PluginProbe ʕ •ᴥ•ʔ
WooCommerce / 8.8.7
WooCommerce v8.8.7
10.9.1 10.9.0 10.9.0-rc.1 10.9.0-beta.2 10.9.0-beta.1 10.8.1 10.8.0 10.8.0-rc.1 10.8.0-beta.2 10.8.0-beta.1 7.8.0-beta.1 7.8.0-beta.2 7.8.0-rc.1 7.8.0-rc.2 7.8.1 7.8.2 7.8.3 7.8.4 7.9.0 7.9.0-beta.1 7.9.0-beta.2 7.9.0-rc.2 7.9.0-rc.3 7.9.1 7.9.2 8.0.0 8.0.0-beta.1 8.0.0-beta.2 8.0.0-rc.1 8.0.0-rc.2 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.1.0 8.1.0-beta.1 8.1.0-rc.1 8.1.0-rc.2 8.1.1 8.1.2 8.1.3 8.1.4 8.2.0 8.2.0-beta.1 8.2.0-rc.1 8.2.0-rc.2 8.2.1 8.2.2 8.2.3 8.2.4 8.2.5 8.3.0 8.3.0-beta.1 8.3.0-rc.1 8.3.0-rc.2 8.3.1 8.3.2 8.3.3 8.3.4 8.4.0 8.4.0-beta.1 8.4.0-rc.1 8.4.1 8.4.2 8.4.3 8.5.0 8.5.0-beta.1 8.5.0-rc.1 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.6.0 8.6.0-beta.1 8.6.0-rc.1 8.6.1 8.6.2 8.6.3 8.6.4 8.7.0 8.7.0-beta.1 8.7.0-beta.2 8.7.0-rc.1 8.7.1 8.7.2 8.7.3 8.8.0 8.8.0-beta.1 8.8.0-rc.1 8.8.1 8.8.2 8.8.3 8.8.4 8.8.5 8.8.6 8.8.7 8.9.0 8.9.0-beta.1 8.9.0-rc.1 8.9.1 8.9.2 8.9.3 8.9.4 8.9.5 9.0.0 9.0.0-beta.1 9.0.0-beta.2 9.0.0-rc.1 9.0.1 9.0.2 9.0.3 9.0.4 9.1.0 9.1.0-beta.1 9.1.0-rc.1 9.1.1 9.1.2 9.1.3 9.1.4 9.1.5 9.1.6 9.2.0 9.2.0-beta.1 9.2.0-rc.1 9.2.1 9.2.2 9.2.3 9.2.4 9.2.5 9.3.0 9.3.0-beta.1 9.3.0-rc.1 9.3.1 9.3.2 9.3.3 9.3.4 9.3.5 9.3.6 9.4.0 9.4.0-beta.1 9.4.0-beta.2 9.4.0-rc.1 9.4.0-rc.2 9.4.0-rc.3 9.4.0-rc.4 9.4.1 9.4.2 9.4.3 9.4.4 9.4.5 9.5.0 9.5.0-beta.1 9.5.0-beta.2 9.5.0-rc.1 9.5.1 9.5.2 9.5.3 9.5.4 9.6.0 9.6.0-beta.1 9.6.0-beta.2 9.6.0-rc.1 9.6.1 9.6.2 9.6.3 9.6.4 9.7.0 9.7.0-beta.1 9.7.0-rc.1 9.7.1 9.7.2 9.7.3 9.8.0 9.8.0-beta.1 9.8.0-rc.1 9.8.1 9.8.2 9.8.3 9.8.4 9.8.5 9.8.6 9.8.7 9.9.0 9.9.0-beta.1 9.9.0-rc.1 9.9.1 9.9.2 9.9.3 9.9.4 9.9.5 9.9.6 9.9.7 3.7.3 7.1.2 3.8.0 7.2.0 3.8.0-beta.1 7.2.0-beta.1 3.8.0-rc.1 7.2.0-beta.2 3.8.0-rc.2 7.2.0-rc.1 3.8.1 7.2.0-rc.2 3.8.2 7.2.1 3.8.3 7.2.2 3.9.0 7.2.3 3.9.0-beta.1 7.2.4 3.9.0-beta.2 7.3.0 3.9.0-rc.1 7.3.0-beta.1 3.9.0-rc.2 7.3.0-beta.2 3.9.0-rc.3 7.3.0-rc.1 3.9.0-rc.4 7.3.0-rc.2 3.9.1 7.3.1 3.9.2 7.4.0 3.9.3 7.4.0-beta.1 3.9.4 7.4.0-beta.2 3.9.5 7.4.0-rc.1 4.0.0 7.4.0-rc.2 