PluginProbe
WebTotem Security / 1.0
WebTotem Security v1.0
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | services.php +103 -173 2.2.11.0 View file →
@@ -1,193 +1,122 @@
1 1 <?php defined('ABSPATH') or die("Protected By WT!");
2 2
3 -function wtsec_cmd($cmd, $service, $_service, $uid, $status, $domain = '')
4 -{
5 - global $wp_filesystem;
3 +function wtsec_cmd($wp_filesystem,$cmd, $service, $_service, $uid, $status,$domain = ''){
6 4
7 - //bug fix with wp file system, which return null
8 - if (empty($wp_filesystem)) {
9 - require_once(ABSPATH . '/wp-admin/includes/file.php');
10 - WP_Filesystem();
11 - }
12 -
13 - //retry checking
14 - if (empty($wp_filesystem)) {
15 - WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
16 - return false;
17 - }
18 -
19 5 switch ($cmd) {
20 6 case $_service . "_install":
21 7 try {
22 8 $file = wtsec_generateFile($uid, $service);
23 - if (is_null($file['name'])) {
24 - WTSEC_LIBRARY_Session::setNotification("error", wtsec_locale("failed_to_download_agent"));
25 - return false;
9 + if($service === "WAF"){
10 + $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
11 + $path = $plugin_path;
12 + $target_dir = $wp_filesystem->find_folder($path);
13 + if(!$wp_filesystem->is_dir($path)) {
14 + $wp_filesystem->mkdir($target_dir);
26 15 }
27 - if ($service === "WAF") {
28 - $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
29 - $path = $plugin_path;
30 - $target_dir = $wp_filesystem->find_folder($path);
31 - if (!$wp_filesystem->is_dir($path)) {
32 - $wp_filesystem->mkdir($target_dir);
33 - }
34 - $target_file = trailingslashit($target_dir) . $file['name'];
35 - if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)) {
36 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
37 - } else {
38 - wtsec_app()->set($_service . '_installed_file', $file['name']);
39 - }
40 - } else {
16 + $target_file = trailingslashit($target_dir).$file['name'];
17 + if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)){
18 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
19 + }else{
20 + wtsec_app()->set($_service . '_installed_file',$file['name']);
21 + }
22 + }else{
41 23 $target_dir = $wp_filesystem->find_folder($wp_filesystem->abspath());
42 - $target_file = trailingslashit($target_dir) . $file['name'];
43 - if (!$wp_filesystem->put_contents($target_file, $file['file'])) {
44 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
45 - } else {
46 - if ($service === "AM") { wtsec_addCheckFile(); }
47 - wtsec_app()->set($_service . '_installed_file', $file['name']);
24 + $target_file = trailingslashit($target_dir).$file['name'];
25 + if(!$wp_filesystem->put_contents($target_file, $file['file'])) {
26 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
27 + }else{
28 + wtsec_app()->set($_service . '_installed_file',$file['name']);
48 29 }
49 30 }
50 - if ($service !== "AM") {
51 - wtsec_serviceConnect($uid, $service, $domain . '/' . $file['name']);
52 - }
31 + wtsec_serviceConnect($uid, $service,$domain.'/'.$file['name']);
53 32 } catch (Exception $e) {
54 - WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
55 - return false;
33 + print_r($e->getMessage());
34 + die();
56 35 }
57 36 break;
58 37 case $_service . "_start":
59 - WTSEC_LIBRARY_WT::changeStatus($status['config_id'], $uid);
60 - wtsec_app()->set($_service . '_status', "start");
38 + WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
39 + wtsec_app()->set($_service.'_status',"start");
61 40 break;
62 41 case $_service . "_stop":
63 -// WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
64 - wtsec_app()->set($_service . '_status', "stop");
42 + WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
43 + wtsec_app()->set($_service.'_status',"stop");
