PluginProbe
The WP Remote WordPress Plugin / trunk
The WP Remote WordPress Plugin vtrunk
6.72 6.69 6.65 6.62 6.48 6.47 4.87 4.97 5.05 5.09 5.16 5.22 5.24 5.25 5.38 5.41 5.42 5.45 5.47 5.53 5.56 5.65 5.68 5.72 5.73 All 53 releases
← All changes | protect/fw.php +371 -97 6.48trunk View file →
@@ -1,13 +1,13 @@
1 1 <?php
2 2 if (!defined('ABSPATH') && !defined('MCDATAPATH')) exit;
3 3
4 -if (!class_exists('WPRProtectFW_V648')) :
4 +if (!class_exists('WPRProtectFW_V672')) :
5 5 require_once dirname( __FILE__ ) . '/fw/rule/errors.php';
6 6 require_once dirname( __FILE__ ) . '/fw/rule/engine.php';
7 7 require_once dirname( __FILE__ ) . '/fw/rule.php';
8 8
9 -class WPRProtectFW_V648 {
9 +class WPRProtectFW_V672 {
10 10 private $brand_name;
11 11 private $protect_mode;
12 12 private $request;
13 13 private $ipstore;
@@ -22,13 +22,13 @@
22 22 private $is_ip_checked_for_blacklisted = false;
23 23 private $is_ip_whitelisted = null;
24 24 private $has_valid_bypass_cookie;
25 25
26 - private $mode = WPRProtectFW_V648::MODE_DISABLED;
27 - private $ip_cookie_mode = WPRProtectFW_V648::IP_COOKIE_MODE_DISABLED;
28 - private $admin_cookie_mode = WPRProtectFW_V648::ADMIN_COOKIE_MODE_DISABLED;
29 - private $bypass_level = WPRProtectFW_V648::WP_USER_ROLE_LEVEL_CONTRIBUTOR;
30 - private $wpf_rule_init_mode = WPRProtectFW_V648::WPF_RULE_INIT_MODE_WP;
26 + private $mode = WPRProtectFW_V672::MODE_DISABLED;
27 + private $ip_cookie_mode = WPRProtectFW_V672::IP_COOKIE_MODE_DISABLED;
28 + private $admin_cookie_mode = WPRProtectFW_V672::ADMIN_COOKIE_MODE_DISABLED;
29 + private $bypass_level = WPRProtectFW_V672::WP_USER_ROLE_LEVEL_CONTRIBUTOR;
30 + private $wpf_rule_init_mode = WPRProtectFW_V672::WPF_RULE_INIT_MODE_WP;
31 31 private $custom_roles = array();
32 32 private $cookie_key = "";
33 33 private $cookie_path = "";
34 34 private $cookie_domain = "";
@@ -33,14 +33,14 @@
33 33 private $cookie_path = "";
34 34 private $cookie_domain = "";
35 35 private $cookie_validity = 2592000;
36 36 private $can_set_cache_prevention_cookie = false;
37 - private $rules_mode = WPRProtectFW_V648::RULES_MODE_DISABLED;
37 + private $rules_mode = WPRProtectFW_V672::RULES_MODE_DISABLED;
38 38 private $is_geo_blocking = false;
39 39 private $is_wp_user_cookie_enabled = false;
40 40 private $log_config = array();
41 - private $request_profiling_mode = WPRProtectFW_V648::REQ_PROFILING_MODE_DISABLED;
42 - private $logging_mode = WPRProtectFW_V648::LOGGING_MODE_VISITOR;
41 + private $request_profiling_mode = WPRProtectFW_V672::REQ_PROFILING_MODE_DISABLED;
42 + private $logging_mode = WPRProtectFW_V672::LOGGING_MODE_VISITOR;
43 43 private $skip_log_config = array();
44 44 private $skip_log_cookies = array();
45 45 private $skip_log_headers = array();
46 46 private $skip_log_post_params = array();
@@ -53,9 +53,9 @@
53 53 private $rule_log = array();
54 54 private $matched_rules = array();
55 55 private $break_rule_matching = false;
56 56 private $can_log_raw_body = false;
57 - private $log_slice_size = WPRProtectFW_V648::LOG_SLICE_SIZE;
57 + private $log_slice_size = WPRProtectFW_V672::LOG_SLICE_SIZE;
58 58
59 59 private static $instance = null;
60 60
61 61 const MODE_DISABLED = 1;
@@ -99,18 +99,18 @@
99 99 const LOGGING_MODE_COMPLETE = 2;
100 100 const LOGGING_MODE_DISABLED = 3;
101 101
102 102 const DEFAULT_WP_USER_ROLE_LEVELS = array(
103 - 'administrator' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_ADMIN,
104 - 'editor' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_EDITOR,
105 - 'author' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_AUTHOR,
106 - 'contributor' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_CONTRIBUTOR,
107 - 'subscriber' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_SUBSCRIBER
103 + 'administrator' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_ADMIN,
104 + 'editor' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_EDITOR,
105 + 'author' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_AUTHOR,
106 + 'contributor' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_CONTRIBUTOR,
107 + 'subscriber' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_SUBSCRIBER
108 108 );
109 109
110 110 const EXTRA_WP_USER_ROLE_LEVELS = array(
111 - 'custom' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_CUSTOM,
112 - 'unknown' => WPRProtectFW_V648::WP_USER_ROLE_LEVEL_UNKNOWN
111 + 'custom' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_CUSTOM,
112 + 'unknown' => WPRProtectFW_V672::WP_USER_ROLE_LEVEL_UNKNOWN
113 113 );
114 114
115 115 const TABLE_NAME = "fw_requests";
116 116 const IP_COOKIE_NAME = "mcfw-ip-cookie";
@@ -247,13 +247,13 @@
247 247 }
248 248
249 249 if ($this->isPrependMode()) {
250 250 $log_file = MCDATAPATH . MCCONFKEY . '-mc.log';
251 - $this->ipstore = new WPRProtectIpstore_V648(WPRProtectIpstore_V648::STORAGE_TYPE_FS);
