PluginProbe
The WP Remote WordPress Plugin / 6.76
The WP Remote WordPress Plugin v6.76
6.76 6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 All 54 releases
← All changes | protect/fw.php +393 -103 5.566.76 View file →
@@ -1,13 +1,13 @@
1 1 <?php
2 2 if (!defined('ABSPATH') && !defined('MCDATAPATH')) exit;
3 3
4 -if (!class_exists('WPRProtectFW_V556')) :
4 +if (!class_exists('WPRProtectFW_V676')) :
5 5 require_once dirname( __FILE__ ) . '/fw/rule/errors.php';
6 6 require_once dirname( __FILE__ ) . '/fw/rule/engine.php';
7 7 require_once dirname( __FILE__ ) . '/fw/rule.php';
8 8
9 -class WPRProtectFW_V556 {
9 +class WPRProtectFW_V676 {
10 10 private $brand_name;
11 11 private $protect_mode;
12 12 private $request;
13 13 private $ipstore;
@@ -19,26 +19,28 @@
19 19 private $is_ip_cookie_set = false;
20 20 private $is_request_profiled = false;
21 21 private $is_on_boot_rules_executed = false;
22 22 private $is_ip_checked_for_blacklisted = false;
23 + private $is_ip_whitelisted = null;
23 24 private $has_valid_bypass_cookie;
24 25
25 - private $mode = WPRProtectFW_V556::MODE_DISABLED;
26 - private $ip_cookie_mode = WPRProtectFW_V556::IP_COOKIE_MODE_DISABLED;
27 - private $admin_cookie_mode = WPRProtectFW_V556::ADMIN_COOKIE_MODE_DISABLED;
28 - private $bypass_level = WPRProtectFW_V556::WP_USER_ROLE_LEVEL_CONTRIBUTOR;
29 - private $wpf_rule_init_mode = WPRProtectFW_V556::WPF_RULE_INIT_MODE_WP;
26 + private $mode = WPRProtectFW_V676::MODE_DISABLED;
27 + private $ip_cookie_mode = WPRProtectFW_V676::IP_COOKIE_MODE_DISABLED;
28 + private $admin_cookie_mode = WPRProtectFW_V676::ADMIN_COOKIE_MODE_DISABLED;
29 + private $bypass_level = WPRProtectFW_V676::WP_USER_ROLE_LEVEL_CONTRIBUTOR;
30 + private $wpf_rule_init_mode = WPRProtectFW_V676::WPF_RULE_INIT_MODE_WP;
30 31 private $custom_roles = array();
31 32 private $cookie_key = "";
32 33 private $cookie_path = "";
33 34 private $cookie_domain = "";
35 + private $cookie_validity = 2592000;
34 36 private $can_set_cache_prevention_cookie = false;
35 - private $rules_mode = WPRProtectFW_V556::RULES_MODE_DISABLED;
37 + private $rules_mode = WPRProtectFW_V676::RULES_MODE_DISABLED;
36 38 private $is_geo_blocking = false;
37 39 private $is_wp_user_cookie_enabled = false;
38 40 private $log_config = array();
39 - private $request_profiling_mode = WPRProtectFW_V556::REQ_PROFILING_MODE_DISABLED;
40 - private $logging_mode = WPRProtectFW_V556::LOGGING_MODE_VISITOR;
41 + private $request_profiling_mode = WPRProtectFW_V676::REQ_PROFILING_MODE_DISABLED;
42 + private $logging_mode = WPRProtectFW_V676::LOGGING_MODE_VISITOR;
41 43 private $skip_log_config = array();
42 44 private $skip_log_cookies = array();
43 45 private $skip_log_headers = array();
44 46 private $skip_log_post_params = array();
@@ -51,9 +53,9 @@
51 53 private $rule_log = array();
52 54 private $matched_rules = array();
53 55 private $break_rule_matching = false;
54 56 private $can_log_raw_body = false;
55 - private $log_slice_size = WPRProtectFW_V556::LOG_SLICE_SIZE;
57 + private $log_slice_size = WPRProtectFW_V676::LOG_SLICE_SIZE;
56 58
57 59 private static $instance = null;
58 60
59 61 const MODE_DISABLED = 1;
@@ -97,18 +99,18 @@
97 99 const LOGGING_MODE_COMPLETE = 2;
98 100 const LOGGING_MODE_DISABLED = 3;
99 101
100 102 const DEFAULT_WP_USER_ROLE_LEVELS = array(
101 - 'administrator' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_ADMIN,
102 - 'editor' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_EDITOR,
103 - 'author' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_AUTHOR,
104 - 'contributor' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_CONTRIBUTOR,
105 - 'subscriber' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_SUBSCRIBER
103 + 'administrator' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_ADMIN,
104 + 'editor' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_EDITOR,
105 + 'author' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_AUTHOR,
106 + 'contributor' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_CONTRIBUTOR,
107 + 'subscriber' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_SUBSCRIBER
106 108 );
107 109
108 110 const EXTRA_WP_USER_ROLE_LEVELS = array(
109 - 'custom' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_CUSTOM,
110 - 'unknown' => WPRProtectFW_V556::WP_USER_ROLE_LEVEL_UNKNOWN
111 + 'custom' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_CUSTOM,
112 + 'unknown' => WPRProtectFW_V676::WP_USER_ROLE_LEVEL_UNKNOWN
111 113 );
112 114
113 115 const TABLE_NAME = "fw_requests";
114 116 const IP_COOKIE_NAME = "mcfw-ip-cookie";
@@ -169,8 +171,12 @@
169 171 if (array_key_exists('cookiedomain', $config) && is_string($config['cookiedomain'])) {
170 172 $this->cookie_domain = $config['cookiedomain'];
171 173 }
172 174
175 + if (array_key_exists('cookievalidity', $config) && is_int($config['cookievalidity'])) {
176 + $this->cookie_validity = $config['cookievalidity'];
177 + }
178 +
173 179 if (array_key_exists('cansetcachepreventioncookie', $config) &&
174 180 is_bool($config['cansetcachepreventioncookie'])) {
175 181
176 182 $this->can_set_cache_prevention_cookie = $config['cansetcachepreventioncookie'];
@@ -241,13 +247,13 @@
