abstracts
4 weeks ago
admin
1 week ago
blocks
10 months ago
cli
7 months ago
customizer
3 months ago
data-stores
3 weeks ago
emails
1 week ago
export
1 year ago
gateways
2 months ago
import
2 months ago
integrations
4 weeks ago
interfaces
3 months ago
legacy
3 months ago
libraries
1 year ago
log-handlers
1 year ago
payment-tokens
5 years ago
product-usage
1 year ago
queue
3 months ago
react-admin
3 months ago
rest-api
4 weeks ago
shipping
2 months ago
shortcodes
2 months ago
theme-support
2 years ago
tracks
3 months ago
traits
5 years ago
walkers
5 years ago
wccom-site
4 weeks ago
widgets
4 weeks ago
class-wc-ajax.php
4 weeks ago
class-wc-auth.php
1 year ago
class-wc-autoloader.php
7 months ago
class-wc-background-emailer.php
4 weeks ago
class-wc-background-updater.php
5 years ago
class-wc-brands-brand-settings-manager.php
1 year ago
class-wc-brands-coupons.php
1 year ago
class-wc-brands.php
4 months ago
class-wc-breadcrumb.php
3 months ago
class-wc-cache-helper.php
4 weeks ago
class-wc-cart-fees.php
2 years ago
class-wc-cart-session.php
2 months ago
class-wc-cart-totals.php
10 months ago
class-wc-cart.php
2 months ago
class-wc-checkout.php
4 weeks ago
class-wc-cli.php
9 months ago
class-wc-comments.php
3 months ago
class-wc-countries.php
4 weeks ago
class-wc-coupon.php
4 weeks ago
class-wc-customer-download-log.php
5 years ago
class-wc-customer-download.php
1 year ago
class-wc-customer.php
4 weeks ago
class-wc-data-exception.php
8 years ago
class-wc-data-store.php
3 years ago
class-wc-datetime.php
4 years ago
class-wc-deprecated-action-hooks.php
2 years ago
class-wc-deprecated-filter-hooks.php
2 months ago
class-wc-discounts.php
10 months ago
class-wc-download-handler.php
1 year ago
class-wc-emails.php
1 week ago
class-wc-embed.php
1 year ago
class-wc-form-handler.php
2 months ago
class-wc-frontend-scripts.php
4 weeks ago
class-wc-geo-ip.php
7 months ago
class-wc-geolite-integration.php
6 years ago
class-wc-geolocation.php
4 weeks ago
class-wc-https.php
2 years ago
class-wc-install.php
1 week ago
class-wc-integrations.php
5 years ago
class-wc-log-levels.php
2 years ago
class-wc-logger.php
3 months ago
class-wc-meta-data.php
4 years ago
class-wc-order-factory.php
4 weeks ago
class-wc-order-item-coupon.php
4 years ago
class-wc-order-item-fee.php
4 months ago
class-wc-order-item-meta.php
4 years ago
class-wc-order-item-product.php
4 weeks ago
class-wc-order-item-shipping.php
4 months ago
class-wc-order-item-tax.php
4 years ago
class-wc-order-item.php
4 months ago
class-wc-order-query.php
3 months ago
class-wc-order-refund.php
1 year ago
class-wc-order.php
3 weeks ago
class-wc-payment-gateways.php
4 weeks ago
class-wc-payment-tokens.php
3 years ago
class-wc-post-data.php
4 weeks ago
class-wc-post-types.php
4 weeks ago
class-wc-privacy-background-process.php
1 year ago
class-wc-privacy-erasers.php
9 months ago
class-wc-privacy-exporters.php
4 years ago
class-wc-privacy.php
11 months ago
class-wc-product-attribute.php
3 months ago
class-wc-product-download.php
3 months ago
class-wc-product-external.php
1 year ago
class-wc-product-factory.php
2 months ago
class-wc-product-grouped.php
2 months ago
class-wc-product-query.php
3 months ago
class-wc-product-simple.php
10 months ago
class-wc-product-variable.php