252 - $this->logger = new WPRProtectLogger_V648($log_file, WPRProtectLogger_V648::TYPE_FS);
251 + $this->ipstore = new WPRProtectIpstore_V672(WPRProtectIpstore_V672::STORAGE_TYPE_FS);
252 + $this->logger = new WPRProtectLogger_V672($log_file, WPRProtectLogger_V672::TYPE_FS);
253 253 } else {
254 - $this->ipstore = new WPRProtectIpstore_V648(WPRProtectIpstore_V648::STORAGE_TYPE_DB);
255 - $this->logger = new WPRProtectLogger_V648(WPRProtectFW_V648::TABLE_NAME, WPRProtectLogger_V648::TYPE_DB);
254 + $this->ipstore = new WPRProtectIpstore_V672(WPRProtectIpstore_V672::STORAGE_TYPE_DB);
255 + $this->logger = new WPRProtectLogger_V672(WPRProtectFW_V672::TABLE_NAME, WPRProtectLogger_V672::TYPE_DB);
256 256 }
257 257
258 258 if ($this->is_wp_user_cookie_enabled) {
259 259 $this->loadWPUser();
@@ -264,12 +264,12 @@
264 264
265 265 public static function getInstance($protect_mode, $request, $config, $brand_name) {
266 266 if (!isset(self::$instance)) {
267 267 self::$instance = new self($protect_mode, $request, $config, $brand_name);
268 - } elseif (self::$instance->protect_mode != $protect_mode && $protect_mode == WPRProtect_V648::MODE_WP) {
268 + } elseif (self::$instance->protect_mode != $protect_mode && $protect_mode == WPRProtect_V672::MODE_WP) {
269 269 self::$instance->protect_mode = $protect_mode;
270 270 self::$instance->brand_name = $brand_name;
271 - self::$instance->ipstore = new WPRProtectIpstore_V648(WPRProtectIpstore_V648::STORAGE_TYPE_DB);
271 + self::$instance->ipstore = new WPRProtectIpstore_V672(WPRProtectIpstore_V672::STORAGE_TYPE_DB);
272 272 self::$instance->initRules();
273 273 }
274 274
275 275 return self::$instance;
@@ -275,9 +275,9 @@
275 275 return self::$instance;
276 276 }
277 277
278 278 public static function uninstall() {
279 - WPRProtect_V648::$db->dropBVTable(WPRProtectFW_V648::TABLE_NAME);
279 + WPRProtect_V672::$db->dropBVTable(WPRProtectFW_V672::TABLE_NAME);
280 280 }
281 281
282 282 public function init() {
283 283 if (!$this->isModeDisabled()) {
@@ -295,42 +295,42 @@
295 295 }
296 296 }
297 297
298 298 private function isPrependMode() {
299 - return ($this->protect_mode === WPRProtect_V648::MODE_PREPEND);
299 + return ($this->protect_mode === WPRProtect_V672::MODE_PREPEND);
300 300 }
301 301
302 302 private function isWPMode() {
303 - return ($this->protect_mode === WPRProtect_V648::MODE_WP);
303 + return ($this->protect_mode === WPRProtect_V672::MODE_WP);
304 304 }
305 305
306 306 private function isModeDisabled() {
307 - return ($this->mode === WPRProtectFW_V648::MODE_DISABLED);
307 + return ($this->mode === WPRProtectFW_V672::MODE_DISABLED);
308 308 }
309 309
310 310 private function isModeProtect() {
311 - return ($this->mode === WPRProtectFW_V648::MODE_PROTECT);
311 + return ($this->mode === WPRProtectFW_V672::MODE_PROTECT);
312 312 }
313 313
314 314 private function isAdminCookieEnabled() {
315 - return ($this->admin_cookie_mode === WPRProtectFW_V648::ADMIN_COOKIE_MODE_ENABLED);
315 + return ($this->admin_cookie_mode === WPRProtectFW_V672::ADMIN_COOKIE_MODE_ENABLED);
316 316 }
317 317
318 318 private function isIPCookieEnabled() {
319 - return ($this->ip_cookie_mode === WPRProtectFW_V648::IP_COOKIE_MODE_ENABLED);
319 + return ($this->ip_cookie_mode === WPRProtectFW_V672::IP_COOKIE_MODE_ENABLED);
320 320 }
321 321
322 322 private function isRequestProfilingDisabled() {
323 - return ($this->request_profiling_mode === WPRProtectFW_V648::REQ_PROFILING_MODE_DISABLED);
323 + return ($this->request_profiling_mode === WPRProtectFW_V672::REQ_PROFILING_MODE_DISABLED);
324 324 }
325 325
326 326 private function isRequestProfilingModeDebug() {
327 - return ($this->request_profiling_mode === WPRProtectFW_V648::REQ_PROFILING_MODE_DEBUG);
327 + return ($this->request_profiling_mode === WPRProtectFW_V672::REQ_PROFILING_MODE_DEBUG);
328 328 }
329 329
330 330 private function isRequestHasValidBypassCookie() {
331 331 if (!isset($this->has_valid_bypass_cookie)) {
332 - $cookie = (string) $this->request->getCookies(WPRProtectFW_V648::BYPASS_COOKIE_NAME);
332 + $cookie = (string) $this->request->getCookies(WPRProtectFW_V672::BYPASS_COOKIE_NAME);
333 333 $new_cookie = $this->generateBypassCookie();
334 334 $is_valid = ($this->isAdminCookieEnabled() && $new_cookie && ($cookie === $new_cookie));
335 335 $this->has_valid_bypass_cookie = $is_valid;
336 336 }
@@ -338,17 +338,17 @@
338 338 return $this->has_valid_bypass_cookie;
339 339 }
340 340
341 341 private function isRulesModeProtect() {
342 - return ($this->rules_mode === WPRProtectFW_V648::RULES_MODE_PROTECT);
342 + return ($this->rules_mode === WPRProtectFW_V672::RULES_MODE_PROTECT);
343 343 }
344 344
345 345 public function isLoggingModeComplete() {
346 - return ($this->logging_mode === WPRProtectFW_V648::LOGGING_MODE_COMPLETE);
