PluginProbe
WebTotem Security / 2.3.24
WebTotem Security v2.3.24
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | routes.php +823 -344 2.2.1 → 2.3.24 View file →
@@ -2,9 +2,11 @@
2 2
3 3 add_action('admin_menu', 'wtsec_add_menu_link');
4 4 add_action('wp_ajax_change_status', 'wtsec_ajax_changeStatus');
5 5 add_action('admin_post_change_status', 'wtsec_changeStatus');
6 -add_action('admin_post_login_form', 'wtsec_login_form');
6 +add_action('admin_post_wtsec_login_form', 'wtsec_login_form');
7 +add_action('wp_ajax_waf_add_ip_to_list', 'wtsec_waf_add_ip_to_list');
8 +add_action('wp_ajax_waf_remove_ip_to_list', 'wtsec_waf_remove_ip_to_list');
7 9 add_action('wp_ajax_cmd', 'wtsec_cmd_ajax');
8 10 add_action('admin_post_ajax_cmd', 'wtsec_cmd_ajax');
9 11 add_action('wp_ajax_ajax_firewall', 'wtsec_ajax_firewall');
10 12 add_action('wp_ajax_ajax_antivirus', 'wtsec_ajax_antivirus');
@@ -10,8 +12,22 @@
10 12 add_action('wp_ajax_ajax_antivirus', 'wtsec_ajax_antivirus');
11 13 add_action('wp_ajax_chart_filter', 'wtsec_chart_filter');
12 14 add_action('wp_ajax_map_filter', 'wtsec_map_filter');
13 15 add_action('wp_ajax_color_scheme_toggle', 'wtsec_color_scheme');
16 +add_action('wp_ajax_configs_toggle', 'wtsec_configs_toggle');
17 +add_action('wp_ajax_generate_report', 'wtsec_generate_report');
18 +add_action('wp_ajax_ajax_reports', 'wtsec_ajax_reports');
19 +add_action('wp_ajax_report_link', 'wtsec_report_link');
20 +add_action('wp_ajax_settings', 'wtsec_settings');
21 +add_action('wp_ajax_move_to_quarantine', 'wtsec_move_to_quarantine');
22 +add_action('wp_ajax_move_from_quarantine', 'wtsec_move_from_quarantine');
23 +add_action('wp_ajax_reinstall', 'wtsec_reinstall');
24 +add_action('wp_ajax_setTimeZone', 'wtsec_setTimeZone');
25 +add_action('wp_ajax_waf_settings', 'wtsec_waf_settings');
26 +add_action('wp_ajax_notification', 'wtsec_notification');
27 +add_action('wp_ajax_refresh_index', 'wtsec_index_page');
28 +add_action('wp_ajax_rescan', 'wtsec_force_check_av');
29 +add_action('wp_ajax_av_export', 'wtsec_av_export');
14 30
15 31
16 32 function wtsec_add_menu_link()
17 33 {
@@ -20,10 +36,10 @@
20 36 WTSEC_MENU_TITLE,
21 37 'manage_options',
22 38 wtsec_getRoute('dashboard'),
23 39 'wtsec_index_page',
24 - '',
25 - '1'
40 + wtsec_getImagePath('logo_17x17_w.png'),
41 + '80.8'
26 42 );
27 43 $parent = wtsec_getRoute('dashboard');
28 44 if (WTSEC_LIBRARY_App::authorized()) {
29 45 $capability = 'manage_options';
@@ -43,18 +59,10 @@
43 59 add_submenu_page(null, WTSEC_LIBRARY_Localization::lmsg('logout'), WTSEC_LIBRARY_Localization::lmsg('logout'), 'manage_options', wtsec_getRoute('logout'), 'wtsec_logout');
44 60 }
45 61 }
46 62
47 -function dd($vl)
63 +function wtsec_myGrading($score)
48 64 {
49 - echo '<pre>';
50 - print_r($vl);
51 - echo '</pre>';
52 - die();
53 -}
54 -
55 -function myGrading($score)
56 -{
57 65 if ($score < 0 || $score > 100) return ['grade' => '','color' => ''];
58 66 $scores = [100 => 'A+', 90 => 'A', 80 => 'A-', 70 => 'B+', 60 => 'B', 50 => 'B-', 35 => 'C+', 20 => 'C', 0 => 'C-' ];
59 67 foreach ($scores as $key => $value){
60 68 if($score >= $key){
@@ -62,9 +70,9 @@
62 70 break;
63 71 }
64 72 }
65 73
66 - $color = ($score >= 80) ? 'green' : ($score >= 50) ? 'orange' : 'red';
74 + $color = ($score >= 80) ? 'green' : (($score >= 50) ? 'orange' : 'red');
67 75
68 76 return ['grade' => $grade,'color' => $color];
69 77 }
70 78
@@ -70,8 +78,12 @@
70 78
71 79
72 80 function convertTimeToReadable($date)
73 81 {
82 + if(!$date){
83 + return WTSEC_LIBRARY_Localization::lmsg('unknown');