241 247 }
242 248
243 249 if ($this->isPrependMode()) {
244 250 $log_file = MCDATAPATH . MCCONFKEY . '-mc.log';
245 - $this->ipstore = new WPRProtectIpstore_V556(WPRProtectIpstore_V556::STORAGE_TYPE_FS);
246 - $this->logger = new WPRProtectLogger_V556($log_file, WPRProtectLogger_V556::TYPE_FS);
251 + $this->ipstore = new WPRProtectIpstore_V676(WPRProtectIpstore_V676::STORAGE_TYPE_FS);
252 + $this->logger = new WPRProtectLogger_V676($log_file, WPRProtectLogger_V676::TYPE_FS);
247 253 } else {
248 - $this->ipstore = new WPRProtectIpstore_V556(WPRProtectIpstore_V556::STORAGE_TYPE_DB);
249 - $this->logger = new WPRProtectLogger_V556(WPRProtectFW_V556::TABLE_NAME, WPRProtectLogger_V556::TYPE_DB);
254 + $this->ipstore = new WPRProtectIpstore_V676(WPRProtectIpstore_V676::STORAGE_TYPE_DB);
255 + $this->logger = new WPRProtectLogger_V676(WPRProtectFW_V676::TABLE_NAME, WPRProtectLogger_V676::TYPE_DB);
250 256 }
251 257
252 258 if ($this->is_wp_user_cookie_enabled) {
253 259 $this->loadWPUser();
@@ -258,12 +264,12 @@
258 264
259 265 public static function getInstance($protect_mode, $request, $config, $brand_name) {
260 266 if (!isset(self::$instance)) {
261 267 self::$instance = new self($protect_mode, $request, $config, $brand_name);
262 - } elseif (self::$instance->protect_mode != $protect_mode && $protect_mode == WPRProtect_V556::MODE_WP) {
268 + } elseif (self::$instance->protect_mode != $protect_mode && $protect_mode == WPRProtect_V676::MODE_WP) {
263 269 self::$instance->protect_mode = $protect_mode;
264 270 self::$instance->brand_name = $brand_name;
265 - self::$instance->ipstore = new WPRProtectIpstore_V556(WPRProtectIpstore_V556::STORAGE_TYPE_DB);
271 + self::$instance->ipstore = new WPRProtectIpstore_V676(WPRProtectIpstore_V676::STORAGE_TYPE_DB);
266 272 self::$instance->initRules();
267 273 }
268 274
269 275 return self::$instance;
@@ -269,9 +275,9 @@
269 275 return self::$instance;
270 276 }
271 277
272 278 public static function uninstall() {
273 - WPRProtect_V556::$db->dropBVTable(WPRProtectFW_V556::TABLE_NAME);
279 + WPRProtect_V676::$db->dropBVTable(WPRProtectFW_V676::TABLE_NAME);
274 280 }
275 281
276 282 public function init() {
277 283 if (!$this->isModeDisabled()) {
@@ -289,42 +295,42 @@
289 295 }
290 296 }
291 297
292 298 private function isPrependMode() {
293 - return ($this->protect_mode === WPRProtect_V556::MODE_PREPEND);
299 + return ($this->protect_mode === WPRProtect_V676::MODE_PREPEND);
294 300 }
295 301
296 302 private function isWPMode() {
297 - return ($this->protect_mode === WPRProtect_V556::MODE_WP);
303 + return ($this->protect_mode === WPRProtect_V676::MODE_WP);
298 304 }
299 305
300 306 private function isModeDisabled() {
301 - return ($this->mode === WPRProtectFW_V556::MODE_DISABLED);
307 + return ($this->mode === WPRProtectFW_V676::MODE_DISABLED);
302 308 }
303 309
304 310 private function isModeProtect() {
305 - return ($this->mode === WPRProtectFW_V556::MODE_PROTECT);
311 + return ($this->mode === WPRProtectFW_V676::MODE_PROTECT);
306 312 }
307 313
308 314 private function isAdminCookieEnabled() {
309 - return ($this->admin_cookie_mode === WPRProtectFW_V556::ADMIN_COOKIE_MODE_ENABLED);
315 + return ($this->admin_cookie_mode === WPRProtectFW_V676::ADMIN_COOKIE_MODE_ENABLED);
310 316 }
311 317
312 318 private function isIPCookieEnabled() {
313 - return ($this->ip_cookie_mode === WPRProtectFW_V556::IP_COOKIE_MODE_ENABLED);
319 + return ($this->ip_cookie_mode === WPRProtectFW_V676::IP_COOKIE_MODE_ENABLED);
314 320 }
315 321
316 322 private function isRequestProfilingDisabled() {
317 - return ($this->request_profiling_mode === WPRProtectFW_V556::REQ_PROFILING_MODE_DISABLED);
323 + return ($this->request_profiling_mode === WPRProtectFW_V676::REQ_PROFILING_MODE_DISABLED);
318 324 }
319 325
320 326 private function isRequestProfilingModeDebug() {
321 - return ($this->request_profiling_mode === WPRProtectFW_V556::REQ_PROFILING_MODE_DEBUG);
327 + return ($this->request_profiling_mode === WPRProtectFW_V676::REQ_PROFILING_MODE_DEBUG);
322 328 }
323 329
324 330 private function isRequestHasValidBypassCookie() {
325 331 if (!isset($this->has_valid_bypass_cookie)) {
326 - $cookie = (string) $this->request->getCookies(WPRProtectFW_V556::BYPASS_COOKIE_NAME);
332 + $cookie = (string) $this->request->getCookies(WPRProtectFW_V676::BYPASS_COOKIE_NAME);
327 333 $new_cookie = $this->generateBypassCookie();
328 334 $is_valid = ($this->isAdminCookieEnabled() && $new_cookie && ($cookie === $new_cookie));
329 335 $this->has_valid_bypass_cookie = $is_valid;
330 336 }
@@ -332,17 +338,17 @@
332 338 return $this->has_valid_bypass_cookie;
333 339 }
334 340
335 341 private function isRulesModeProtect() {
336 - return ($this->rules_mode === WPRProtectFW_V556::RULES_MODE_PROTECT);
342 + return ($this->rules_mode === WPRProtectFW_V676::RULES_MODE_PROTECT);
337 343 }
338 344
339 345 public function isLoggingModeComplete() {
340 - return ($this->logging_mode === WPRProtectFW_V556::LOGGING_MODE_COMPLETE);
346 + return ($this->logging_mode === WPRProtectFW_V676::LOGGING_MODE_COMPLETE);
341 347 }
342 348
343 349 public function isLoggingModeVisitor() {
344 - return ($this->logging_mode === WPRProtectFW_V556::LOGGING_MODE_VISITOR);