346 + return ($this->logging_mode === WPRProtectFW_V672::LOGGING_MODE_COMPLETE);
347 347 }
348 348
349 349 public function isLoggingModeVisitor() {
350 - return ($this->logging_mode === WPRProtectFW_V648::LOGGING_MODE_VISITOR);
350 + return ($this->logging_mode === WPRProtectFW_V672::LOGGING_MODE_VISITOR);
351 351 }
352 352
353 353 public function isGeoBlockingEnabled() {
354 354 return ($this->is_geo_blocking === true);
@@ -354,13 +354,13 @@
354 354 return ($this->is_geo_blocking === true);
355 355 }
356 356
357 357 private function isWPFRuleInitModePrepend() {
358 - return ($this->wpf_rule_init_mode === WPRProtectFW_V648::WPF_RULE_INIT_MODE_PREPEND);
358 + return ($this->wpf_rule_init_mode === WPRProtectFW_V672::WPF_RULE_INIT_MODE_PREPEND);
359 359 }
360 360
361 361 private function isWPFRuleInitModeWP() {
362 - return ($this->wpf_rule_init_mode === WPRProtectFW_V648::WPF_RULE_INIT_MODE_WP);
362 + return ($this->wpf_rule_init_mode === WPRProtectFW_V672::WPF_RULE_INIT_MODE_WP);
363 363 }
364 364
365 365 private function canInitWPFRules() {
366 366 if (!$this->isWPFRuleInitModePrepend() && $this->isPrependMode()) {
@@ -387,18 +387,18 @@
387 387 if (function_exists('is_user_logged_in') && is_user_logged_in()) {
388 388 $current_wp_user = $this->getCurrentWPUser();
389 389
390 390 if (!$current_wp_user->isIdentical($this->request->wp_user)) {
391 - $serialized_wp_user = WPRProtectWPUser_V648::_serialize($current_wp_user);
391 + $serialized_wp_user = WPRProtectWPUser_V672::_serialize($current_wp_user);
392 392 $cookie_val = $serialized_wp_user . '_' .
393 - WPRProtectUtils_V648::signMessage($serialized_wp_user, $this->cookie_key);
393 + WPRProtectUtils_V672::signMessage($serialized_wp_user, $this->cookie_key);
394 394 $cookie_val = base64_encode($cookie_val);
395 395
396 - $this->setCookie(WPRProtectWPUser_V648::COOKIE_NAME, $cookie_val);
396 + $this->setCookie(WPRProtectWPUser_V672::COOKIE_NAME, $cookie_val);
397 397 }
398 398 } elseif ($this->request->wp_user->isLoggedIn()) {
399 - $this->request->wp_user = WPRProtectWPUser_V648::defaultUser();
400 - $this->unsetCookie(WPRProtectWPUser_V648::COOKIE_NAME);
399 + $this->request->wp_user = WPRProtectWPUser_V672::defaultUser();
400 + $this->unsetCookie(WPRProtectWPUser_V672::COOKIE_NAME);
401 401 }
402 402 }
403 403
404 404 private function getCurrentWPUser() {
@@ -413,9 +413,9 @@
413 413 $role_level = $this->getCurrentWPUserRoleLevel();
414 414 $capabilities = $this->getCurrentWPUserCapabilities();
415 415 }
416 416
417 - return (new WPRProtectWPUser_V648($id, $role_level, $capabilities, $time));
417 + return (new WPRProtectWPUser_V672($id, $role_level, $capabilities, $time));
418 418 }
419 419
420 420 private function getCurrentWPUserCapabilities() {
421 421 $capabilities = array();
@@ -432,11 +432,11 @@
432 432 return $capabilities;
433 433 }
434 434
435 435 private function loadWPUser() {
436 - $this->request->wp_user = WPRProtectWPUser_V648::defaultUser();
436 + $this->request->wp_user = WPRProtectWPUser_V672::defaultUser();
437 437
438 - $cookie_val = $this->request->getCookies(WPRProtectWPUser_V648::COOKIE_NAME);
438 + $cookie_val = $this->request->getCookies(WPRProtectWPUser_V672::COOKIE_NAME);
439 439 if (!is_string($cookie_val)) {
440 440 return;
441 441 }
442 442
@@ -450,10 +450,10 @@
450 450 return;
451 451 }
452 452 list($serialized_user, $signature) = $cookie_val_array;
453 453
454 - if (WPRProtectUtils_V648::verifyMessage($serialized_user, $signature, $this->cookie_key) === true) {
455 - $wp_user = WPRProtectWPUser_V648::_unserialize($serialized_user);
454 + if (WPRProtectUtils_V672::verifyMessage($serialized_user, $signature, $this->cookie_key) === true) {
455 + $wp_user = WPRProtectWPUser_V672::_unserialize($serialized_user);
456 456
457 457 if (!isset($wp_user) || $wp_user->time !== (int) floor(time() / $this->cookie_validity)) {
458 458 return;
459 459 }
@@ -466,10 +466,10 @@
466 466 $this->request->wp_user->capability_names[] = $capability_names[$capability];
467 467 }
468 468 }
469 469
470 - $role_by_level = array_flip(array_merge(WPRProtectFW_V648::DEFAULT_WP_USER_ROLE_LEVELS,
471 - WPRProtectFW_V648::EXTRA_WP_USER_ROLE_LEVELS));
470 + $role_by_level = array_flip(array_merge(WPRProtectFW_V672::DEFAULT_WP_USER_ROLE_LEVELS,
471 + WPRProtectFW_V672::EXTRA_WP_USER_ROLE_LEVELS));
472 472 $this->request->wp_user->role = $role_by_level[$this->request->wp_user->role_level];
473 473 }
474 474 }
475 475
@@ -491,11 +491,11 @@
491 491 }
492 492
493 493 if ($this->isPrependMode()) {
494 494 $rules_file = MCDATAPATH . MCCONFKEY . '-' . 'mc_rules.json';
495 - $rule_arrays = WPRProtectUtils_V648::parseFile($rules_file);
495 + $rule_arrays = WPRProtectUtils_V672::parseFile($rules_file);
496 496 } else {
497 - $rule_arrays = WPRProtect_V648::$settings->getOption('bvruleset');
497 + $rule_arrays = WPRProtect_V672::$settings->getOption('bvruleset');
