PluginProbe
WebTotem Security / 2.1
WebTotem Security v2.1
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | services.php +96 -159 2.2.12.1 View file →
@@ -1,138 +1,89 @@
1 1 <?php defined('ABSPATH') or die("Protected By WT!");
2 2
3 -function wtsec_cmd($cmd, $service, $_service, $uid, $status, $domain = '')
4 -{
5 - global $wp_filesystem;
3 +function wtsec_cmd($wp_filesystem,$cmd, $service, $_service, $uid, $status,$domain = ''){
6 4
7 - //bug fix with wp file system, which return null
8 - if (empty($wp_filesystem)) {
9 - require_once(ABSPATH . '/wp-admin/includes/file.php');
10 - WP_Filesystem();
11 - }
12 -
13 - //retry checking
14 - if (empty($wp_filesystem)) {
15 - WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
16 - return false;
17 - }
18 -
19 5 switch ($cmd) {
20 6 case $_service . "_install":
21 7 try {
22 8 $file = wtsec_generateFile($uid, $service);
23 - if (is_null($file['name'])) {
24 - WTSEC_LIBRARY_Session::setNotification("error", wtsec_locale("failed_to_download_agent"));
25 - return false;
9 + if($service === "WAF"){
10 + $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
11 + $path = $plugin_path;
12 + $target_dir = $wp_filesystem->find_folder($path);
13 + if(!$wp_filesystem->is_dir($path)) {
14 + $wp_filesystem->mkdir($target_dir);
26 15 }
27 - if ($service === "WAF") {
28 - $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
29 - $path = $plugin_path;
30 - $target_dir = $wp_filesystem->find_folder($path);
31 - if (!$wp_filesystem->is_dir($path)) {
32 - $wp_filesystem->mkdir($target_dir);
33 - }
34 - $target_file = trailingslashit($target_dir) . $file['name'];
35 - if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)) {
36 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
37 - } else {
38 - wtsec_app()->set($_service . '_installed_file', $file['name']);
39 - }
40 - } else {
16 + $target_file = trailingslashit($target_dir).$file['name'];
17 + if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)){
18 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
19 + }else{
20 + wtsec_app()->set($_service . '_installed_file',$file['name']);
21 + }
22 + }else{
41 23 $target_dir = $wp_filesystem->find_folder($wp_filesystem->abspath());
42 - $target_file = trailingslashit($target_dir) . $file['name'];
43 - if (!$wp_filesystem->put_contents($target_file, $file['file'])) {
44 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
45 - } else {
46 - if ($service === "AM") { wtsec_addCheckFile(); }
47 - wtsec_app()->set($_service . '_installed_file', $file['name']);
24 + $target_file = trailingslashit($target_dir).$file['name'];
25 + if(!$wp_filesystem->put_contents($target_file, $file['file'])) {
26 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
27 + }else{
28 + wtsec_app()->set($_service . '_installed_file',$file['name']);
48 29 }
49 30 }
50 - if ($service !== "AM") {
51 - wtsec_serviceConnect($uid, $service, $domain . '/' . $file['name']);
52 - }
31 + wtsec_serviceConnect($uid, $service,$domain.'/'.$file['name']);
53 32 } catch (Exception $e) {
54 - WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
55 - return false;
33 + print_r($e->getMessage());
34 + die();
56 35 }
57 36 break;
58 37 case $_service . "_start":
59 - WTSEC_LIBRARY_WT::changeStatus($status['config_id'], $uid);
60 - wtsec_app()->set($_service . '_status', "start");
38 + WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
39 + wtsec_app()->set($_service.'_status',"start");
61 40 break;
62 41 case $_service . "_stop":
63 42 // WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
64 - wtsec_app()->set($_service . '_status', "stop");
43 + wtsec_app()->set($_service.'_status',"stop");
65 44 break;
66 45 case $_service . "_connect":
67 46 $file = wtsec_getInstalledFile($_service);
68 47 if ($file) {
69 48 wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
70 - } else {
71 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
49 + }else{
50 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
72 51 }
73 52 break;
74 53 case $_service . "_uninstall":
75 54 try {
76 55 $file = wtsec_getInstalledFile($_service);
77 - if ($service === "WAF") {
56 + if($service === "WAF"){
78 57 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
79 58 $mainDir = $plugin_path;
80 - } else {
59 + }else{
81 60 $mainDir = $wp_filesystem->abspath();
82 61 }
83 62 $target_dir = $wp_filesystem->find_folder($mainDir);
84 - $target_file = trailingslashit($mainDir) . $file;
63 + $target_file = trailingslashit($mainDir).$file;
85 64 if (!$wp_filesystem->delete($target_file)) {
86 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service, 'directory' => $target_dir]));
65 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service,'directory' => $target_dir]));