350 + return ($this->logging_mode === WPRProtectFW_V676::LOGGING_MODE_VISITOR);
345 351 }
346 352
347 353 public function isGeoBlockingEnabled() {
348 354 return ($this->is_geo_blocking === true);
@@ -348,13 +354,13 @@
348 354 return ($this->is_geo_blocking === true);
349 355 }
350 356
351 357 private function isWPFRuleInitModePrepend() {
352 - return ($this->wpf_rule_init_mode === WPRProtectFW_V556::WPF_RULE_INIT_MODE_PREPEND);
358 + return ($this->wpf_rule_init_mode === WPRProtectFW_V676::WPF_RULE_INIT_MODE_PREPEND);
353 359 }
354 360
355 361 private function isWPFRuleInitModeWP() {
356 - return ($this->wpf_rule_init_mode === WPRProtectFW_V556::WPF_RULE_INIT_MODE_WP);
362 + return ($this->wpf_rule_init_mode === WPRProtectFW_V676::WPF_RULE_INIT_MODE_WP);
357 363 }
358 364
359 365 private function canInitWPFRules() {
360 366 if (!$this->isWPFRuleInitModePrepend() && $this->isPrependMode()) {
@@ -364,9 +370,9 @@
364 370 return true;
365 371 }
366 372
367 373 private function generateBypassCookie() {
368 - $time = floor(time() / 43200);
374 + $time = floor(time() / $this->cookie_validity);
369 375
370 376 return hash('sha256', $this->bypass_level . $time . $this->cookie_key);
371 377 }
372 378
@@ -381,18 +387,18 @@
381 387 if (function_exists('is_user_logged_in') && is_user_logged_in()) {
382 388 $current_wp_user = $this->getCurrentWPUser();
383 389
384 390 if (!$current_wp_user->isIdentical($this->request->wp_user)) {
385 - $serialized_wp_user = WPRProtectWPUser_V556::_serialize($current_wp_user);
391 + $serialized_wp_user = WPRProtectWPUser_V676::_serialize($current_wp_user);
386 392 $cookie_val = $serialized_wp_user . '_' .
387 - WPRProtectUtils_V556::signMessage($serialized_wp_user, $this->cookie_key);
393 + WPRProtectUtils_V676::signMessage($serialized_wp_user, $this->cookie_key);
388 394 $cookie_val = base64_encode($cookie_val);
389 395
390 - $this->setcookie(WPRProtectWPUser_V556::COOKIE_NAME, $cookie_val, time() + 43200);
396 + $this->setCookie(WPRProtectWPUser_V676::COOKIE_NAME, $cookie_val);
391 397 }
392 398 } elseif ($this->request->wp_user->isLoggedIn()) {
393 - $this->request->wp_user = WPRProtectWPUser_V556::defaultUser();
394 - $this->unsetCookie(WPRProtectWPUser_V556::COOKIE_NAME);
399 + $this->request->wp_user = WPRProtectWPUser_V676::defaultUser();
400 + $this->unsetCookie(WPRProtectWPUser_V676::COOKIE_NAME);
395 401 }
396 402 }
397 403
398 404 private function getCurrentWPUser() {
@@ -398,9 +404,9 @@
398 404 private function getCurrentWPUser() {
399 405 $id = 0;
400 406 $role_level = 0;
401 407 $capabilities = array();
402 - $time = (int) floor(time() / 43200);
408 + $time = (int) floor(time() / $this->cookie_validity);
403 409
404 410 if (function_exists('wp_get_current_user')) {
405 411 $user = wp_get_current_user();
406 412 $id = $user->ID;
@@ -407,9 +413,9 @@
407 413 $role_level = $this->getCurrentWPUserRoleLevel();
408 414 $capabilities = $this->getCurrentWPUserCapabilities();
409 415 }
410 416
411 - return (new WPRProtectWPUser_V556($id, $role_level, $capabilities, $time));
417 + return (new WPRProtectWPUser_V676($id, $role_level, $capabilities, $time));
412 418 }
413 419
414 420 private function getCurrentWPUserCapabilities() {
415 421 $capabilities = array();
@@ -426,11 +432,11 @@
426 432 return $capabilities;
427 433 }
428 434
429 435 private function loadWPUser() {
430 - $this->request->wp_user = WPRProtectWPUser_V556::defaultUser();
436 + $this->request->wp_user = WPRProtectWPUser_V676::defaultUser();
431 437
432 - $cookie_val = $this->request->getCookies(WPRProtectWPUser_V556::COOKIE_NAME);
438 + $cookie_val = $this->request->getCookies(WPRProtectWPUser_V676::COOKIE_NAME);
433 439 if (!is_string($cookie_val)) {
434 440 return;
435 441 }
436 442
@@ -444,12 +450,12 @@
444 450 return;
445 451 }
446 452 list($serialized_user, $signature) = $cookie_val_array;
447 453
448 - if (WPRProtectUtils_V556::verifyMessage($serialized_user, $signature, $this->cookie_key) === true) {
449 - $wp_user = WPRProtectWPUser_V556::_unserialize($serialized_user);
454 + if (WPRProtectUtils_V676::verifyMessage($serialized_user, $signature, $this->cookie_key) === true) {
455 + $wp_user = WPRProtectWPUser_V676::_unserialize($serialized_user);
450 456
451 - if (!isset($wp_user) || $wp_user->time !== (int) floor(time() / 43200)) {
457 + if (!isset($wp_user) || $wp_user->time !== (int) floor(time() / $this->cookie_validity)) {
452 458 return;
453 459 }
454 460
455 461 $this->request->wp_user = $wp_user;
@@ -460,10 +466,10 @@
460 466 $this->request->wp_user->capability_names[] = $capability_names[$capability];
461 467 }
462 468 }
463 469
464 - $role_by_level = array_flip(array_merge(WPRProtectFW_V556::DEFAULT_WP_USER_ROLE_LEVELS,
465 - WPRProtectFW_V556::EXTRA_WP_USER_ROLE_LEVELS));
470 + $role_by_level = array_flip(array_merge(WPRProtectFW_V676::DEFAULT_WP_USER_ROLE_LEVELS,
471 + WPRProtectFW_V676::EXTRA_WP_USER_ROLE_LEVELS));
466 472 $this->request->wp_user->role = $role_by_level[$this->request->wp_user->role_level];
467 473 }
468 474 }
469 475
@@ -485,11 +491,11 @@
485 491 }
486 492
487 493 if ($this->isPrependMode()) {
488 494 $rules_file = MCDATAPATH . MCCONFKEY . '-' . 'mc_rules.json';