498 498 if(!is_array($rule_arrays)) {
499 499 $rule_arrays = array();
500 500 }
501 501 }
@@ -505,9 +505,9 @@
505 505 return;
506 506 }
507 507
508 508 foreach($rule_arrays as $rule_array) {
509 - $rule = WPRProtectFWRule_V648::init($rule_array);
509 + $rule = WPRProtectFWRule_V672::init($rule_array);
510 510
511 511 if ($rule) {
512 512 if (!$this->is_rule_initialized && $rule->isExeOnBoot()) {
513 513 if (!$this->isRequestHasValidBypassCookie()) {
@@ -529,40 +529,108 @@
529 529 $this->rules[] = $rule;
530 530 }
531 531
532 532 private function initWPFRule($rule) {
533 - if ($rule->isExeOnPreUpdateOption()) {
533 + switch ($rule->execute_on) {
534 + case WPRProtectFWRule_V672::EXE_ON_PRE_UPDATE_OPTION:
534 535 $this->addWPHook($rule, 'pre_update_option', 'handleRequestOnPreUpdateOption', 3);
535 - } elseif ($rule->isExeOnPreDeletePost()) {
536 + break;
537 + case WPRProtectFWRule_V672::EXE_ON_PRE_DELETE_POST:
536 538 $this->addWPHook($rule, 'pre_delete_post', 'handleRequestOnPreDeletePost', 3);
537 - } elseif ($rule->isExeOnWPInsertPostEmptyContent()) {
538 - $this->addWPHook($rule, 'wp_insert_post_empty_content', 'handleRequestOnWPInsertPostEmptyContent', 2);
539 - } elseif ($rule->isExeOnInsertUserMeta()) {
539 + break;
540 + case WPRProtectFWRule_V672::EXE_ON_WP_INSERT_POST_EMPTY_CONTENT:
541 + $this->addWPHook($rule, 'wp_insert_post_empty_content',
542 + 'handleRequestOnWPInsertPostEmptyContent', 2);
543 + break;
544 + case WPRProtectFWRule_V672::EXE_ON_INSERT_USER_META:
540 545 $this->addWPHook($rule, 'insert_user_meta', 'handleRequestOnInsertUserMeta', 4);
541 - } elseif ($rule->isExeOnDeleteOption()) {
546 + break;
547 + case WPRProtectFWRule_V672::EXE_ON_DELETE_OPTION:
542 548 $this->addWPHook($rule, 'delete_option', 'handleRequestOnDeleteOption', 1, 'action');
543 - } elseif ($rule->isExeOnDeleteUser()) {
549 + break;
550 + case WPRProtectFWRule_V672::EXE_ON_DELETE_USER:
544 551 $this->addWPHook($rule, 'delete_user', 'handleRequestOnDeleteUser', 3, 'action');
545 - } elseif ($rule->isExeOnPasswordReset()) {
552 + break;
553 + case WPRProtectFWRule_V672::EXE_ON_PASSWORD_RESET:
546 554 $this->addWPHook($rule, 'password_reset', 'handleRequestOnPasswordReset', 2, 'action');
547 - } elseif ($rule->isExeOnSendAuthCookies()) {
555 + break;
556 + case WPRProtectFWRule_V672::EXE_ON_SEND_AUTH_COOKIES:
548 557 $this->addWPHook($rule, 'send_auth_cookies', 'handleRequestOnSendAuthCookies', 6);
549 - } elseif ($rule->isExeOnSetAuthCookie()) {
558 + break;
559 + case WPRProtectFWRule_V672::EXE_ON_SET_AUTH_COOKIE:
550 560 $this->addWPHook($rule, 'set_auth_cookie', 'handleRequestOnSetAuthCookie', 6, 'action');
551 - } elseif ($rule->isExeOnInit()) {
561 + break;
562 + case WPRProtectFWRule_V672::EXE_ON_INIT:
552 563 $this->addWPHook($rule, 'init', 'handleRequestOnInit', 0, 'action');
553 - } elseif ($rule->isExeOnUserRegister()) {
564 + break;
565 + case WPRProtectFWRule_V672::EXE_ON_USER_REGISTER:
554 566 $this->addWPHook($rule, 'user_register', 'handleRequestOnUserRegister', 2, 'action');
555 - } elseif ($rule->isExeOnAddUserMeta()) {
567 + break;
568 + case WPRProtectFWRule_V672::EXE_ON_ADD_USER_META:
556 569 $this->addWPHook($rule, 'add_user_meta', 'handleRequestOnAddUserMeta', 3, 'action');
557 - } elseif ($rule->isExeOnUpdateUserMetadata()) {
570 + break;
571 + case WPRProtectFWRule_V672::EXE_ON_UPDATE_USER_METADATA:
558 572 $this->addWPHook($rule, 'update_user_metadata', 'handleRequestOnUpdateUserMetadata', 5);
559 - } elseif ($rule->isExeOnUpdateUserMeta()) {
573 + break;
574 + case WPRProtectFWRule_V672::EXE_ON_UPDATE_USER_META:
560 575 $this->addWPHook($rule, 'update_user_meta', 'handleRequestOnUpdateUserMeta', 4, 'action');
561 - } elseif ($rule->isExeOnAddOption()) {
576 + break;
577 + case WPRProtectFWRule_V672::EXE_ON_ADD_OPTION:
562 578 $this->addWPHook($rule, 'add_option', 'handleRequestOnAddOption', 2, 'action');
563 - } elseif ($rule->isExeOnWPPreInsertUserData()) {
579 + break;
580 + case WPRProtectFWRule_V672::EXE_ON_WP_PRE_INSERT_USER_DATA:
564 581 $this->addWPHook($rule, 'wp_pre_insert_user_data', 'handleRequestOnWPPreInsertUserData', 4);
582 + break;
583 + case WPRProtectFWRule_V672::EXE_ON_REST_REQUEST_BEFORE_CALLBACKS:
584 + $this->addWPHook($rule, 'rest_request_before_callbacks',
585 + 'handleRequestOnRestRequestBeforeCallbacks', 3);
586 + break;
587 + case WPRProtectFWRule_V672::EXE_ON_ADMIN_INIT:
588 + $this->addWPHook($rule, 'admin_init', 'handleRequestOnAdminInit', 0, 'action');
589 + break;
590 + case WPRProtectFWRule_V672::EXE_ON_WP_HANDLE_UPLOAD_PREFILTER:
591 + $this->addWPHook($rule, 'wp_handle_upload_prefilter',
592 + 'handleRequestOnWPHandleUploadPrefilter', 1);
593 + break;
594 + case WPRProtectFWRule_V672::EXE_ON_TEMPLATE_REDIRECT:
595 + $this->addWPHook($rule, 'template_redirect', 'handleRequestOnTemplateRedirect', 0, 'action');
596 + break;
597 + case WPRProtectFWRule_V672::EXE_ON_WP_LOADED:
598 + $this->addWPHook($rule, 'wp_loaded', 'handleRequestOnWPLoaded', 0, 'action');
599 + break;
600 + case WPRProtectFWRule_V672::EXE_ON_ADD_POST_METADATA:
601 + $this->addWPHook($rule, 'add_post_metadata', 'handleRequestOnAddPostMetadata', 5);
602 + break;
603 + case WPRProtectFWRule_V672::EXE_ON_UPDATE_POST_METADATA:
604 + $this->addWPHook($rule, 'update_post_metadata', 'handleRequestOnUpdatePostMetadata', 5);
605 + break;
606 + case WPRProtectFWRule_V672::EXE_ON_DELETE_POST_METADATA:
607 + $this->addWPHook($rule, 'delete_post_metadata', 'handleRequestOnDeletePostMetadata', 5);
608 + break;
609 + case WPRProtectFWRule_V672::EXE_ON_ADD_TERM_METADATA:
610 + $this->addWPHook($rule, 'add_term_metadata', 'handleRequestOnAddTermMetadata', 5);
611 + break;
612 + case WPRProtectFWRule_V672::EXE_ON_UPDATE_TERM_METADATA:
613 + $this->addWPHook($rule, 'update_term_metadata', 'handleRequestOnUpdateTermMetadata', 5);
614 + break;
615 + case WPRProtectFWRule_V672::EXE_ON_DELETE_TERM_METADATA:
616 + $this->addWPHook($rule, 'delete_term_metadata', 'handleRequestOnDeleteTermMetadata', 5);
617 + break;
618 + case WPRProtectFWRule_V672::EXE_ON_ADD_COMMENT_METADATA:
619 + $this->addWPHook($rule, 'add_comment_metadata', 'handleRequestOnAddCommentMetadata', 5);
620 + break;
621 + case WPRProtectFWRule_V672::EXE_ON_UPDATE_COMMENT_METADATA:
622 + $this->addWPHook($rule, 'update_comment_metadata', 'handleRequestOnUpdateCommentMetadata', 5);
623 + break;
624 + case WPRProtectFWRule_V672::EXE_ON_DELETE_COMMENT_METADATA:
625 + $this->addWPHook($rule, 'delete_comment_metadata', 'handleRequestOnDeleteCommentMetadata', 5);
626 + break;
627 + case WPRProtectFWRule_V672::EXE_ON_ADD_USER_METADATA:
628 + $this->addWPHook($rule, 'add_user_metadata', 'handleRequestOnAddUserMetadata', 5);
629 + break;
630 + case WPRProtectFWRule_V672::EXE_ON_DELETE_USER_METADATA:
631 + $this->addWPHook($rule, 'delete_user_metadata', 'handleRequestOnDeleteUserMetadata', 5);
632 + break;
565 633 }
566 634 }
567 635
568 636 private function addWPHook($rule, $hook_name, $function_name, $accepted_args, $hook_type = 'filter') {
@@ -576,9 +644,9 @@
576 644 } else {
577 645 add_filter($hook_name, $callback, -9999999, $accepted_args);
578 646 }
579 647 } else {
580 - WPRProtectUtils_V648::preInitWPHook($hook_name, $callback, -9999999, $accepted_args);
648 + WPRProtectUtils_V672::preInitWPHook($hook_name, $callback, -9999999, $accepted_args);
581 649 }
582 650 }
583 651
584 652 $this->pushWPFRule($function_name, $rule);
@@ -901,8 +969,199 @@
901 969 $this->handleRequestOnRuleMatch($rules, $variables, $log_data);
902 970 }
903 971 }
904 972
973 + private function handleRequestOnLifecycleHook($function_name, $hook_name) {
974 + $rules = $this->getWPFRules($function_name);
975 +
976 + if (!empty($rules)) {
977 + $variables = $this->getLifecycleHookVariables($hook_name);
978 + $this->handleRequestOnRuleMatch($rules, $variables, $variables);
979 + }
980 + }
981 +
982 + private function getLifecycleHookVariables($hook_name) {
983 + $variables = array('hook' => $hook_name);
984 +
985 + if (function_exists('is_admin')) {
986 + $variables['is_admin'] = is_admin();
987 + }
988 +
989 + if (function_exists('wp_doing_ajax')) {
990 + $variables['is_ajax'] = wp_doing_ajax();
991 + } else {
992 + $variables['is_ajax'] = (defined('DOING_AJAX') && DOING_AJAX);
993 + }
994 +
995 + $variables['is_cron'] = (defined('DOING_CRON') && DOING_CRON);
996 + $variables['is_rest_request'] = (defined('REST_REQUEST') && REST_REQUEST);
997 +
998 + return $variables;
999 + }
1000 +
1001 + public function handleRequestOnAdminInit() {
1002 + $this->handleRequestOnLifecycleHook('handleRequestOnAdminInit', 'admin_init');
1003 + }
1004 +
1005 + public function handleRequestOnTemplateRedirect() {
1006 + $this->handleRequestOnLifecycleHook('handleRequestOnTemplateRedirect', 'template_redirect');
1007 + }
1008 +
1009 + public function handleRequestOnWPLoaded() {
1010 + $this->handleRequestOnLifecycleHook('handleRequestOnWPLoaded', 'wp_loaded');
1011 + }
1012 +
1013 + public function handleRequestOnRestRequestBeforeCallbacks($response, $handler, $request) {
1014 + $rules = $this->getWPFRules('handleRequestOnRestRequestBeforeCallbacks');
1015 +
1016 + if (!empty($rules)) {
1017 + $this->handleRequestOnRuleMatch($rules);
1018 + }
1019 +
1020 + return $response;
1021 + }
1022 +
1023 + private function getSafeUploadFileData($file) {
1024 + $data = array();
1025 +
1026 + if (!is_array($file)) {
1027 + return $data;
1028 + }
1029 +
1030 + foreach (array('name', 'type', 'size', 'error') as $key) {
1031 + if (array_key_exists($key, $file) && (is_scalar($file[$key]) || is_null($file[$key]))) {
1032 + $data[$key] = $file[$key];