2 months ago
class-wc-product-variation.php
1 year ago
class-wc-query.php
4 weeks ago
class-wc-rate-limiter.php
4 years ago
class-wc-regenerate-images-request.php
3 years ago
class-wc-regenerate-images.php
1 year ago
class-wc-register-wp-admin-settings.php
4 years ago
class-wc-rest-authentication.php
1 year ago
class-wc-rest-exception.php
5 years ago
class-wc-session-handler.php
2 months ago
class-wc-shipping-rate.php
11 months ago
class-wc-shipping-zone.php
5 years ago
class-wc-shipping-zones.php
6 months ago
class-wc-shipping.php
4 weeks ago
class-wc-shortcodes.php
1 year ago
class-wc-structured-data.php
4 weeks ago
class-wc-tax.php
4 weeks ago
class-wc-template-loader.php
6 months ago
class-wc-tracker.php
7 months ago
class-wc-validation.php
2 years ago
class-wc-webhook.php
4 weeks ago
class-woocommerce.php
1 week ago
wc-account-functions.php
6 months ago
wc-attribute-functions.php
4 weeks ago
wc-brands-functions.php
1 year ago
wc-cart-functions.php
4 months ago
wc-conditional-functions.php
10 months ago
wc-core-functions.php
4 weeks ago
wc-coupon-functions.php
4 months ago
wc-deprecated-functions.php
3 months ago
wc-formatting-functions.php
6 months ago
wc-interactivity-api-functions.php
4 weeks ago
wc-notice-functions.php
4 months ago
wc-order-functions.php
3 weeks ago
wc-order-item-functions.php
3 years ago
wc-order-step-logger-functions.php
3 months ago
wc-page-functions.php
3 weeks ago
wc-product-functions.php
4 weeks ago
wc-rest-functions.php
6 months ago
wc-stock-functions.php
6 months ago
wc-template-functions.php
4 weeks ago
wc-template-hooks.php
9 months ago
wc-term-functions.php
4 weeks ago
wc-update-functions.php
1 week ago
wc-user-functions.php
4 weeks ago
wc-webhook-functions.php
4 weeks ago
wc-widget-functions.php
5 years ago
class-wc-geolocation.php
385 lines
| 1 | <?php |
| 2 | /** |
| 3 | * Geolocation class |
| 4 | * |
| 5 | * Handles geolocation and updating the geolocation database. |
| 6 | * |
| 7 | * This product includes GeoLite data created by MaxMind, available from http://www.maxmind.com. |
| 8 | * |
| 9 | * @package WooCommerce\Classes |
| 10 | * @version 3.9.0 |
| 11 | */ |
| 12 | |
| 13 | use Automattic\WooCommerce\Enums\DefaultCustomerAddress; |
| 14 | |
| 15 | defined( 'ABSPATH' ) || exit; |
| 16 | |
| 17 | /** |
| 18 | * WC_Geolocation Class. |
| 19 | */ |
| 20 | class WC_Geolocation { |
| 21 | |
| 22 | /** |
| 23 | * GeoLite IPv4 DB. |
| 24 | * |
| 25 | * @deprecated 3.4.0 |
| 26 | */ |
| 27 | const GEOLITE_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz'; |
| 28 | |
| 29 | /** |
| 30 | * GeoLite IPv6 DB. |
| 31 | * |
| 32 | * @deprecated 3.4.0 |
| 33 | */ |
| 34 | const GEOLITE_IPV6_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoIPv6.dat.gz'; |
| 35 | |
| 36 | /** |
| 37 | * GeoLite2 DB. |
| 38 | * |
| 39 | * @since 3.4.0 |
| 40 | * @deprecated 3.9.0 |
| 41 | */ |
| 42 | const GEOLITE2_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoLite2-Country.tar.gz'; |
| 43 | |
| 44 | /** |
| 45 | * API endpoints for looking up user IP address. |
| 46 | * |
| 47 | * @var array |
| 48 | */ |
| 49 | private static $ip_lookup_apis = array( |
| 50 | 'ipify' => 'http://api.ipify.org/', |
| 51 | 'ipecho' => 'http://ipecho.net/plain', |
| 52 | 'ident' => 'http://ident.me', |