4.0.0-beta.1 7.4.1 4.0.0-rc.1 7.4.2 4.0.0-rc.2 7.5.0 4.0.1 7.5.0-beta.1 4.0.2 7.5.0-beta.2 4.0.3 7.5.0-rc.1 4.0.4 7.5.1 4.1.0 7.5.2 4.1.0-beta.1 7.6.0 4.1.0-beta.2 7.6.0-beta.1 4.1.0-rc.1 7.6.0-beta.2 4.1.0-rc.2 7.6.0-rc.1 4.1.1 7.6.0-rc.2 4.1.2 7.6.0-rc.3 4.1.3 7.6.1 4.1.4 7.6.2 4.2.0 7.7.0 4.2.0-RC.1 7.7.0-beta.1 4.2.0-RC.2 7.7.0-beta.2 4.2.0-beta.1 7.7.0-rc.1 4.2.1 7.7.1 4.2.2 7.7.2 4.2.3 7.7.3 4.2.4 7.8.0 4.2.5 4.3.0 4.3.0-beta.1 4.3.0-rc.1 4.3.0-rc.2 4.3.0-rc.3 4.3.1 4.3.2 4.3.3 4.3.4 4.3.5 4.3.6 4.4.0 4.4.0-beta.1 4.4.0-rc.1 4.4.1 4.4.2 4.4.3 4.4.4 4.5.0 4.5.0-beta.1 4.5.0-rc.1 4.5.0-rc.3 4.5.1 4.5.2 4.5.3 4.5.4 4.5.5 4.6.0 4.6.0-beta.1 4.6.0-rc.1 4.6.1 4.6.2 4.6.3 4.6.4 4.6.5 4.7.0 4.7.0-beta.1 4.7.0-beta.2 4.7.0-rc.1 4.7.1 4.7.1-beta.1 4.7.2 4.7.3 4.7.4 4.8.0 4.8.0-beta.1 4.8.0-rc.1 4.8.0-rc.2 4.8.1 4.8.2 4.8.3 4.9.0 4.9.0-beta.1 4.9.0-rc.1 4.9.0-rc.2 4.9.1 4.9.2 4.9.3 4.9.4 4.9.5 5.0.0 5.0.0-beta.1 5.0.0-beta.2 5.0.0-rc.1 5.0.0-rc.2 5.0.0-rc.3 5.0.1 5.0.2 5.0.3 5.1.0 5.1.0-beta.1 5.1.0-rc.1 trunk 5.1.1 10.0.0 5.1.2 10.0.0-rc.1 5.1.3 10.0.0-rc.2 5.2.0 10.0.1 5.2.0-beta.1 10.0.2 5.2.0-rc.1 10.0.3 5.2.0-rc.2 10.0.4 5.2.1 10.0.5 5.2.2 10.0.6 5.2.3 10.1.0 5.2.4 10.1.0-rc.1 5.2.5 10.1.0-rc.2 5.3.0 10.1.0-rc.3 5.3.0-beta.1 10.1.0-rc.4 5.3.0-rc.1 10.1.1 5.3.0-rc.2 10.1.2 5.3.1 10.1.3 5.3.2 10.1.4 5.3.3 10.2.0 5.4.0 10.2.0-beta.1 5.4.0-beta.1 10.2.0-beta.2 5.4.0-rc.1 10.2.0-rc.1 5.4.1 10.2.1 5.4.2 10.2.2 5.4.3 10.2.3 5.4.4 10.2.4 5.4.5 10.3.0 5.5.0 10.3.0-beta.1 5.5.0-beta.1 10.3.0-beta.2 5.5.0-rc.1 10.3.0-rc.1 5.5.0-rc.2 10.3.0-rc.2 5.5.1 10.3.1 5.5.2 10.3.2 5.5.3 10.3.3 5.5.4 10.3.4 5.5.5 10.3.5 5.6.0 10.3.6 5.6.0-beta.1 10.3.7 5.6.0-rc.1 10.3.8 5.6.0-rc.2 10.4.0 5.6.1 10.4.0-beta.1 5.6.2 10.4.0-beta.2 5.6.3 10.4.0-rc.1 5.7.0 10.4.1 5.7.0-beta.1 10.4.2 5.7.0-rc.1 10.4.3 5.7.1 10.4.4 5.7.2 10.5.0 5.7.3 10.5.0-beta.1 5.8.0 10.5.0-beta.2 5.8.0-beta.1 10.5.0-rc.1 5.8.0-beta.2 10.5.0-rc.2 5.8.0-rc.1 10.5.0-rc.3 5.8.1 10.5.1 5.8.2 10.5.2 5.9.0 10.5.3 5.9.0-beta.1 10.6.0 5.9.0-rc.1 10.6.0-beta.1 5.9.0-rc.2 10.6.0-beta.2 