1033 + }
1034 + }
1035 +
1036 + if (array_key_exists('name', $data) && is_string($data['name'])) {
1037 + $data['extension'] = strtolower(pathinfo($data['name'], PATHINFO_EXTENSION));
1038 + }
1039 +
1040 + return $data;
1041 + }
1042 +
1043 + private function getMetadataValueLogData($key, $value) {
1044 + $data = array(
1045 + $key . '_type' => gettype($value),
1046 + $key . '_size' => null
1047 + );
1048 +
1049 + if (is_null($value)) {
1050 + $data[$key . '_size'] = 0;
1051 + } elseif (is_scalar($value)) {
1052 + $data[$key . '_size'] = strlen((string) $value);
1053 + } elseif (is_array($value)) {
1054 + $data[$key . '_count'] = count($value);
1055 + } elseif (is_object($value)) {
1056 + $data[$key . '_count'] = count(get_object_vars($value));
1057 + }
1058 +
1059 + return $data;
1060 + }
1061 +
1062 + public function handleRequestOnWPHandleUploadPrefilter($file) {
1063 + $rules = $this->getWPFRules('handleRequestOnWPHandleUploadPrefilter');
1064 +
1065 + if (!empty($rules)) {
1066 + $safe_file = $this->getSafeUploadFileData($file);
1067 + $variables = array('file' => $safe_file);
1068 + $this->handleRequestOnRuleMatch($rules, $variables, $variables);
1069 + }
1070 +
1071 + return $file;
1072 + }
1073 +
1074 + private function handleRequestOnMetadataFilter($function_name, $meta_type, $operation, $check,
1075 + $object_id, $meta_key, $meta_value, $extra = array()) {
1076 +
1077 + $rules = $this->getWPFRules($function_name);
1078 +
1079 + if (!empty($rules)) {
1080 + $variables = array_merge(array(
1081 + 'check' => $check,
1082 + 'meta_type' => $meta_type,
1083 + 'operation' => $operation,
1084 + 'object_id' => $object_id,
1085 + 'meta_key' => $meta_key,
1086 + 'meta_value' => $meta_value
1087 + ), $extra);
1088 +
1089 + $log_extra = $extra;
1090 + if (array_key_exists('prev_value', $log_extra)) {
1091 + $prev_value = $log_extra['prev_value'];
1092 + unset($log_extra['prev_value']);
1093 + $log_extra = array_merge($log_extra, $this->getMetadataValueLogData('prev_value', $prev_value));
1094 + }
1095 +
1096 + $log_data = array_merge(array(
1097 + 'meta_type' => $meta_type,
1098 + 'operation' => $operation,
1099 + 'object_id' => $object_id,
1100 + 'meta_key' => $meta_key
1101 + ), $this->getMetadataValueLogData('meta_value', $meta_value), $log_extra);
1102 +
1103 + $this->handleRequestOnRuleMatch($rules, $variables, $log_data);
1104 + }
1105 +
1106 + return $check;
1107 + }
1108 +
1109 + public function handleRequestOnAddPostMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1110 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddPostMetadata',
1111 + 'post', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1112 + }
1113 +
1114 + public function handleRequestOnUpdatePostMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1115 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdatePostMetadata',
1116 + 'post', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1117 + }
1118 +
1119 + public function handleRequestOnDeletePostMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1120 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeletePostMetadata',
1121 + 'post', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1122 + }
1123 +
1124 + public function handleRequestOnAddTermMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1125 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddTermMetadata',
1126 + 'term', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1127 + }
1128 +
1129 + public function handleRequestOnUpdateTermMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1130 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdateTermMetadata',
1131 + 'term', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1132 + }
1133 +
1134 + public function handleRequestOnDeleteTermMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1135 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteTermMetadata',
1136 + 'term', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1137 + }
1138 +
1139 + public function handleRequestOnAddCommentMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1140 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddCommentMetadata',
1141 + 'comment', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1142 + }
1143 +
1144 + public function handleRequestOnUpdateCommentMetadata($check, $object_id, $meta_key, $meta_value, $prev_value) {
1145 + return $this->handleRequestOnMetadataFilter('handleRequestOnUpdateCommentMetadata',
1146 + 'comment', 'update', $check, $object_id, $meta_key, $meta_value, array('prev_value' => $prev_value));
1147 + }
1148 +
1149 + public function handleRequestOnDeleteCommentMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1150 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteCommentMetadata',
1151 + 'comment', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1152 + }