| 53 | 'tnedi' => 'http://tnedi.me', |
| 54 | ); |
| 55 | |
| 56 | /** |
| 57 | * API endpoints for geolocating an IP address |
| 58 | * |
| 59 | * @var array |
| 60 | */ |
| 61 | private static $geoip_apis = array( |
| 62 | 'ipinfo.io' => 'https://ipinfo.io/%s/json', |
| 63 | 'ip-api.com' => 'http://ip-api.com/json/%s', |
| 64 | ); |
| 65 | |
| 66 | /** |
| 67 | * Check if geolocation is enabled. |
| 68 | * |
| 69 | * @since 3.4.0 |
| 70 | * @param string $current_settings Current geolocation settings. |
| 71 | * @return bool |
| 72 | */ |
| 73 | private static function is_geolocation_enabled( $current_settings ) { |
| 74 | return in_array( $current_settings, array( DefaultCustomerAddress::GEOLOCATION, DefaultCustomerAddress::GEOLOCATION_AJAX ), true ); |
| 75 | } |
| 76 | |
| 77 | /** |
| 78 | * Get current user IP Address. |
| 79 | * |
| 80 | * @return string |
| 81 | */ |
| 82 | public static function get_ip_address() { |
| 83 | if ( isset( $_SERVER['HTTP_X_REAL_IP'] ) ) { |
| 84 | return sanitize_text_field( wp_unslash( $_SERVER['HTTP_X_REAL_IP'] ) ); |
| 85 | } elseif ( isset( $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) { |
| 86 | // Proxy servers can send through this header like this: X-Forwarded-For: client1, proxy1, proxy2 |
| 87 | // Make sure we always only send through the first IP in the list which should always be the client IP. |
| 88 | $value = trim( current( preg_split( '/,/', sanitize_text_field( wp_unslash( $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) ) ) ); |
| 89 | // Account for the '<IPv4 address>:<port>', '[<IPv6>]' and '[<IPv6>]:<port>' cases, removing the port. |
| 90 | // The regular expression is oversimplified on purpose, later 'rest_is_ip_address' will do the actual IP address validation. |
| 91 | $value = preg_replace( '/([0-9]+\.[0-9]+\.[0-9]+\.[0-9]+)\:.*|\[([^]]+)\].*/', '$1$2', $value ); |
| 92 | return (string) rest_is_ip_address( $value ); |
| 93 | } elseif ( isset( $_SERVER['REMOTE_ADDR'] ) ) { |
| 94 | // Make sure we always only send through the first IP in the list which should always be the client IP. |
| 95 | $value = trim( current( preg_split( '/,/', sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) ) ) ) ); |
| 96 | return (string) rest_is_ip_address( $value ); |
| 97 | } |
| 98 | return ''; |
| 99 | } |
| 100 | |
| 101 | /** |
| 102 | * Get user IP Address using an external service. |
| 103 | * This can be used as a fallback for users on localhost where |
| 104 | * get_ip_address() will be a local IP and non-geolocatable. |
| 105 | * |
| 106 | * @return string |
| 107 | */ |
| 108 | public static function get_external_ip_address() { |
| 109 | $external_ip_address = '0.0.0.0'; |
| 110 | |
| 111 | if ( '' !== self::get_ip_address() ) { |
| 112 | $transient_name = 'external_ip_address_' . self::get_ip_address(); |
| 113 | $external_ip_address = get_transient( $transient_name ); |
| 114 | } |
| 115 | |
| 116 | if ( false === $external_ip_address ) { |
| 117 | $external_ip_address = '0.0.0.0'; |
| 118 | $ip_lookup_services = apply_filters( 'woocommerce_geolocation_ip_lookup_apis', self::$ip_lookup_apis ); |
| 119 | $ip_lookup_services_keys = array_keys( $ip_lookup_services ); |
| 120 | shuffle( $ip_lookup_services_keys ); |