87 66 }
88 67 wtsec_app()->set($_service . '_status', "uninstalled");
89 68 WTSEC_LIBRARY_App::deleteOption($_service . '_installed_file');
90 69 } catch (Exception $e) {
91 - WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
92 - return false;
70 + print_r($e->getMessage());
71 + die();
93 72 }
94 73 break;
95 74 }
96 - return true;
97 75 }
98 76
99 -// Add check file if plugin is activated
100 -function wtsec_addCheckFile(){
101 - global $wp_filesystem;
102 -
103 - if (empty($wp_filesystem)) {
104 - require_once(ABSPATH . '/wp-admin/includes/file.php');
105 - WP_Filesystem();
106 - }
107 -
108 - //retry checking
109 - if (empty($wp_filesystem)) {
110 - WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
111 - return false;
112 - }
113 -
114 - $target_dir = $wp_filesystem->find_folder(WTSEC_PLUGIN_PATH);
115 - $target_file = trailingslashit($target_dir) . 'generate.php';
116 - $content = '<?php echo rand()?>';
117 -
118 - if ($wp_filesystem->put_contents($target_file, $content, FS_CHMOD_FILE)) {
119 - return true;
120 - }
121 -
122 - WTSEC_LIBRARY_Session::setNotification("error", "generate fail");
123 - return false;
124 -}
125 -
126 77 function wtsec_checkStatus($id, $service)
127 78 {
128 79 $service = ucfirst(strtolower($service));
129 80 $is_active = null;
130 81 $config_id = null;
131 - $result = WTSEC_LIBRARY_WT::checkStatus($id, $service);
82 + $result = WTSEC_LIBRARY_WT::checkStatus($id,$service);
132 83 $data = $result['data']['auth']['viewer']['sites']['one']['configs'];
133 - foreach ($data as &$cfg) {
134 - if (!empty($cfg)) {
84 + foreach ($data as &$cfg){
85 + if(!empty($cfg)){
135 86 $is_active = $cfg['isActive'];
136 87 $config_id = $cfg['id'];
137 88 }
138 89 }
@@ -142,52 +93,37 @@
142 93 }
143 94 return ['active' => $is_active, 'config_id' => $config_id];
144 95 }
145 96
97 +
98 +
146 99 function wtsec_generateFile($id, $service)
147 100 {
148 - if ($service === "AM") {
149 - $result = WTSEC_LIBRARY_WT::generateAmFile($id);
150 - if (!isset($result['data']['auth']['am']['install'])) {
151 - $file = ['filename' => null, "body" => null];
152 - } else {
153 - $url = $result['data']['auth']['am']['install'];
154 - $file = WTSEC_LIBRARY_WT::getFileByUrl($url);
155 - if (empty($file)) {
156 - $file = WTSEC_LIBRARY_WT::getFileByUrl($url);
157 - }
158 - }
159 -
160 - $name = $file["filename"];
161 - $file = $file["body"];
162 - } else {
163 - $result = WTSEC_LIBRARY_WT::generateFile($id, $service);
164 - $name = $result['data']['auth']['agents']['generate']['agentName'];
101 + $result = WTSEC_LIBRARY_WT::generateFile($id,$service);
102 + $name = $result['data']['auth']['agents']['generate']['agentName'];
103 + $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
104 + if(empty($file)){
165 105 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
166 - if (empty($file)) {
167 - $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
168 - }
169 106 }
170 -
171 107 return ['file' => $file, 'name' => $name];
172 108 }
173 109
174 -function wtsec_serviceConnect($id, $service, $domain = '')
110 +function wtsec_serviceConnect($id, $service,$domain = '')
175 111 {
176 - $result = WTSEC_LIBRARY_WT::serviceConnect($id, $service);
112 + $result = WTSEC_LIBRARY_WT::serviceConnect($id,$service);
177 113 $status = isset($result['errors']) && !isset($result['data']['auth']['agents']['check']) ? false : true;
178 114 if (!$status) {
179 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
115 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
180 116 }
181 117 return $status;
182 118 }
183 119
184 120
185 -function wtsec_servicePing($service, $domain = '')
121 +function wtsec_servicePing($service,$domain = '')
186 122 {
187 - if ($domain == NULL) return false;
188 - if (stripos($domain, "http") === false) {
189 - $domain = "http://" . $domain;
123 + if($domain == NULL) return false;
124 + if(mb_stripos($domain,"http") === false){
125 + $domain = "http://".$domain;
190 126 }
191 127 $args = [
192 128 'timeout' => '10',
193 129 'sslverify' => false,
@@ -192,71 +128,78 @@
192 128 'timeout' => '10',
193 129 'sslverify' => false,
194 130 'redirection' => 3,
195 131 ];
196 - $response = wp_remote_get($domain, $args);
132 + $response = wp_remote_get($domain,$args);
197 133 $httpcode = wp_remote_retrieve_response_code($response);
198 - if ($httpcode >= 200 && $httpcode < 400) {
134 + if($httpcode>=200 && $httpcode<400){
199 135 return true;
200 136 } else {
201 - WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
137 + WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
202 138 return false;
203 139 }
204 140 }
205 141
206 -function wtsec_button($label = '', $class = '')