489 - $rule_arrays = WPRProtectUtils_V556::parseFile($rules_file);
495 + $rule_arrays = WPRProtectUtils_V676::parseFile($rules_file);
490 496 } else {
491 - $rule_arrays = WPRProtect_V556::$settings->getOption('bvruleset');
497 + $rule_arrays = WPRProtect_V676::$settings->getOption('bvruleset');
492 498 if(!is_array($rule_arrays)) {
493 499 $rule_arrays = array();
494 500 }
495 501 }
@@ -499,9 +505,9 @@
499 505 return;
500 506 }
501 507
502 508 foreach($rule_arrays as $rule_array) {
503 - $rule = WPRProtectFWRule_V556::init($rule_array);
509 + $rule = WPRProtectFWRule_V676::init($rule_array);
504 510
505 511 if ($rule) {
506 512 if (!$this->is_rule_initialized && $rule->isExeOnBoot()) {
507 513 if (!$this->isRequestHasValidBypassCookie()) {
@@ -523,40 +529,108 @@
523 529 $this->rules[] = $rule;
524 530 }
525 531
526 532 private function initWPFRule($rule) {
527 - if ($rule->isExeOnPreUpdateOption()) {
533 + switch ($rule->execute_on) {
534 + case WPRProtectFWRule_V676::EXE_ON_PRE_UPDATE_OPTION:
528 535 $this->addWPHook($rule, 'pre_update_option', 'handleRequestOnPreUpdateOption', 3);
529 - } elseif ($rule->isExeOnPreDeletePost()) {
536 + break;
537 + case WPRProtectFWRule_V676::EXE_ON_PRE_DELETE_POST:
530 538 $this->addWPHook($rule, 'pre_delete_post', 'handleRequestOnPreDeletePost', 3);
531 - } elseif ($rule->isExeOnWPInsertPostEmptyContent()) {
532 - $this->addWPHook($rule, 'wp_insert_post_empty_content', 'handleRequestOnWPInsertPostEmptyContent', 2);
533 - } elseif ($rule->isExeOnInsertUserMeta()) {
539 + break;
540 + case WPRProtectFWRule_V676::EXE_ON_WP_INSERT_POST_EMPTY_CONTENT:
541 + $this->addWPHook($rule, 'wp_insert_post_empty_content',
542 + 'handleRequestOnWPInsertPostEmptyContent', 2);
543 + break;
544 + case WPRProtectFWRule_V676::EXE_ON_INSERT_USER_META:
534 545 $this->addWPHook($rule, 'insert_user_meta', 'handleRequestOnInsertUserMeta', 4);
535 - } elseif ($rule->isExeOnDeleteOption()) {
546 + break;
547 + case WPRProtectFWRule_V676::EXE_ON_DELETE_OPTION:
536 548 $this->addWPHook($rule, 'delete_option', 'handleRequestOnDeleteOption', 1, 'action');
537 - } elseif ($rule->isExeOnDeleteUser()) {
549 + break;
550 + case WPRProtectFWRule_V676::EXE_ON_DELETE_USER:
538 551 $this->addWPHook($rule, 'delete_user', 'handleRequestOnDeleteUser', 3, 'action');
539 - } elseif ($rule->isExeOnPasswordReset()) {
552 + break;
553 + case WPRProtectFWRule_V676::EXE_ON_PASSWORD_RESET:
540 554 $this->addWPHook($rule, 'password_reset', 'handleRequestOnPasswordReset', 2, 'action');
541 - } elseif ($rule->isExeOnSendAuthCookies()) {
555 + break;
556 + case WPRProtectFWRule_V676::EXE_ON_SEND_AUTH_COOKIES:
542 557 $this->addWPHook($rule, 'send_auth_cookies', 'handleRequestOnSendAuthCookies', 6);
543 - } elseif ($rule->isExeOnSetAuthCookie()) {
558 + break;
559 + case WPRProtectFWRule_V676::EXE_ON_SET_AUTH_COOKIE:
544 560 $this->addWPHook($rule, 'set_auth_cookie', 'handleRequestOnSetAuthCookie', 6, 'action');
545 - } elseif ($rule->isExeOnInit()) {
561 + break;
562 + case WPRProtectFWRule_V676::EXE_ON_INIT:
546 563 $this->addWPHook($rule, 'init', 'handleRequestOnInit', 0, 'action');
547 - } elseif ($rule->isExeOnUserRegister()) {
564 + break;
565 + case WPRProtectFWRule_V676::EXE_ON_USER_REGISTER:
548 566 $this->addWPHook($rule, 'user_register', 'handleRequestOnUserRegister', 2, 'action');
549 - } elseif ($rule->isExeOnAddUserMeta()) {
567 + break;
568 + case WPRProtectFWRule_V676::EXE_ON_ADD_USER_META:
550 569 $this->addWPHook($rule, 'add_user_meta', 'handleRequestOnAddUserMeta', 3, 'action');
551 - } elseif ($rule->isExeOnUpdateUserMetadata()) {
570 + break;
571 + case WPRProtectFWRule_V676::EXE_ON_UPDATE_USER_METADATA:
552 572 $this->addWPHook($rule, 'update_user_metadata', 'handleRequestOnUpdateUserMetadata', 5);
553 - } elseif ($rule->isExeOnUpdateUserMeta()) {
573 + break;
574 + case WPRProtectFWRule_V676::EXE_ON_UPDATE_USER_META:
554 575 $this->addWPHook($rule, 'update_user_meta', 'handleRequestOnUpdateUserMeta', 4, 'action');
555 - } elseif ($rule->isExeOnAddOption()) {
576 + break;
577 + case WPRProtectFWRule_V676::EXE_ON_ADD_OPTION:
556 578 $this->addWPHook($rule, 'add_option', 'handleRequestOnAddOption', 2, 'action');
557 - } elseif ($rule->isExeOnWPPreInsertUserData()) {
579 + break;
580 + case WPRProtectFWRule_V676::EXE_ON_WP_PRE_INSERT_USER_DATA:
558 581 $this->addWPHook($rule, 'wp_pre_insert_user_data', 'handleRequestOnWPPreInsertUserData', 4);
582 + break;
583 + case WPRProtectFWRule_V676::EXE_ON_REST_REQUEST_BEFORE_CALLBACKS:
584 + $this->addWPHook($rule, 'rest_request_before_callbacks',
585 + 'handleRequestOnRestRequestBeforeCallbacks', 3);
586 + break;
587 + case WPRProtectFWRule_V676::EXE_ON_ADMIN_INIT:
588 + $this->addWPHook($rule, 'admin_init', 'handleRequestOnAdminInit', 0, 'action');
589 + break;
590 + case WPRProtectFWRule_V676::EXE_ON_WP_HANDLE_UPLOAD_PREFILTER:
591 + $this->addWPHook($rule, 'wp_handle_upload_prefilter',
592 + 'handleRequestOnWPHandleUploadPrefilter', 1);
593 + break;
594 + case WPRProtectFWRule_V676::EXE_ON_TEMPLATE_REDIRECT:
595 + $this->addWPHook($rule, 'template_redirect', 'handleRequestOnTemplateRedirect', 0, 'action');
596 + break;