| 121 | |
| 122 | foreach ( $ip_lookup_services_keys as $service_name ) { |
| 123 | $service_endpoint = $ip_lookup_services[ $service_name ]; |
| 124 | $response = wp_safe_remote_get( |
| 125 | $service_endpoint, |
| 126 | array( |
| 127 | 'timeout' => 2, |
| 128 | 'user-agent' => 'WooCommerce/' . wc()->version, |
| 129 | ) |
| 130 | ); |
| 131 | |
| 132 | if ( ! is_wp_error( $response ) && rest_is_ip_address( $response['body'] ) ) { |
| 133 | $external_ip_address = apply_filters( 'woocommerce_geolocation_ip_lookup_api_response', wc_clean( $response['body'] ), $service_name ); |
| 134 | break; |
| 135 | } |
| 136 | } |
| 137 | |
| 138 | set_transient( $transient_name, $external_ip_address, DAY_IN_SECONDS ); |
| 139 | } |
| 140 | |
| 141 | return $external_ip_address; |
| 142 | } |
| 143 | |
| 144 | /** |
| 145 | * Geolocate an IP address. |
| 146 | * |
| 147 | * @param string $ip_address IP Address. |
| 148 | * @param bool $fallback If true, fallbacks to alternative IP detection (can be slower). |
| 149 | * @param bool $api_fallback If true, uses geolocation APIs if the database file doesn't exist (can be slower). |
| 150 | * @return array |
| 151 | */ |
| 152 | public static function geolocate_ip( $ip_address = '', $fallback = false, $api_fallback = true ) { |
| 153 | /** |
| 154 | * Filter to allow custom geolocation of the IP address. |
| 155 | * |
| 156 | * @since 3.9.0 |
| 157 | * @param string $geolocation Country code. |
| 158 | * @param string $ip_address IP Address. |
| 159 | * @param bool $fallback If true, fallbacks to alternative IP detection (can be slower). |
| 160 | * @param bool $api_fallback If true, uses geolocation APIs if the database file doesn't exist (can be slower). |
| 161 | * @return string |
| 162 | */ |
| 163 | $country_code = apply_filters( 'woocommerce_geolocate_ip', false, $ip_address, $fallback, $api_fallback ); |
| 164 | |
| 165 | if ( false !== $country_code ) { |
| 166 | return array( |
| 167 | 'country' => $country_code, |
| 168 | 'state' => '', |
| 169 | 'city' => '', |
| 170 | 'postcode' => '', |
| 171 | ); |
| 172 | } |
| 173 | |
| 174 | if ( empty( $ip_address ) ) { |
| 175 | $ip_address = self::get_ip_address(); |
| 176 | $country_code = self::get_country_code_from_headers(); |
| 177 | } |
| 178 | |
| 179 | /** |
| 180 | * Get geolocation filter. |
| 181 | * |
| 182 | * @since 3.9.0 |
| 183 | * @param array $geolocation Geolocation data, including country, state, city, and postcode. |
| 184 | * @param string $ip_address IP Address. |
| 185 | */ |
| 186 | $geolocation = apply_filters( |
| 187 | 'woocommerce_get_geolocation', |
| 188 | array( |
| 189 | 'country' => $country_code ? $country_code : '', |
| 190 | 'state' => '', |
| 191 | 'city' => '', |
| 192 | 'postcode' => '', |
| 193 | ), |
| 194 | $ip_address |
| 195 | ); |
| 196 | |
| 197 | // If we still haven't found a country code, let's consider doing an API lookup. |
| 198 | if ( '' === $geolocation['country'] && $api_fallback ) { |
| 199 | $geolocation['country'] = self::geolocate_via_api( $ip_address ); |
| 200 | } |
| 201 | |
| 202 | // It's possible that we're in a local environment, in which case the geolocation needs to be done from the |
| 203 | // external address. |