5.9.1 10.6.0-rc.1 5.9.2 10.6.1 6.0.0 10.6.2 6.0.0-beta.1 10.7.0 6.0.0-rc.1 10.7.0-beta.1 6.0.1 10.7.0-beta.2 6.0.2 10.7.0-rc.1 6.1.0 3.0.0 6.1.0-beta.1 3.0.1 6.1.0-rc.1 3.0.2 6.1.0-rc.2 3.0.3 6.1.1 3.0.4 6.1.2 3.0.5 6.1.3 3.0.6 6.2.0 3.0.7 6.2.0-beta.1 3.0.8 6.2.0-rc.1 3.0.9 6.2.0-rc.2 3.1.0 6.2.1 3.1.1 6.2.2 3.1.2 6.2.3 3.2.0 6.3.0 3.2.1 6.3.0-beta.1 3.2.2 6.3.0-rc.1 3.2.3 6.3.0-rc.2 3.2.4 6.3.1 3.2.5 6.3.2 3.2.6 6.4.0 3.3.0 6.4.0-beta.1 3.3.1 6.4.0-rc.1 3.3.2 6.4.1 3.3.2-rc.1 6.4.2 3.3.3 6.5.0 3.3.4 6.5.0-beta.1 3.3.5 6.5.0-rc.1 3.3.6 6.5.0-rc.2 3.4.0 6.5.1 3.4.0-beta.1 6.5.2 3.4.0-rc.2 6.6.0 3.4.1 6.6.0-beta.1 3.4.2 6.6.0-rc.1 3.4.3 6.6.0-rc.2 3.4.4 6.6.1 3.4.5 6.6.2 3.4.6 6.7.0 3.4.7 6.7.0-beta.1 3.4.8 6.7.0-beta.2 3.5.0 6.7.0-rc.1 3.5.0-beta.1 6.7.1 3.5.0-rc.1 6.8.0 3.5.0-rc.2 6.8.0-beta.1 3.5.1 6.8.0-beta.2 3.5.10 6.8.0-rc.1 3.5.2 6.8.1 3.5.3 6.8.2 3.5.4 6.8.3 3.5.5 6.9.0 3.5.6 6.9.0-beta.1 3.5.7 6.9.0-beta.2 3.5.8 6.9.0-rc.1 3.5.9 6.9.1 3.6.0 6.9.2 3.6.0-beta.1 6.9.3 3.6.0-rc.1 6.9.4 3.6.0-rc.2 6.9.5 3.6.0-rc.3 7.0.0 3.6.1 7.0.0-beta.1 3.6.2 7.0.0-beta.2 3.6.3 7.0.0-beta.3 3.6.4 7.0.0-rc.1 3.6.5 7.0.0-rc.2 3.6.6 7.0.1 3.6.7 7.0.2 3.7.0 7.1.0 3.7.0-beta.1 7.1.0-beta.1 3.7.0-rc.1 7.1.0-beta.2 3.7.0-rc.2 7.1.0-rc.1 3.7.1 7.1.0-rc.2 3.7.2 7.1.1
woocommerce / includes / wccom-site / class-wc-wccom-site.php
woocommerce / includes / wccom-site Last commit date
installation 2 years ago rest-api 2 years ago class-wc-wccom-site-installer.php 2 years ago class-wc-wccom-site.php 2 years ago
class-wc-wccom-site.php
250 lines
1 <?php
2 /**
3 * WooCommerce.com Product Installation.
4 *
5 * @package WooCommerce\WCCom
6 * @since 3.7.0
7 */
8
9 use WC_REST_WCCOM_Site_Installer_Error_Codes as Installer_Error_Codes;
10 use WC_REST_WCCOM_Site_Installer_Error as Installer_Error;
11
12 defined( 'ABSPATH' ) || exit;
13
14 /**
15 * WC_WCCOM_Site Class
16 *
17 * Main class for WooCommerce.com connected site.
18 */
19 class WC_WCCOM_Site {
20
21 const AUTH_ERROR_FILTER_NAME = 'wccom_auth_error';
22
23 /**
24 * Load the WCCOM site class.
