }
50
51 if ($uid === null) {
52 $uid = $this->getSystemUid();
53 }
54
55 if ($uid === '') {
56 throw new DceSecurityException(
57 'Unable to get a user identifier using the system DCE '
58 . 'Security provider; please provide a custom identifier or '
59 . 'use a different provider'
60 );
61 }
62
63 $uid = new IntegerObject($uid);
64
65 return $uid;
66 }
67
68 /**
69 * @throws DceSecurityException if unable to get a group identifier
70 *
71 * @inheritDoc
72 */
73 public function getGid(): IntegerObject
74 {
75 static $gid = null;
76
77 if ($gid instanceof IntegerObject) {
78 return $gid;
79 }
80
81 if ($gid === null) {
82 $gid = $this->getSystemGid();
83 }
84
85 if ($gid === '') {
86 throw new DceSecurityException(
87 'Unable to get a group identifier using the system DCE '
88 . 'Security provider; please provide a custom identifier or '
89 . 'use a different provider'
90 );
91 }
92
93 $gid = new IntegerObject($gid);
94
95 return $gid;
96 }
97
98 /**
99 * Returns the UID from the system
100 */
101 private function getSystemUid(): string
102 {
103 if (!$this->hasShellExec()) {
104 return '';
105 }
106
107 switch ($this->getOs()) {
108 case 'WIN':
109 return $this->getWindowsUid();
110 case 'DAR':
111 case 'FRE':
112 case 'LIN':
113 default:
114 return trim((string) shell_exec('id -u'));
115 }
116 }
117
118 /**
119 * Returns the GID from the system
120 */
121 private function getSystemGid(): string
122 {
123 if (!$this->hasShellExec()) {
124 return '';
125 }
126
127 switch ($this->getOs()) {
128 case 'WIN':
129 return $this->getWindowsGid();
130 case 'DAR':
131 case 'FRE':
132 case 'LIN':
133 default:
134 return trim((string) shell_exec('id -g'));
135 }
136 }
137
138 /**
139 * Returns true if shell_exec() is available for use
140 */
141 private function hasShellExec(): bool
142 {
143 $disabledFunctions = strtolower((string) ini_get('disable_functions'));
144
145 return strpos($disabledFunctions, 'shell_exec') === false;
146 }
147
148 /**
149 * Returns the PHP_OS string
150 */
151 private function getOs(): string
152 {
153 return strtoupper(substr(constant('PHP_OS'), 0, 3));
154 }
155
156 /**
157 * Returns the user identifier for a user on a Windows system
158 *
159 * Windows does not have the same concept as an effective POSIX UID for the
160 * running script. Instead, each user is uniquely identified by an SID
161 * (security identifier). The SID includes three 32-bit unsigned integers
162 * that make up a unique domain identifier, followed by an RID (relative
163 * identifier) that we will use as the UID. The primary caveat is that this
164 * UID may not be unique to the system, since it is, instead, unique to the
165 * domain.
166 *
167 * @link https://www.lifewire.com/what-is-an-sid-number-2626005 What Is an SID Number?
168 * @link https://bit.ly/30vE7NM Well-known SID Structures
169 * @link https://bit.ly/2FWcYKJ Well-known security identifiers in Windows operating systems
170 * @link https://www.windows-commandline.com/get-sid-of-user/ Get SID of user
171 */
172 private function getWindowsUid(): string
173 {
174 $response = shell_exec('whoami /user /fo csv /nh');
175
176 if ($response === null) {
177 return '';
178 }
179
180 $sid = str_getcsv(trim((string) $response))[1] ?? '';
181
182 if (($lastHyphen = strrpos($sid, '-')) === false) {
183 return '';
184 }
185
186 return trim(substr($sid, $lastHyphen + 1));
187 }
188
189 /**
190 * Returns a group identifier for a user on a Windows system
191 *
192 * Since Windows does not have the same concept as an effective POSIX GID
193 * for the running script, we will get the local group memberships for the
194 * user running the script. Then, we will get the SID (security identifier)
195 * for the first group that appears in that list. Finally, we will return
196 * the RID (relative identifier) for the group and use that as the GID.
197 *
198 * @link https://www.windows-commandline.com/list-of-user-groups-command-line/ List of user groups command line
199 */
200 private function getWindowsGid(): string
201 {
202 $response = shell_exec('net user %username% | findstr /b /i "Local Group Memberships"');
203
204 if ($response === null) {
205 return '';
206 }
207
208 /** @var string[] $userGroups */
209 $userGroups = preg_split('/\s{2,}/', (string) $response, -1, PREG_SPLIT_NO_EMPTY);
210
211 $firstGroup = trim($userGroups[1] ?? '', "* \t\n\r\0\x0B");
212
213 if ($firstGroup === '') {
214 return '';
215 }
216
217 $response = shell_exec('wmic group get name,sid | findstr /b /i ' . escapeshellarg($firstGroup));
218
219 if ($response === null) {
220 return '';
221 }
222
223 /** @var string[] $userGroup */
224 $userGroup = preg_split('/\s{2,}/', (string) $response, -1, PREG_SPLIT_NO_EMPTY);
225
226 $sid = $userGroup[1] ?? '';
227
228 if (($lastHyphen = strrpos($sid, '-')) === false) {
229 return '';
230 }
231
232 return trim((string) substr($sid, $lastHyphen + 1));
233 }
234 }
235