65 44 break;
66 45 case $_service . "_connect":
67 46 $file = wtsec_getInstalledFile($_service);
68 47 if ($file) {
69 48 wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
70 - } else {
71 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
49 + }else{
50 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
72 51 }
73 52 break;
74 53 case $_service . "_uninstall":
75 54 try {
76 55 $file = wtsec_getInstalledFile($_service);
77 - if ($service === "WAF") {
56 + if($service === "WAF"){
78 57 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
79 58 $mainDir = $plugin_path;
80 - } else {
59 + }else{
81 60 $mainDir = $wp_filesystem->abspath();
82 61 }
83 62 $target_dir = $wp_filesystem->find_folder($mainDir);
84 - $target_file = trailingslashit($mainDir) . $file;
63 + $target_file = trailingslashit($mainDir).$file;
85 64 if (!$wp_filesystem->delete($target_file)) {
86 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service, 'directory' => $target_dir]));
65 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service,'directory' => $target_dir]));
87 66 }
88 67 wtsec_app()->set($_service . '_status', "uninstalled");
89 68 WTSEC_LIBRARY_App::deleteOption($_service . '_installed_file');
90 69 } catch (Exception $e) {
91 - WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
92 - return false;
70 + print_r($e->getMessage());
71 + die();
93 72 }
94 73 break;
95 74 }
96 - return true;
97 75 }
98 76
99 -// Add check file if plugin is activated
100 -function wtsec_addCheckFile(){
101 - global $wp_filesystem;
102 -
103 - if (empty($wp_filesystem)) {
104 - require_once(ABSPATH . '/wp-admin/includes/file.php');
105 - WP_Filesystem();
77 +function wtsec_checkStatus($id, $service)
78 +{
79 + $result = WTSEC_LIBRARY_WT::checkStatus($id,$service);
80 + $data = $result['data'][strtolower($service) . 'ServiceChecks'][0];
81 + $is_active = (boolean)$data['config']['isActive'];
82 + $config_id = $data['config']['id'];
83 + $status = $data['status'];
84 + if ($status == -300 && $is_active) {
85 + wtsec_app()->set($service . '_connected_' . $id, false);
106 86 }
107 -
108 - //retry checking
109 - if (empty($wp_filesystem)) {
110 - WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
111 - return false;
112 - }
113 -
114 - $target_dir = $wp_filesystem->find_folder(WTSEC_PLUGIN_PATH);
115 - $target_file = trailingslashit($target_dir) . 'generate.php';
116 - $content = '<?php echo rand()?>';
117 -
118 - if ($wp_filesystem->put_contents($target_file, $content, FS_CHMOD_FILE)) {
119 - return true;
120 - }
121 -
122 - WTSEC_LIBRARY_Session::setNotification("error", "generate fail");
123 - return false;
87 + return ['active' => $is_active, 'status' => $status, 'config_id' => $config_id];
124 88 }
125 89
126 -function wtsec_checkStatus($id, $service)
127 -{
128 - $service = ucfirst(strtolower($service));
129 - $is_active = null;
130 - $config_id = null;
131 - $result = WTSEC_LIBRARY_WT::checkStatus($id, $service);
132 - $data = $result['data']['auth']['viewer']['sites']['one']['configs'];
133 - foreach ($data as &$cfg) {
134 - if (!empty($cfg)) {
135 - $is_active = $cfg['isActive'];
136 - $config_id = $cfg['id'];
137 - }
138 - }
139 90
140 - if ($is_active === false) {
141 - wtsec_app()->set($service . '_connected_' . $id, true);
142 - }
143 - return ['active' => $is_active, 'config_id' => $config_id];
144 -}
145 91
146 92 function wtsec_generateFile($id, $service)
147 93 {
148 - if ($service === "AM") {
149 - $result = WTSEC_LIBRARY_WT::generateAmFile($id);
150 - if (!isset($result['data']['auth']['am']['install'])) {
151 - $file = ['filename' => null, "body" => null];
152 - } else {
153 - $url = $result['data']['auth']['am']['install'];