1153 +
1154 + public function handleRequestOnAddUserMetadata($check, $object_id, $meta_key, $meta_value, $unique) {
1155 + return $this->handleRequestOnMetadataFilter('handleRequestOnAddUserMetadata',
1156 + 'user', 'add', $check, $object_id, $meta_key, $meta_value, array('unique' => $unique));
1157 + }
1158 +
1159 + public function handleRequestOnDeleteUserMetadata($check, $object_id, $meta_key, $meta_value, $delete_all) {
1160 + return $this->handleRequestOnMetadataFilter('handleRequestOnDeleteUserMetadata',
1161 + 'user', 'delete', $check, $object_id, $meta_key, $meta_value, array('delete_all' => $delete_all));
1162 + }
1163 +
905 1164 private function setShutdownCallback() {
906 1165 if (!$this->is_shutdown_cb_set) {
907 1166 register_shutdown_function(array($this, 'log'));
908 1167 $this->is_shutdown_cb_set = true;
@@ -943,14 +1202,14 @@
943 1202 }
944 1203
945 1204 private function setIPCookie() {
946 1205 if (!$this->is_ip_cookie_set && $this->isIPCookieEnabled() &&
947 - !$this->request->getCookies(WPRProtectFW_V648::IP_COOKIE_NAME)) {
1206 + !$this->request->getCookies(WPRProtectFW_V672::IP_COOKIE_NAME)) {
948 1207
949 1208 $time = floor(time() / 86400);
950 1209 $cookie = hash('sha256', $this->request->ip . $time . $this->cookie_key);
951 1210 if ($cookie) {
952 - $this->setCookie(WPRProtectFW_V648::IP_COOKIE_NAME, $cookie, time() + 86400);
1211 + $this->setCookie(WPRProtectFW_V672::IP_COOKIE_NAME, $cookie, time() + 86400);
953 1212 }
954 1213 }
955 1214 }
956 1215
@@ -956,18 +1215,18 @@
956 1215
957 1216 private function getCurrentWPUserRoleLevel() {
958 1217 if (function_exists('current_user_can')) {
959 1218 if (function_exists('is_super_admin') && is_super_admin()) {
960 - return WPRProtectFW_V648::WP_USER_ROLE_LEVEL_ADMIN;
1219 + return WPRProtectFW_V672::WP_USER_ROLE_LEVEL_ADMIN;
961 1220 }
962 1221
963 1222 foreach ($this->custom_roles as $role) {
964 1223 if (current_user_can($role)) {
965 - return WPRProtectFW_V648::WP_USER_ROLE_LEVEL_CUSTOM;
1224 + return WPRProtectFW_V672::WP_USER_ROLE_LEVEL_CUSTOM;
966 1225 }
967 1226 }
968 1227
969 - foreach (WPRProtectFW_V648::DEFAULT_WP_USER_ROLE_LEVELS as $role => $level) {
1228 + foreach (WPRProtectFW_V672::DEFAULT_WP_USER_ROLE_LEVELS as $role => $level) {
970 1229 if (current_user_can($role)) {
971 1230 return $level;
972 1231 }
973 1232 }
@@ -1073,11 +1332,11 @@
1073 1332
1074 1333 private function getBVCookies() {
1075 1334 $cookies = array();
1076 1335
1077 - if ($this->request->getCookies(WPRProtectFW_V648::IP_COOKIE_NAME) !== NULL) {
1078 - $cookie_val = (string) $this->request->getCookies(WPRProtectFW_V648::IP_COOKIE_NAME);
1079 - $cookies[WPRProtectFW_V648::IP_COOKIE_NAME] = $cookie_val;
1336 + if ($this->request->getCookies(WPRProtectFW_V672::IP_COOKIE_NAME) !== NULL) {
1337 + $cookie_val = (string) $this->request->getCookies(WPRProtectFW_V672::IP_COOKIE_NAME);
1338 + $cookies[WPRProtectFW_V672::IP_COOKIE_NAME] = $cookie_val;
1080 1339 }
1081 1340
1082 1341 return $cookies;
1083 1342 }
@@ -1229,13 +1488,19 @@
1229 1488 $this->updateRuleLog('inspect', "cookies", $this->getCookiesToLog($this->request->getCookies()));
1230 1489 $this->updateRuleLog('inspect', "getParams", $this->request->getGetParams());
1231 1490 $this->updateRuleLog('inspect', "postParams", $this->getParamsToLog($this->request->getPostParams(), "POST"));
1232 1491 $this->updateRuleLog('inspect', "jsonParams", $this->getParamsToLog($this->request->getJsonParams(), "JSON"));
1233 - $this->updateRuleLog('inspect', "rawBody", $this->getRawBodyToLog($this->request->getRawBody()));
1492 + $this->updateRuleLog('inspect', "bodyParserStatus", $this->request->getBodyParserStatus());
1493 + if ($this->can_log_raw_body) {
1494 + $raw_body = $this->request->getRawBody();
1495 + if (!empty($raw_body)) {
1496 + $this->updateRuleLog('inspect', "rawBody", $this->getRawBodyToLog($raw_body));
1497 + }
1498 + }
1234 1499 }
1235 1500
1236 1501 private function getUserBy($attribute, $value) {
1237 - if (isset($value) && function_exists('get_user_by') && WPRProtectUtils_V648::havePluginsLoaded()) {
1502 + if (isset($value) && function_exists('get_user_by') && WPRProtectUtils_V672::havePluginsLoaded()) {
1238 1503 return get_user_by($attribute, $value);
1239 1504 }
1240 1505 }
1241 1506
@@ -1337,9 +1602,9 @@
1337 1602 xlsx|psd|mp3|m4a|ogg|wav|mp4|m4v|mov|wmv|avi|mpg|ogv|3gp|3g2|php|html|phtml|js|css)/ix', $value)) {
1338 1603 $profiled_data[$key]["file"] = true;
1339 1604 }
1340 1605
1341 - if ($this->matchCount(WPRProtectFWRule_V648::SQLIREGEX, $value) > 2) {
1606 + if ($this->matchCount(WPRProtectFWRule_V672::SQLIREGEX, $value) > 2) {
1342 1607 $profiled_data[$key]["sql"] = true;
1343 1608 }
1344 1609
1345 1610 if (WPRHelper::safePregMatch('/(?:\.{2}[\/]+)/', $value)) {
@@ -1405,8 +1670,14 @@