597 + case WPRProtectFWRule_V676::EXE_ON_WP_LOADED:
598 + $this->addWPHook($rule, 'wp_loaded', 'handleRequestOnWPLoaded', 0, 'action');
599 + break;
600 + case WPRProtectFWRule_V676::EXE_ON_ADD_POST_METADATA:
601 + $this->addWPHook($rule, 'add_post_metadata', 'handleRequestOnAddPostMetadata', 5);
602 + break;
603 + case WPRProtectFWRule_V676::EXE_ON_UPDATE_POST_METADATA:
604 + $this->addWPHook($rule, 'update_post_metadata', 'handleRequestOnUpdatePostMetadata', 5);
605 + break;
606 + case WPRProtectFWRule_V676::EXE_ON_DELETE_POST_METADATA:
607 + $this->addWPHook($rule, 'delete_post_metadata', 'handleRequestOnDeletePostMetadata', 5);
608 + break;
609 + case WPRProtectFWRule_V676::EXE_ON_ADD_TERM_METADATA:
610 + $this->addWPHook($rule, 'add_term_metadata', 'handleRequestOnAddTermMetadata', 5);
611 + break;
612 + case WPRProtectFWRule_V676::EXE_ON_UPDATE_TERM_METADATA:
613 + $this->addWPHook($rule, 'update_term_metadata', 'handleRequestOnUpdateTermMetadata', 5);
614 + break;
615 + case WPRProtectFWRule_V676::EXE_ON_DELETE_TERM_METADATA:
616 + $this->addWPHook($rule, 'delete_term_metadata', 'handleRequestOnDeleteTermMetadata', 5);
617 + break;
618 + case WPRProtectFWRule_V676::EXE_ON_ADD_COMMENT_METADATA:
619 + $this->addWPHook($rule, 'add_comment_metadata', 'handleRequestOnAddCommentMetadata', 5);
620 + break;
621 + case WPRProtectFWRule_V676::EXE_ON_UPDATE_COMMENT_METADATA:
622 + $this->addWPHook($rule, 'update_comment_metadata', 'handleRequestOnUpdateCommentMetadata', 5);
623 + break;
624 + case WPRProtectFWRule_V676::EXE_ON_DELETE_COMMENT_METADATA:
625 + $this->addWPHook($rule, 'delete_comment_metadata', 'handleRequestOnDeleteCommentMetadata', 5);
626 + break;
627 + case WPRProtectFWRule_V676::EXE_ON_ADD_USER_METADATA:
628 + $this->addWPHook($rule, 'add_user_metadata', 'handleRequestOnAddUserMetadata', 5);
629 + break;
630 + case WPRProtectFWRule_V676::EXE_ON_DELETE_USER_METADATA:
631 + $this->addWPHook($rule, 'delete_user_metadata', 'handleRequestOnDeleteUserMetadata', 5);
632 + break;
559 633 }
560 634 }
561 635
562 636 private function addWPHook($rule, $hook_name, $function_name, $accepted_args, $hook_type = 'filter') {
@@ -570,9 +644,9 @@
570 644 } else {
571 645 add_filter($hook_name, $callback, -9999999, $accepted_args);
572 646 }
573 647 } else {
574 - WPRProtectUtils_V556::preInitWPHook($hook_name, $callback, -9999999, $accepted_args);
648 + WPRProtectUtils_V676::preInitWPHook($hook_name, $callback, -9999999, $accepted_args);
575 649 }
576 650 }
577 651
578 652 $this->pushWPFRule($function_name, $rule);
@@ -895,8 +969,199 @@
895 969 $this->handleRequestOnRuleMatch($rules, $variables, $log_data);
896 970 }
897 971 }
898 972
973 + private function handleRequestOnLifecycleHook($function_name, $hook_name) {
974 + $rules = $this->getWPFRules($function_name);
975 +
976 + if (!empty($rules)) {
977 + $variables = $this->getLifecycleHookVariables($hook_name);
978 + $this->handleRequestOnRuleMatch($rules, $variables, $variables);
979 + }
980 + }
981 +
982 + private function getLifecycleHookVariables($hook_name) {
983 + $variables = array('hook' => $hook_name);
984 +
985 + if (function_exists('is_admin')) {
986 + $variables['is_admin'] = is_admin();
987 + }
988 +
989 + if (function_exists('wp_doing_ajax')) {
990 + $variables['is_ajax'] = wp_doing_ajax();
991 + } else {
992 + $variables['is_ajax'] = (defined('DOING_AJAX') && DOING_AJAX);
993 + }
994 +
995 + $variables['is_cron'] = (defined('DOING_CRON') && DOING_CRON);
996 + $variables['is_rest_request'] = (defined('REST_REQUEST') && REST_REQUEST);
997 +
998 + return $variables;
999 + }
1000 +
1001 + public function handleRequestOnAdminInit() {
1002 + $this->handleRequestOnLifecycleHook('handleRequestOnAdminInit', 'admin_init');
1003 + }
1004 +
1005 + public function handleRequestOnTemplateRedirect() {
1006 + $this->handleRequestOnLifecycleHook('handleRequestOnTemplateRedirect', 'template_redirect');
1007 + }
1008 +
1009 + public function handleRequestOnWPLoaded() {
1010 + $this->handleRequestOnLifecycleHook('handleRequestOnWPLoaded', 'wp_loaded');
1011 + }
1012 +
1013 + public function handleRequestOnRestRequestBeforeCallbacks($response, $handler, $request) {
1014 + $rules = $this->getWPFRules('handleRequestOnRestRequestBeforeCallbacks');
1015 +
1016 + if (!empty($rules)) {
1017 + $this->handleRequestOnRuleMatch($rules);
1018 + }
1019 +
1020 + return $response;
1021 + }
1022 +
1023 + private function getSafeUploadFileData($file) {
1024 + $data = array();
1025 +
1026 + if (!is_array($file)) {
1027 + return $data;
1028 + }
1029 +
1030 + foreach (array('name', 'type', 'size', 'error') as $key) {
1031 + if (array_key_exists($key, $file) && (is_scalar($file[$key]) || is_null($file[$key]))) {
1032 + $data[$key] = $file[$key];
1033 + }
1034 + }
1035 +
1036 + if (array_key_exists('name', $data) && is_string($data['name'])) {
1037 + $data['extension'] = strtolower(pathinfo($data['name'], PATHINFO_EXTENSION));
1038 + }
1039 +
1040 + return $data;
1041 + }
1042 +
1043 + private function getMetadataValueLogData($key, $value) {
1044 + $data = array(
1045 + $key . '_type' => gettype($value),
1046 + $key . '_size' => null
1047 + );
1048 +
1049 + if (is_null($value)) {