| 204 | if ( '' === $geolocation['country'] && $fallback ) { |
| 205 | $external_ip_address = self::get_external_ip_address(); |
| 206 | |
| 207 | // Only bother with this if the external IP differs. |
| 208 | if ( '0.0.0.0' !== $external_ip_address && $external_ip_address !== $ip_address ) { |
| 209 | return self::geolocate_ip( $external_ip_address, false, $api_fallback ); |
| 210 | } |
| 211 | } |
| 212 | |
| 213 | return array( |
| 214 | 'country' => $geolocation['country'], |
| 215 | 'state' => $geolocation['state'], |
| 216 | 'city' => $geolocation['city'], |
| 217 | 'postcode' => $geolocation['postcode'], |
| 218 | ); |
| 219 | } |
| 220 | |
| 221 | /** |
| 222 | * Path to our local db. |
| 223 | * |
| 224 | * @deprecated 3.9.0 |
| 225 | * @param string $deprecated Deprecated since 3.4.0. |
| 226 | * @return string |
| 227 | */ |
| 228 | public static function get_local_database_path( $deprecated = '2' ) { |
| 229 | wc_deprecated_function( 'WC_Geolocation::get_local_database_path', '3.9.0' ); |
| 230 | $integration = wc()->integrations->get_integration( 'maxmind_geolocation' ); |
| 231 | return $integration->get_database_service()->get_database_path(); |
| 232 | } |
| 233 | |
| 234 | /** |
| 235 | * Update geoip database. |
| 236 | * |
| 237 | * @deprecated 3.9.0 |
| 238 | * Extract files with PharData. Tool built into PHP since 5.3. |
| 239 | */ |
| 240 | public static function update_database() { |
| 241 | wc_deprecated_function( 'WC_Geolocation::update_database', '3.9.0' ); |
| 242 | $integration = wc()->integrations->get_integration( 'maxmind_geolocation' ); |
| 243 | $integration->update_database(); |
| 244 | } |
| 245 | |
| 246 | /** |
| 247 | * Fetches the country code from the request headers, if one is available. |
| 248 | * |
| 249 | * @since 3.9.0 |
| 250 | * @return string The country code pulled from the headers, or empty string if one was not found. |
| 251 | */ |
| 252 | private static function get_country_code_from_headers() { |
| 253 | $country_code = ''; |
| 254 | |
| 255 | $headers = array( |
| 256 | 'MM_COUNTRY_CODE', |
| 257 | 'GEOIP_COUNTRY_CODE', |
| 258 | 'HTTP_CF_IPCOUNTRY', |
| 259 | 'HTTP_X_COUNTRY_CODE', |
| 260 | ); |
| 261 | |
| 262 | foreach ( $headers as $header ) { |
| 263 | if ( empty( $_SERVER[ $header ] ) ) { |
| 264 | continue; |
| 265 | } |
| 266 | |
| 267 | $country_code = strtoupper( sanitize_text_field( wp_unslash( $_SERVER[ $header ] ) ) ); |
| 268 | break; |
| 269 | } |
| 270 | |
| 271 | return $country_code; |
| 272 | } |
| 273 | |
| 274 | /** |
| 275 | * Use APIs to Geolocate the user. |
| 276 | * |
| 277 | * Geolocation APIs can be added through the use of the woocommerce_geolocation_geoip_apis filter. |
| 278 | * Provide a name=>value pair for service-slug=>endpoint. |
| 279 | * |
| 280 | * If APIs are defined, one will be chosen at random to fulfil the request. After completing, the result |
| 281 | * will be cached in a transient. |
| 282 | * |
| 283 | * @param string $ip_address IP address. |
| 284 | * @return string |
| 285 | */ |
| 286 | private static function geolocate_via_api( $ip_address ) { |
| 287 | $country_code = get_transient( 'geoip_' . $ip_address ); |
| 288 | |
| 289 | if ( false === $country_code ) { |
| 290 | $geoip_services = apply_filters( 'woocommerce_geolocation_geoip_apis', self::$geoip_apis ); |