1405 1670 if ($this->can_log_raw_body && $is_debug_mode && $log_raw_body && !empty($this->request->getRawBody())) {
1406 1671 $profiled_data += array("RAW_BODY" => $this->getRawBodyToLog($this->request->getRawBody()));
1407 1672 }
1408 1673
1674 + $body_parser_status = $this->request->getBodyParserStatus();
1675 + $profiled_data = array(
1676 + "BODY_RAW_STATUS" => $body_parser_status['raw_body_status'],
1677 + "JSON_PARAMS_STATUS" => $body_parser_status['json_params_status']
1678 + ) + $profiled_data;
1679 +
1409 1680 $this->request_profiled_data = $profiled_data;
1410 1681 $this->is_request_profiled = true;
1411 1682 }
1412 1683 }
@@ -1420,15 +1691,15 @@
1420 1691 }
1421 1692
1422 1693 private function canRequestBypassFirewall() {
1423 1694 if ($this->isRequestIPWhitelisted() || $this->isRequestHasValidBypassCookie()) {
1424 - $this->request->category = WPRProtectRequest_V648::CATEGORY_WHITELISTED;
1425 - $this->request->status = WPRProtectRequest_V648::STATUS_BYPASSED;
1695 + $this->request->category = WPRProtectRequest_V672::CATEGORY_WHITELISTED;
1696 + $this->request->status = WPRProtectRequest_V672::STATUS_BYPASSED;
1426 1697
1427 1698 return true;
1428 - } elseif (WPRProtectUtils_V648::isPrivateIP($this->request->ip)) {
1429 - $this->request->category = WPRProtectRequest_V648::CATEGORY_PRIVATEIP;
1430 - $this->request->status = WPRProtectRequest_V648::STATUS_BYPASSED;
1699 + } elseif (WPRProtectUtils_V672::isPrivateIP($this->request->ip)) {
1700 + $this->request->category = WPRProtectRequest_V672::CATEGORY_PRIVATEIP;
1701 + $this->request->status = WPRProtectRequest_V672::STATUS_BYPASSED;
1431 1702
1432 1703 return true;
1433 1704 }
1434 1705
@@ -1450,19 +1721,22 @@
1450 1721 }
1451 1722 }
1452 1723
1453 1724 private function handleRequestOnRuleMatch($rules, $engine_vars = array(), $log_data = array()) {
1725 + $normalized_engine_vars = WPRProtectFWRuleEngine_V672::normalizeVariables($engine_vars);
1726 +
1454 1727 foreach ($rules as $rule) {
1455 1728 if ($this->break_rule_matching) {
1456 1729 break;
1457 1730 }
1458 1731
1459 - $_engine_vars = $engine_vars;
1732 + $_engine_vars = $normalized_engine_vars;
1460 1733 if (array_key_exists('variables', $rule->opts)) {
1461 - $_engine_vars = array_merge($_engine_vars, $rule->opts['variables']);
1734 + $_engine_vars = array_merge($_engine_vars,
1735 + WPRProtectFWRuleEngine_V672::normalizeVariables($rule->opts['variables']));
1462 1736 }
1463 1737
1464 - $rule_engine = new WPRProtectFWRuleEngine_V648($this->request, $_engine_vars);
1738 + $rule_engine = new WPRProtectFWRuleEngine_V672($this->request, $_engine_vars);
1465 1739
1466 1740 if ($rule_engine->evaluate($rule) && !$rule_engine->hasError()) {
1467 1741 if (!empty($log_data)) {
1468 1742 $this->updateRuleLog("info", (string) $rule->id, $log_data);
@@ -1473,13 +1747,13 @@
1473 1747 foreach($rule->actions as $action) {
1474 1748 switch ($action["type"]) {
1475 1749 case "ALLOW":
1476 1750 $this->break_rule_matching = true;
1477 - $this->request->category = WPRProtectRequest_V648::CATEGORY_RULE_ALLOWED;
1751 + $this->request->category = WPRProtectRequest_V672::CATEGORY_RULE_ALLOWED;
1478 1752 return;
1479 1753 case "BLOCK":
1480 1754 if ($this->isModeProtect()) {
1481 - $this->terminateRequest(WPRProtectRequest_V648::CATEGORY_RULE_BLOCKED);
1755 + $this->terminateRequest(WPRProtectRequest_V672::CATEGORY_RULE_BLOCKED);
1482 1756 }
1483 1757 return;
1484 1758 case "INSPECT":
1485 1759 $this->inspectRequest();
@@ -1493,15 +1767,15 @@
1493 1767 }
1494 1768
1495 1769 private function terminateRequest($category) {
1496 1770 $this->request->category = $category;
1497 - $this->request->status = WPRProtectRequest_V648::STATUS_BLOCKED;
1771 + $this->request->status = WPRProtectRequest_V672::STATUS_BLOCKED;
1498 1772 $this->request->setRespCode(403);
1499 1773
1500 1774 if ($this->can_set_cache_prevention_cookie &&
1501 - !$this->request->getCookies(WPRProtectFW_V648::PREVENT_CACHE_COOKIE_NAME)) {
1775 + !$this->request->getCookies(WPRProtectFW_V672::PREVENT_CACHE_COOKIE_NAME)) {
1502 1776 $value = "Prevent Caching Response.";
1503 - $this->setCookie(WPRProtectFW_V648::PREVENT_CACHE_COOKIE_NAME, $value, time() + 43200);
1777 + $this->setCookie(WPRProtectFW_V672::PREVENT_CACHE_COOKIE_NAME, $value, time() + 43200);
1504 1778 }
1505 1779
1506 1780 header("Cache-Control: no-cache, no-store, must-revalidate");
1507 1781 header("Pragma: no-cache");
@@ -1527,9 +1801,9 @@
1527 1801 $role_level = $this->getCurrentWPUserRoleLevel();
1528 1802 if ($role_level >= $this->bypass_level) {
1529 1803 $cookie = $this->generateBypassCookie();
1530 1804 if ($cookie) {
1531 - $this->setCookie(WPRProtectFW_V648::BYPASS_COOKIE_NAME, $cookie);
1805 + $this->setCookie(WPRProtectFW_V672::BYPASS_COOKIE_NAME, $cookie);
1532 1806 }
1533 1807 }
1534 1808 }
1535 1809 }