1050 + $data[$key . '_size'] = 0;
1051 + } elseif (is_scalar($value)) {
1052 + $data[$key . '_size'] = strlen((string) $value);
1053 + } elseif (is_array($value)) {
1054 + $data[$key . '_count'] = count($value);
1055 + } elseif (is_object($value)) {
1056 + $data[$key . '_count'] = count(get_object_vars($value));
1057 + }
1058 +
1059 + return $data;
1060 + }
1061 +
1062 + public function handleRequestOnWPHandleUploadPrefilter($file) {
1063 + $rules = $this->getWPFRules('handleRequestOnWPHandleUploadPrefilter');
1064 +
1065 + if (!empty($rules)) {
1066 + $safe_file = $this->getSafeUploadFileData($file);
1067 + $variables = array('file' => $safe_file);
1068 + $this->handleRequestOnRuleMatch($rules, $variables, $variables);
1069 + }
1070 +
1071 + return $file;
1072 + }
1073 +
1074 + private function handleRequestOnMetadataFilter($function_name, $meta_type, $operation, $check,
1075 + $object_id, $meta_key, $meta_value, $extra = array()) {
1076 +
1077 + $rules = $this->getWPFRules($function_name);
1078 +
1079 + if (!empty($rules)) {
1080 + $variables = array_merge(array(
1081 + 'check' => $check,
1082 + 'meta_type' => $meta_type,
1083 + 'operation' => $operation,
1084 + 'object_id' => $object_id,
1085 + 'meta_key' => $meta_key,
1086 + 'meta_value' => $meta_value
1087 + ), $extra);
1088 +
1089 + $log_extra = $extra;
1090 + if (array_key_exists('prev_value', $log_extra)) {
1091 + $prev_value = $log_extra['prev_value'];
1092 + unset($log_extra['prev_value']);
1093 + $log_extra = array_merge($log_extra, $this->getMetadataValueLogData('prev_value', $prev_value));
1094 + }
1095 +
1096 + $log_data = array_merge(array(
1097 + 'meta_type' => $meta_type,
1098 + 'operation' => $operation,
1099 + 'object_id' => $object_id,
1100 + 'meta_key' => $meta_key
1101 + ), $this->getMetadataValueLogData('meta_value', $meta_value), $log_extra);
1102 +
1103 + $this->handleRequestOnRuleMatch($rules, $variables, $log_data);
1104 + }
1105 +
1106 + return $check;
1107 + }
1108 +
1109 + public function handleRequestOnAddPostMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1110 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddPostMetadata',
1111 + 'post', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1112 + }
1113 +
1114 + public function handleRequestOnUpdatePostMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1115 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdatePostMetadata',
1116 + 'post', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1117 + }
1118 +
1119 + public function handleRequestOnDeletePostMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1120 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeletePostMetadata',
1121 + 'post', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1122 + }
1123 +
1124 + public function handleRequestOnAddTermMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1125 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddTermMetadata',
1126 + 'term', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1127 + }
1128 +
1129 + public function handleRequestOnUpdateTermMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1130 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdateTermMetadata',
1131 + 'term', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1132 + }
1133 +
1134 + public function handleRequestOnDeleteTermMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1135 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteTermMetadata',
1136 + 'term', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1137 + }
1138 +
1139 + public function handleRequestOnAddCommentMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1140 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddCommentMetadata',
1141 + 'comment', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1142 + }
1143 +
1144 + public function handleRequestOnUpdateCommentMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1145 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdateCommentMetadata',
1146 + 'comment', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1147 + }
1148 +
1149 + public function handleRequestOnDeleteCommentMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1150 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteCommentMetadata',
1151 + 'comment', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1152 + }
1153 +
1154 + public function handleRequestOnAddUserMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1155 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddUserMetadata',
1156 + 'user', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1157 + }
1158 +
1159 + public function handleRequestOnDeleteUserMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1160 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteUserMetadata',
1161 + 'user', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1162 + }
1163 +
899 1164 private function setShutdownCallback() {
900 1165 if (!$this->is_shutdown_cb_set) {
901 1166 register_shutdown_function(array($this, 'log'));
902 1167 $this->is_shutdown_cb_set = true;
@@ -902,9 +1167,13 @@
902 1167 $this->is_shutdown_cb_set = true;
903 1168 }
904 1169 }
905 1170
906 - private function setCookie($name, $value, $expire) {