154 - $file = WTSEC_LIBRARY_WT::getFileByUrl($url);
155 - if (empty($file)) {
156 - $file = WTSEC_LIBRARY_WT::getFileByUrl($url);
157 - }
158 - }
159 -
160 - $name = $file["filename"];
161 - $file = $file["body"];
162 - } else {
163 - $result = WTSEC_LIBRARY_WT::generateFile($id, $service);
164 - $name = $result['data']['auth']['agents']['generate']['agentName'];
94 + $result = WTSEC_LIBRARY_WT::generateFile($id,$service);
95 + $name = $result['data']['generateAgent']['agentName'] . '.' . strtolower($service) . '.php';
96 + $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
97 + if(empty($file)){
165 98 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
166 - if (empty($file)) {
167 - $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
168 - }
169 99 }
170 -
171 100 return ['file' => $file, 'name' => $name];
172 101 }
173 102
174 -function wtsec_serviceConnect($id, $service, $domain = '')
103 +function wtsec_serviceConnect($id, $service,$domain = '')
175 104 {
176 - $result = WTSEC_LIBRARY_WT::serviceConnect($id, $service);
177 - $status = isset($result['errors']) && !isset($result['data']['auth']['agents']['check']) ? false : true;
105 + $result = WTSEC_LIBRARY_WT::serviceConnect($id,$service);
106 + $status = (isset($result['errors']) || isset($result['data']['checkAgent']['lockFor']) || (isset($result['data']['checkAgent']['installed']) && $result['data']['checkAgent']['installed'] === false)) ? false : true;
178 107 if (!$status) {
179 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
108 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
180 109 }
181 110 return $status;
182 111 }
183 112
184 113
185 -function wtsec_servicePing($service, $domain = '')
114 +function wtsec_servicePing($service,$domain = '')
186 115 {
187 - if ($domain == NULL) return false;
188 - if (stripos($domain, "http") === false) {
189 - $domain = "http://" . $domain;
116 + if($domain == NULL) return false;
117 + if(mb_stripos($domain,"http") === false){
118 + $domain = "http://".$domain;
190 119 }
191 120 $args = [
192 121 'timeout' => '10',
193 122 'sslverify' => false,
@@ -192,71 +121,78 @@
192 121 'timeout' => '10',
193 122 'sslverify' => false,
194 123 'redirection' => 3,
195 124 ];
196 - $response = wp_remote_get($domain, $args);
125 + $response = wp_remote_get($domain,$args);
197 126 $httpcode = wp_remote_retrieve_response_code($response);
198 - if ($httpcode >= 200 && $httpcode < 400) {
127 + if($httpcode>=200 && $httpcode<400){
199 128 return true;
200 129 } else {
201 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
130 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
202 131 return false;
203 132 }
204 133 }
205 134
206 -function wtsec_button($label = '', $class = '')
207 -{
208 - return '<button class="ww-button ' . $class . '">' . $label . '</button>';
135 +function wtsec_button($label = '',$class = ''){
136 + return '<button class="ww-button '.$class.'">'.$label.'</button>';
209 137 }
210 138
211 -function wtsec_main_button($label = '', $class = '')
212 -{
213 - return '<button class="ww-button ' . $class . '">' . $label . '</button>';
139 +function wtsec_main_button($label = '',$class = ''){
140 + return '<button class="ww-button '.$class.'">'.$label.'</button>';
214 141 }
215 142
216 -function wtsec_generateButtons($uid, $_service, $service, $status, $domain = '')
143 +function wtsec_generateButtons($uid,$_service, $service, $status,$domain = '')
217 144 {
218 145 $url = esc_url(admin_url('admin-post.php'));
219 146 $buttons = [];
220 147
221 - $form = '<form action="' . $url . '" method="post" style="display:inline-block;">
222 - <input type="hidden" name="service" value="' . $_service . '">