25 *
26 * @since 3.7.0
27 */
28 public static function load() {
29 self::includes();
30
31 add_action( 'woocommerce_wccom_install_products', array( 'WC_WCCOM_Site_Installer', 'install' ) );
32 add_filter( 'determine_current_user', array( __CLASS__, 'authenticate_wccom' ), 14 );
33 add_action( 'woocommerce_rest_api_get_rest_namespaces', array( __CLASS__, 'register_rest_namespace' ) );
34 }
35
36 /**
37 * Include support files.
38 *
39 * @since 3.7.0
40 */
41 protected static function includes() {
42 require_once WC_ABSPATH . 'includes/admin/helper/class-wc-helper.php';
43 require_once WC_ABSPATH . 'includes/wccom-site/class-wc-wccom-site-installer.php';
44 }
45
46 /**
47 * Authenticate WooCommerce.com request.
48 *
49 * @since 3.7.0
50 * @param int|false $user_id User ID.
51 * @return int|false
52 */
53 public static function authenticate_wccom( $user_id ) {
54 if ( ! empty( $user_id ) || ! self::is_request_to_wccom_site_rest_api() ) {
55 return $user_id;
56 }
57
58 $auth_header = trim( self::get_authorization_header() );
59
60 if ( stripos( $auth_header, 'Bearer ' ) === 0 ) {
61 $access_token = trim( substr( $auth_header, 7 ) );
62 } elseif ( ! empty( $_GET['token'] ) && is_string( $_GET['token'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
63 $access_token = trim( $_GET['token'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
64 } else {
65 add_filter(
66 self::AUTH_ERROR_FILTER_NAME,
67 function() {
68 return new Installer_Error( Installer_Error_Codes::NO_ACCESS_TOKEN );
69 }
70 );
71 return false;
72 }
73
74 if ( ! empty( $_SERVER['HTTP_X_WOO_SIGNATURE'] ) ) {
75 $signature = trim( $_SERVER['HTTP_X_WOO_SIGNATURE'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.MissingUnslash,WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
76 } elseif ( ! empty( $_GET['signature'] ) && is_string( $_GET['signature'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
77 $signature = trim( $_GET['signature'] ); // phpcs:ignore WordPress.Security.NonceVerification.Recommended, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
78 } else {
79 add_filter(
80 self::AUTH_ERROR_FILTER_NAME,
81 function() {
82 return new Installer_Error( Installer_Error_Codes::NO_SIGNATURE );
83 }
84 );
85 return false;
86 }
87
88 require_once WC_ABSPATH . 'includes/admin/helper/class-wc-helper-options.php';
89 $site_auth = WC_Helper_Options::get( 'auth' );
90
91 if ( empty( $site_auth['access_token'] ) ) {
92 add_filter(
93 self::AUTH_ERROR_FILTER_NAME,
94 function() {
95 return new Installer_Error( Installer_Error_Codes::SITE_NOT_CONNECTED );
96 }
97 );
98 return false;
99 }
100
101 if ( ! hash_equals( $access_token, $site_auth['access_token'] ) ) {
102 add_filter(
103 self::AUTH_ERROR_FILTER_NAME,
104 function() {
105 return new Installer_Error( Installer_Error_Codes::INVALID_TOKEN );
106 }
107 );
108 return false;
109 }
110
111 $body = WP_REST_Server::get_raw_data();
112
113 if ( ! self::verify_wccom_request( $body, $signature, $site_auth['access_token_secret'] ) ) {
114 add_filter(
115 self::AUTH_ERROR_FILTER_NAME,
116 function() {
117 return new Installer_Error( Installer_Error_Codes::REQUEST_VERIFICATION_FAILED );
118 }
119 );
120 return false;
121 }
122
123 $user = get_user_by( 'id', $site_auth['user_id'] );
124 if ( ! $user ) {
125 add_filter(
126 self::AUTH_ERROR_FILTER_NAME,
127 function() {
128 return new Installer_Error( Installer_Error_Codes::USER_NOT_FOUND );
129 }
130 );
131 return false;
132 }
133
134 return $user;
135 }
136
137 /**
138 * Get the authorization header.
139 *
140 * On certain systems and configurations, the Authorization header will be
141 * stripped out by the server or PHP. Typically this is then used to
142 * generate `PHP_AUTH_USER`/`PHP_AUTH_PASS` but not passed on. We use
143 * `getallheaders` here to try and grab it out instead.
144 *
145 * @since 3.7.0
146 * @return string Authorization header if set.