| 291 | |
| 292 | if ( empty( $geoip_services ) ) { |
| 293 | return ''; |
| 294 | } |
| 295 | |
| 296 | $geoip_services_keys = array_keys( $geoip_services ); |
| 297 | |
| 298 | shuffle( $geoip_services_keys ); |
| 299 | |
| 300 | foreach ( $geoip_services_keys as $service_name ) { |
| 301 | $service_endpoint = $geoip_services[ $service_name ]; |
| 302 | $response = wp_safe_remote_get( |
| 303 | sprintf( $service_endpoint, $ip_address ), |
| 304 | array( |
| 305 | 'timeout' => 2, |
| 306 | 'user-agent' => 'WooCommerce/' . wc()->version, |
| 307 | ) |
| 308 | ); |
| 309 | |
| 310 | if ( ! is_wp_error( $response ) && $response['body'] ) { |
| 311 | switch ( $service_name ) { |
| 312 | case 'ipinfo.io': |
| 313 | $data = json_decode( $response['body'] ); |
| 314 | $country_code = isset( $data->country ) ? $data->country : ''; |
| 315 | break; |
| 316 | case 'ip-api.com': |
| 317 | $data = json_decode( $response['body'] ); |
| 318 | $country_code = isset( $data->countryCode ) ? $data->countryCode : ''; // @codingStandardsIgnoreLine |
| 319 | break; |
| 320 | default: |
| 321 | $country_code = apply_filters( 'woocommerce_geolocation_geoip_response_' . $service_name, '', $response['body'] ); |
| 322 | break; |
| 323 | } |
| 324 | |
| 325 | $country_code = sanitize_text_field( strtoupper( $country_code ) ); |
| 326 | |
| 327 | if ( $country_code ) { |
| 328 | break; |
| 329 | } |
| 330 | } |
| 331 | } |
| 332 | |
| 333 | set_transient( 'geoip_' . $ip_address, $country_code, DAY_IN_SECONDS ); |
| 334 | } |
| 335 | |
| 336 | return $country_code; |
| 337 | } |
| 338 | |
| 339 | /** |
| 340 | * Hook in geolocation functionality. |
| 341 | * |
| 342 | * @deprecated 3.9.0 |
| 343 | * @return null |
| 344 | */ |
| 345 | public static function init() { |
| 346 | wc_deprecated_function( 'WC_Geolocation::init', '3.9.0' ); |
| 347 | return null; |
| 348 | } |
| 349 | |
| 350 | /** |
| 351 | * Prevent geolocation via MaxMind when using legacy versions of php. |
| 352 | * |
| 353 | * @deprecated 3.9.0 |
| 354 | * @since 3.4.0 |
| 355 | * @param string $default_customer_address current value. |
| 356 | * @return string |
| 357 | */ |
| 358 | public static function disable_geolocation_on_legacy_php( $default_customer_address ) { |
| 359 | wc_deprecated_function( 'WC_Geolocation::disable_geolocation_on_legacy_php', '3.9.0' ); |
| 360 | |
| 361 | if ( self::is_geolocation_enabled( $default_customer_address ) ) { |
| 362 | $default_customer_address = DefaultCustomerAddress::BASE; |
| 363 | } |
| 364 | |
| 365 | return $default_customer_address; |
| 366 | } |
| 367 | |
| 368 | /** |
| 369 | * Maybe trigger a DB update for the first time. |
| 370 | * |
| 371 | * @deprecated 3.9.0 |
| 372 | * @param string $new_value New value. |
| 373 | * @param string $old_value Old value. |
| 374 | * @return string |
| 375 | */ |
| 376 | public static function maybe_update_database( $new_value, $old_value ) { |
| 377 | wc_deprecated_function( 'WC_Geolocation::maybe_update_database', '3.9.0' ); |
| 378 | if ( $new_value !== $old_value && self::is_geolocation_enabled( $new_value ) ) { |
| 379 | self::update_database(); |
| 380 | } |
| 381 | |
| 382 | return $new_value; |
| 383 | } |
| 384 | } |
| 385 |