207 -{
208 - return '<button class="ww-button ' . $class . '">' . $label . '</button>';
142 +function wtsec_button($label = '',$class = ''){
143 + return '<button class="ww-button '.$class.'">'.$label.'</button>';
209 144 }
210 145
211 -function wtsec_main_button($label = '', $class = '')
212 -{
213 - return '<button class="ww-button ' . $class . '">' . $label . '</button>';
146 +function wtsec_main_button($label = '',$class = ''){
147 + return '<button class="ww-button '.$class.'">'.$label.'</button>';
214 148 }
215 149
216 -function wtsec_generateButtons($uid, $_service, $service, $status, $domain = '')
150 +function wtsec_generateButtons($uid,$_service, $service, $status,$domain = '')
217 151 {
218 152 $url = esc_url(admin_url('admin-post.php'));
219 153 $buttons = [];
220 154
221 - $form = '<form action="' . $url . '" method="post" style="display:inline-block;">
222 - <input type="hidden" name="service" value="' . $_service . '">
155 + $form = '<form action="'.$url.'" method="post" style="display:inline-block;">
156 + <input type="hidden" name="service" value="'.$_service.'">
223 157 <input type="hidden" name="action" value="ajax_cmd">
224 - <input type="hidden" name="uid" value="' . $uid . '">
158 + <input type="hidden" name="uid" value="'.$uid.'">
225 159 <input type="hidden" name="cmd" value="{{{cmd}}}">{{{button}}}</form>';
226 160 $result = [];
227 161 $installedFile = wtsec_checkInstalledFile($_service);
162 + $runned = $status['active'];
163 +
164 + if($service === "WAF"){
165 + $first_class = "";
166 + }else{
167 + $first_class = "ww-button--block ";
168 + }
228 169 $disable_uninstall = false;
229 - $first_class = "ww-button--block ";
230 -
231 - if ($service === "AM") {
232 - if (!$installedFile['status']) {
233 - $cmd = $_service . '_install';
234 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
170 + if (!$installedFile['status']) {
171 + $cmd = $_service . '_install';
172 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'),$first_class."ww-button--success"),'cmd' => $cmd];
173 + } else {
174 + if($service === "WAF"){
175 + $url = $domain.'/?ping='.$installedFile['file'];
176 + }else{
177 + $url = $domain.'/'.$installedFile['file'];
178 + }
179 + $connected = wtsec_servicePing($service,$url);
180 + if (!$connected) {
181 + $disable_uninstall = false;
182 + $cmd = $_service . '_connect';
183 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('connect'),$first_class."ww-button--success"),'cmd' => $cmd];
235 184 } else {
236 -// $url = $domain.'/'.$installedFile['file'];
237 -// $connected = wtsec_servicePing($service,$url);
238 - if (!$disable_uninstall) {
239 - $cmd = $_service . '_uninstall';
240 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'), $first_class . "ww-button--attention"), 'cmd' => $cmd];
185 + if ($runned) {
186 + $cmd = $_service . '_stop';
187 +// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('stop'),"ww-button--primary"),'cmd' => $cmd];
188 + } else {
189 + $cmd = $_service . '_start';
190 +// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('run'),"ww-button--primary"),'cmd' => $cmd];
241 191 }
242 192 }
243 - } else {
244 - if ($service === "WAF") {
245 - $first_class = "";
193 + if(!$disable_uninstall){
194 + $cmd = $_service . '_uninstall';
195 + $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'),$first_class."ww-button--attention"),'cmd' => $cmd];
246 196 }
247 -
248 - if ($status === "not_installed") {
249 - $cmd = $_service . '_install';
250 - $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
251 - }
252 197 }
253 -
254 -
255 - foreach ($buttons as $btn) {
198 + foreach ($buttons as $btn){
256 199 $newform = $form;
257 - $newform = str_replace("{{{cmd}}}", $btn['cmd'], $newform);
258 - $newform = str_replace("{{{button}}}", $btn['button'], $newform);
200 + $newform = str_replace("{{{cmd}}}",$btn['cmd'],$newform);
201 + $newform = str_replace("{{{button}}}",$btn['button'],$newform);
259 202 $result[$btn['place']] = $newform;
260 203 }
261 204 return $result;
262 205 }
@@ -263,16 +206,10 @@
263 206
264 207 function wtsec_checkInstalledFile($service)
265 208 {
266 209 $file = wtsec_getInstalledFile($service);
267 - if ($service == "waf") {
268 - $root = WTSEC_INSTALLATION_DIR;
269 - } else {
270 - $root = ABSPATH;
271 - }
272 - return ['status' => ((bool)$file) && is_file($root . $file), 'file' => $file];
210 + return ['status' => (bool) $file,'file' => $file];
273 211 }
274 212
275 -function wtsec_getInstalledFile($service)
276 -{
277 - return wtsec_app()->get($service . "_installed_file");
213 +function wtsec_getInstalledFile($service){
214 + return wtsec_app()->get($service."_installed_file");
278 215 }