1171 + private function setCookie($name, $value, $expire = null) {
1172 + if ($expire === null) {
1173 + $expire = time() + $this->cookie_validity;
1174 + }
1175 +
907 1176 $path = $this->cookie_path;
908 1177 $cookie_domain = $this->cookie_domain;
909 1178
910 1179 if (version_compare(PHP_VERSION, '5.2.0') >= 0) {
@@ -933,14 +1202,14 @@
933 1202 }
934 1203
935 1204 private function setIPCookie() {
936 1205 if (!$this->is_ip_cookie_set && $this->isIPCookieEnabled() &&
937 - !$this->request->getCookies(WPRProtectFW_V556::IP_COOKIE_NAME)) {
1206 + !$this->request->getCookies(WPRProtectFW_V676::IP_COOKIE_NAME)) {
938 1207
939 1208 $time = floor(time() / 86400);
940 1209 $cookie = hash('sha256', $this->request->ip . $time . $this->cookie_key);
941 1210 if ($cookie) {
942 - $this->setCookie(WPRProtectFW_V556::IP_COOKIE_NAME, $cookie, time() + 86400);
1211 + $this->setCookie(WPRProtectFW_V676::IP_COOKIE_NAME, $cookie, time() + 86400);
943 1212 }
944 1213 }
945 1214 }
946 1215
@@ -946,18 +1215,18 @@
946 1215
947 1216 private function getCurrentWPUserRoleLevel() {
948 1217 if (function_exists('current_user_can')) {
949 1218 if (function_exists('is_super_admin') && is_super_admin()) {
950 - return WPRProtectFW_V556::WP_USER_ROLE_LEVEL_ADMIN;
1219 + return WPRProtectFW_V676::WP_USER_ROLE_LEVEL_ADMIN;
951 1220 }
952 1221
953 1222 foreach ($this->custom_roles as $role) {
954 1223 if (current_user_can($role)) {
955 - return WPRProtectFW_V556::WP_USER_ROLE_LEVEL_CUSTOM;
1224 + return WPRProtectFW_V676::WP_USER_ROLE_LEVEL_CUSTOM;
956 1225 }
957 1226 }
958 1227
959 - foreach (WPRProtectFW_V556::DEFAULT_WP_USER_ROLE_LEVELS as $role => $level) {
1228 + foreach (WPRProtectFW_V676::DEFAULT_WP_USER_ROLE_LEVELS as $role => $level) {
960 1229 if (current_user_can($role)) {
961 1230 return $level;
962 1231 }
963 1232 }
@@ -1063,11 +1332,11 @@
1063 1332
1064 1333 private function getBVCookies() {
1065 1334 $cookies = array();
1066 1335
1067 - if ($this->request->getCookies(WPRProtectFW_V556::IP_COOKIE_NAME) !== NULL) {
1068 - $cookie_val = (string) $this->request->getCookies(WPRProtectFW_V556::IP_COOKIE_NAME);
1069 - $cookies[WPRProtectFW_V556::IP_COOKIE_NAME] = $cookie_val;
1336 + if ($this->request->getCookies(WPRProtectFW_V676::IP_COOKIE_NAME) !== NULL) {
1337 + $cookie_val = (string) $this->request->getCookies(WPRProtectFW_V676::IP_COOKIE_NAME);
1338 + $cookies[WPRProtectFW_V676::IP_COOKIE_NAME] = $cookie_val;
1070 1339 }
1071 1340
1072 1341 return $cookies;
1073 1342 }
@@ -1219,13 +1488,19 @@
1219 1488 $this->updateRuleLog('inspect', "cookies", $this->getCookiesToLog($this->request->getCookies()));
1220 1489 $this->updateRuleLog('inspect', "getParams", $this->request->getGetParams());
1221 1490 $this->updateRuleLog('inspect', "postParams", $this->getParamsToLog($this->request->getPostParams(), "POST"));
1222 1491 $this->updateRuleLog('inspect', "jsonParams", $this->getParamsToLog($this->request->getJsonParams(), "JSON"));
1223 - $this->updateRuleLog('inspect', "rawBody", $this->getRawBodyToLog($this->request->getRawBody()));
1492 + $this->updateRuleLog('inspect', "bodyParserStatus", $this->request->getBodyParserStatus());
1493 + if ($this->can_log_raw_body) {
1494 + $raw_body = $this->request->getRawBody();
1495 + if (!empty($raw_body)) {
1496 + $this->updateRuleLog('inspect', "rawBody", $this->getRawBodyToLog($raw_body));
1497 + }
1498 + }
1224 1499 }
1225 1500
1226 1501 private function getUserBy($attribute, $value) {
1227 - if (isset($value) && function_exists('get_user_by') && WPRProtectUtils_V556::havePluginsLoaded()) {
1502 + if (isset($value) && function_exists('get_user_by') && WPRProtectUtils_V676::havePluginsLoaded()) {
1228 1503 return get_user_by($attribute, $value);
1229 1504 }
1230 1505 }
1231 1506
@@ -1327,9 +1602,9 @@
1327 1602 xlsx|psd|mp3|m4a|ogg|wav|mp4|m4v|mov|wmv|avi|mpg|ogv|3gp|3g2|php|html|phtml|js|css)/ix', $value)) {
1328 1603 $profiled_data[$key]["file"] = true;
1329 1604 }
1330 1605
1331 - if ($this->matchCount(WPRProtectFWRule_V556::SQLIREGEX, $value) > 2) {
1606 + if ($this->matchCount(WPRProtectFWRule_V676::SQLIREGEX, $value) > 2) {
1332 1607 $profiled_data[$key]["sql"] = true;
1333 1608 }
1334 1609
1335 1610 if (WPRHelper::safePregMatch('/(?:\.{2}[\/]+)/', $value)) {
@@ -1395,8 +1670,14 @@
1395 1670 if ($this->can_log_raw_body && $is_debug_mode && $log_raw_body && !empty($this->request->getRawBody())) {
1396 1671 $profiled_data += array("RAW_BODY" => $this->getRawBodyToLog($this->request->getRawBody()));
1397 1672 }
1398 1673
1674 + $body_parser_status = $this->request->getBodyParserStatus();
1675 + $profiled_data = array(
1676 + "BODY_RAW_STATUS" => $body_parser_status['raw_body_status'],
1677 + "JSON_PARAMS_STATUS" => $body_parser_status['json_params_status']
1678 + ) + $profiled_data;
1679 +
1399 1680 $this->request_profiled_data = $profiled_data;
1400 1681 $this->is_request_profiled = true;
1401 1682 }
1402 1683 }
@@ -1401,20 +1682,24 @@
1401 1682 }
1402 1683 }
1403 1684
1404 1685 private function isRequestIPWhitelisted() {
1405 - return $this->ipstore->isFWIPWhitelisted($this->request->ip);
1686 + if (!isset($this->is_ip_whitelisted)) {