148 + $form = '<form action="'.$url.'" method="post" style="display:inline-block;">
149 + <input type="hidden" name="service" value="'.$_service.'">
223 150 <input type="hidden" name="action" value="ajax_cmd">
224 - <input type="hidden" name="uid" value="' . $uid . '">
151 + <input type="hidden" name="uid" value="'.$uid.'">
225 152 <input type="hidden" name="cmd" value="{{{cmd}}}">{{{button}}}</form>';
226 153 $result = [];
227 154 $installedFile = wtsec_checkInstalledFile($_service);
155 + $runned = $status['active'];
156 +
157 + if($service === "WAF"){
158 + $first_class = "";
159 + }else{
160 + $first_class = "ww-button--block ";
161 + }
228 162 $disable_uninstall = false;
229 - $first_class = "ww-button--block ";
230 -
231 - if ($service === "AM") {
232 - if (!$installedFile['status']) {
233 - $cmd = $_service . '_install';
234 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
163 + if (!$installedFile['status']) {
164 + $cmd = $_service . '_install';
165 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'),$first_class."ww-button--success"),'cmd' => $cmd];
166 + } else {
167 + if($service === "WAF"){
168 + $url = $domain.'/?ping='.$installedFile['file'];
169 + }else{
170 + $url = $domain.'/'.$installedFile['file'];
171 + }
172 + $connected = wtsec_servicePing($service,$url);
173 + if (!$connected) {
174 + $disable_uninstall = true;
175 + $cmd = $_service . '_connect';
176 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('connect'),$first_class."ww-button--success"),'cmd' => $cmd];
235 177 } else {
236 -// $url = $domain.'/'.$installedFile['file'];
237 -// $connected = wtsec_servicePing($service,$url);
238 - if (!$disable_uninstall) {
239 - $cmd = $_service . '_uninstall';
240 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'), $first_class . "ww-button--attention"), 'cmd' => $cmd];
178 + if ($runned) {
179 + $cmd = $_service . '_stop';
180 + $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('stop'),"ww-button--primary"),'cmd' => $cmd];
181 + } else {
182 + $cmd = $_service . '_start';
183 + $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('run'),"ww-button--primary"),'cmd' => $cmd];
241 184 }
242 185 }
243 - } else {
244 - if ($service === "WAF") {
245 - $first_class = "";
186 + if(!$disable_uninstall && !$runned){
187 + $cmd = $_service . '_uninstall';
188 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'),$first_class."ww-button--attention"),'cmd' => $cmd];
246 189 }
247 -
248 - if ($status === "not_installed") {
249 - $cmd = $_service . '_install';
250 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
251 - }
252 190 }
253 -
254 -
255 - foreach ($buttons as $btn) {
191 + foreach ($buttons as $btn){
256 192 $newform = $form;
257 - $newform = str_replace("{{{cmd}}}", $btn['cmd'], $newform);
258 - $newform = str_replace("{{{button}}}", $btn['button'], $newform);
193 + $newform = str_replace("{{{cmd}}}",$btn['cmd'],$newform);
194 + $newform = str_replace("{{{button}}}",$btn['button'],$newform);
259 195 $result[$btn['place']] = $newform;
260 196 }
261 197 return $result;
262 198 }
@@ -263,16 +199,10 @@
263 199
264 200 function wtsec_checkInstalledFile($service)
265 201 {
266 202 $file = wtsec_getInstalledFile($service);
267 - if ($service == "waf") {
268 - $root = WTSEC_INSTALLATION_DIR;
269 - } else {
270 - $root = ABSPATH;
271 - }
272 - return ['status' => ((bool)$file) && is_file($root . $file), 'file' => $file];
203 + return ['status' => (bool) $file,'file' => $file];
273 204 }
274 205
275 -function wtsec_getInstalledFile($service)
276 -{
277 - return wtsec_app()->get($service . "_installed_file");
206 +function wtsec_getInstalledFile($service){
207 + return wtsec_app()->get($service."_installed_file");
278 208 }