147 */
148 protected static function get_authorization_header() {
149 if ( ! empty( $_SERVER['HTTP_AUTHORIZATION'] ) ) {
150 return wp_unslash( $_SERVER['HTTP_AUTHORIZATION'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
151 }
152
153 if ( function_exists( 'getallheaders' ) ) {
154 $headers = getallheaders();
155 // Check for the authoization header case-insensitively.
156 foreach ( $headers as $key => $value ) {
157 if ( 'authorization' === strtolower( $key ) ) {
158 return $value;
159 }
160 }
161 }
162
163 return '';
164 }
165
166 /**
167 * Check if this is a request to WCCOM Site REST API.
168 *
169 * @since 3.7.0
170 * @return bool
171 */
172 protected static function is_request_to_wccom_site_rest_api() {
173
174 if ( isset( $_REQUEST['rest_route'] ) ) { // phpcs:ignore WordPress.Security.NonceVerification.Recommended
175 $route = wp_unslash( $_REQUEST['rest_route'] ); // phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitized, WordPress.Security.NonceVerification.Recommended
176 $rest_prefix = '';
177 } else {
178 $route = wp_unslash( add_query_arg( array() ) );
179 $rest_prefix = trailingslashit( rest_get_url_prefix() );
180 }
181
182 return false !== strpos( $route, $rest_prefix . 'wccom-site/' );
183 }
184
185 /**
186 * Verify WooCommerce.com request from a given body and signature request.
187 *
188 * @since 3.7.0
189 * @param string $body Request body.
190 * @param string $signature Request signature found in X-Woo-Signature header.
191 * @param string $access_token_secret Access token secret for this site.
192 * @return bool
193 */
194 protected static function verify_wccom_request( $body, $signature, $access_token_secret ) {
195 // phpcs:disable WordPress.Security.ValidatedSanitizedInput.InputNotValidated, WordPress.Security.ValidatedSanitizedInput.MissingUnslash, WordPress.Security.ValidatedSanitizedInput.InputNotSanitized
196 $data = array(
197 'host' => $_SERVER['HTTP_HOST'],
198 'request_uri' => urldecode( remove_query_arg( array( 'token', 'signature' ), $_SERVER['REQUEST_URI'] ) ),
199 'method' => strtoupper( $_SERVER['REQUEST_METHOD'] ),
200 );
201 // phpcs:enable
202
203 if ( ! empty( $body ) ) {
204 $data['body'] = $body;
205 }
206
207 $expected_signature = hash_hmac( 'sha256', wp_json_encode( $data ), $access_token_secret );
208
209 return hash_equals( $expected_signature, $signature );
210 }
211
212 /**
213 * Register wccom-site REST namespace.
214 *
215 * @since 3.7.0
216 * @param array $namespaces List of registered namespaces.
217 * @return array Registered namespaces.
218 */
219 public static function register_rest_namespace( $namespaces ) {
220
221 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/class-wc-rest-wccom-site-installer-error-codes.php';
222 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/class-wc-rest-wccom-site-installer-error.php';
223 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/endpoints/abstract-wc-rest-wccom-site-controller.php';
224 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/endpoints/class-wc-rest-wccom-site-installer-controller.php';
225 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/endpoints/class-wc-rest-wccom-site-ssr-controller.php';
226 require_once WC_ABSPATH . 'includes/wccom-site/rest-api/endpoints/class-wc-rest-wccom-site-status-controller.php';
227
228 require_once WC_ABSPATH . 'includes/wccom-site/installation/class-wc-wccom-site-installation-state.php';
229 require_once WC_ABSPATH . 'includes/wccom-site/installation/class-wc-wccom-site-installation-state-storage.php';
230 require_once WC_ABSPATH . 'includes/wccom-site/installation/class-wc-wccom-site-installation-manager.php';
231
232 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/interface-installaton-step.php';
233 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/class-wc-wccom-site-installation-step-get-product-info.php';
234 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/class-wc-wccom-site-installation-step-download-product.php';
235 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/class-wc-wccom-site-installation-step-unpack-product.php';
236 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/class-wc-wccom-site-installation-step-move-product.php';
237 require_once WC_ABSPATH . 'includes/wccom-site/installation/installation-steps/class-wc-wccom-site-installation-step-activate-product.php';
238
239 $namespaces['wccom-site/v2'] = array(
240 'installer' => 'WC_REST_WCCOM_Site_Installer_Controller',
241 'ssr' => 'WC_REST_WCCOM_Site_SSR_Controller',
242 'status' => 'WC_REST_WCCOM_Site_Status_Controller',
243 );
244
245 return $namespaces;
246 }
247 }
248
249 WC_WCCOM_Site::load();
250