1687 + $this->is_ip_whitelisted = $this->ipstore->isFWIPWhitelisted($this->request->ip);
1688 + }
1689 +
1690 + return $this->is_ip_whitelisted;
1406 1691 }
1407 1692
1408 1693 private function canRequestBypassFirewall() {
1409 1694 if ($this->isRequestIPWhitelisted() || $this->isRequestHasValidBypassCookie()) {
1410 - $this->request->category = WPRProtectRequest_V556::CATEGORY_WHITELISTED;
1411 - $this->request->status = WPRProtectRequest_V556::STATUS_BYPASSED;
1695 + $this->request->category = WPRProtectRequest_V676::CATEGORY_WHITELISTED;
1696 + $this->request->status = WPRProtectRequest_V676::STATUS_BYPASSED;
1412 1697
1413 1698 return true;
1414 - } elseif (WPRProtectUtils_V556::isPrivateIP($this->request->ip)) {
1415 - $this->request->category = WPRProtectRequest_V556::CATEGORY_PRIVATEIP;
1416 - $this->request->status = WPRProtectRequest_V556::STATUS_BYPASSED;
1699 + } elseif (WPRProtectUtils_V676::isPrivateIP($this->request->ip)) {
1700 + $this->request->category = WPRProtectRequest_V676::CATEGORY_PRIVATEIP;
1701 + $this->request->status = WPRProtectRequest_V676::STATUS_BYPASSED;
1417 1702
1418 1703 return true;
1419 1704 }
1420 1705
@@ -1436,19 +1721,22 @@
1436 1721 }
1437 1722 }
1438 1723
1439 1724 private function handleRequestOnRuleMatch($rules, $engine_vars = array(), $log_data = array()) {
1725 + $normalized_engine_vars = WPRProtectFWRuleEngine_V676::normalizeVariables($engine_vars);
1726 +
1440 1727 foreach ($rules as $rule) {
1441 1728 if ($this->break_rule_matching) {
1442 1729 break;
1443 1730 }
1444 1731
1445 - $_engine_vars = $engine_vars;
1732 + $_engine_vars = $normalized_engine_vars;
1446 1733 if (array_key_exists('variables', $rule->opts)) {
1447 - $_engine_vars = array_merge($_engine_vars, $rule->opts['variables']);
1734 + $_engine_vars = array_merge($_engine_vars,
1735 + WPRProtectFWRuleEngine_V676::normalizeVariables($rule->opts['variables']));
1448 1736 }
1449 1737
1450 - $rule_engine = new WPRProtectFWRuleEngine_V556($this->request, $_engine_vars);
1738 + $rule_engine = new WPRProtectFWRuleEngine_V676($this->request, $_engine_vars);
1451 1739
1452 1740 if ($rule_engine->evaluate($rule) && !$rule_engine->hasError()) {
1453 1741 if (!empty($log_data)) {
1454 1742 $this->updateRuleLog("info", (string) $rule->id, $log_data);
@@ -1459,13 +1747,13 @@
1459 1747 foreach($rule->actions as $action) {
1460 1748 switch ($action["type"]) {
1461 1749 case "ALLOW":
1462 1750 $this->break_rule_matching = true;
1463 - $this->request->category = WPRProtectRequest_V556::CATEGORY_RULE_ALLOWED;
1751 + $this->request->category = WPRProtectRequest_V676::CATEGORY_RULE_ALLOWED;
1464 1752 return;
1465 1753 case "BLOCK":
1466 1754 if ($this->isModeProtect()) {
1467 - $this->terminateRequest(WPRProtectRequest_V556::CATEGORY_RULE_BLOCKED);
1755 + $this->terminateRequest(WPRProtectRequest_V676::CATEGORY_RULE_BLOCKED);
1468 1756 }
1469 1757 return;
1470 1758 case "INSPECT":
1471 1759 $this->inspectRequest();
@@ -1479,15 +1767,15 @@
1479 1767 }
1480 1768
1481 1769 private function terminateRequest($category) {
1482 1770 $this->request->category = $category;
1483 - $this->request->status = WPRProtectRequest_V556::STATUS_BLOCKED;
1771 + $this->request->status = WPRProtectRequest_V676::STATUS_BLOCKED;
1484 1772 $this->request->setRespCode(403);
1485 1773
1486 1774 if ($this->can_set_cache_prevention_cookie &&
1487 - !$this->request->getCookies(WPRProtectFW_V556::PREVENT_CACHE_COOKIE_NAME)) {
1775 + !$this->request->getCookies(WPRProtectFW_V676::PREVENT_CACHE_COOKIE_NAME)) {
1488 1776 $value = "Prevent Caching Response.";
1489 - $this->setCookie(WPRProtectFW_V556::PREVENT_CACHE_COOKIE_NAME, $value, time() + 43200);
1777 + $this->setCookie(WPRProtectFW_V676::PREVENT_CACHE_COOKIE_NAME, $value, time() + 43200);
1490 1778 }
1491 1779
1492 1780 header("Cache-Control: no-cache, no-store, must-revalidate");
1493 1781 header("Pragma: no-cache");
@@ -1492,8 +1780,9 @@
1492 1780 header("Cache-Control: no-cache, no-store, must-revalidate");
1493 1781 header("Pragma: no-cache");
1494 1782 header("Expires: 0");
1495 1783 header('HTTP/1.0 403 Forbidden');
1784 + // phpcs:disable WordPress.Security.EscapeOutput.OutputNotEscaped
1496 1785 die("
1497 1786 <div style='height: 98vh;'>
1498 1787 <div style='text-align: center; padding: 10% 0; font-family: Arial, Helvetica, sans-serif;'>
1499 1788 <div><p>" . $this->brand_name . " Firewall</p></div>
@@ -1501,8 +1790,9 @@
1501 1790 <p>Reference ID: " . $this->request->getRequestID() . "</p>
1502 1791 </div>
1503 1792 </div>
1504 1793 ");
1794 + // phpcs:enable WordPress.Security.EscapeOutput.OutputNotEscaped
1505 1795 }
1506 1796
1507 1797 public function setBypassCookie() {
1508 1798 if (function_exists('is_user_logged_in') && is_user_logged_in() &&
@@ -1511,11 +1801,11 @@
1511 1801 $role_level = $this->getCurrentWPUserRoleLevel();
1512 1802 if ($role_level >= $this->bypass_level) {
1513 1803 $cookie = $this->generateBypassCookie();
1514 1804 if ($cookie) {
1515 - $this->setCookie(WPRProtectFW_V556::BYPASS_COOKIE_NAME, $cookie, time() + 43200);
1805 + $this->setCookie(WPRProtectFW_V676::BYPASS_COOKIE_NAME, $cookie);
1516 1806 }
1517 1807 }
1518 1808 }
1519 1809 }
1520 1810 }
1521 -endif;
1811 +endif;