84 + }
85 +
74 86 $lang = get_locale();
75 87 //enable russian language
76 88 if ($lang === "ru_RU") {
77 89 $lang .= ".UTF-8";
@@ -79,9 +91,14 @@
79 91 }
80 92 if(strpos($date, ".") !== false){
81 93 $date = substr($date, 0, strpos($date, "."));
82 94 }
83 - return strftime("%B %e, %Y / %R", strtotime($date." UTC"));
95 +
96 + $time_zone = WTSEC_LIBRARY_App::_get('time_zone');
97 + $userTime = ($time_zone) ? strtotime( $time_zone . 'hours', strtotime($date)) : strtotime($date);
98 +
99 + return date_i18n('F j, Y \/ H:i', $userTime);
100 + //return strftime("%B %e, %Y / %R", strtotime($date." UTC"));
84 101 }
85 102
86 103
87 104 function convertToCurrentTime($date)
@@ -95,14 +112,25 @@
95 112 if(strpos($date, ".") !== false){
96 113 $date = substr($date, 0, strpos($date, "."));
97 114 }
98 115 $date .= " UTC";
99 - $current_time = strtotime($date);
100 - return ['date' => date("Y-m-d", $current_time),'time' => date("H:i:s",$current_time)];
116 +
117 + $time_zone = WTSEC_LIBRARY_App::_get('time_zone');
118 + $userTime = ($time_zone) ? strtotime($time_zone . 'hours', strtotime($date)) : strtotime($date);
119 +
120 + return ['date' => date("Y-m-d", $userTime),'time' => date("H:i:s",$userTime)];
101 121 }
102 122
123 +
103 124 function wtsec_index_page()
104 125 {
126 + $ajax = false;
127 + if (wtsec_request()->method === "POST") {
128 + if(wtsec_request()->ajax){
129 + $ajax = true;
130 + }
131 + }
132 +
105 133 $host = WTSEC_LIBRARY_WT::getOwnSite();
106 134
107 135 $services = [];
108 136 if (!empty($host)) {
@@ -108,8 +136,9 @@
108 136 if (!empty($host)) {
109 137 $services = [
110 138 "settings" => [
111 139 "token" => WTSEC_LIBRARY_App::getToken(),
140 + "email" => WTSEC_LIBRARY_WT::getEmail(),
112 141 "site_id" => $host['id'],
113 142 ],
114 143 "score" => [
115 144 "total_score" => 0,
@@ -119,222 +148,267 @@
119 148 "description" => wtsec_locale("score.description"),
120 149 "information" => "",
121 150 "grade" => "",
122 151 ],
152 + 'wafTraining' => true,
123 153 ];
124 154
125 - $score = json_decode(WTSEC_LIBRARY_WT::getScore(), true);
126 - if (!empty($score)) {
127 - $total_score = round($score['totalScore']);
128 - $my_grading = myGrading($total_score);
129 - $services["score"] = [
130 - "total_score" => $total_score."%",
131 - "tested_on" => convertTimeToReadable($score['date']),
132 - "server_ip" => $score['ip'],
133 - "location" => $score['country'],
134 - "description" => wtsec_locale("score.description"),
135 - "information" => wtsec_locale("score.higher_than_percent", ['percent' => $score['ishigherthan']]),
136 - "grade" => $my_grading['grade'],
137 - "color" => $my_grading['color'],
138 - ];
155 + $checks = WTSEC_LIBRARY_WT::getAllChecks($host['id']);
156 + $services = wtsec_dashboard_getData($checks, $services, $host);
157 +
158 + }
159 +
160 + if(!$ajax){
161 + wtsec_layout("dashboard", $services);
162 + } else {
163 + wtsec_layout_part("dashboard", $services,false);
164 + wp_die();
165 + }
166 +}
167 +
168 +function wtsec_dashboard_getData($checks, $services, $host){
169 + foreach ($checks as $service => $site) {
170 + if (empty($site) || !is_array($site)) {
171 + continue;
139 172 }
140 173
141 - $checks = WTSEC_LIBRARY_WT::getAllChecks($host['id']);
142 - foreach ($checks as $service => $site) {
143 - if (empty($site) || !is_array($site)) {
144 - continue;
145 - }
146 - switch ($service) {
147 - case "availability":
148 - $services["wa"] = [
174 + switch ($service) {
175 + case "scoring":
176 + $total_score = round($site['score']);
177 + $my_grading = wtsec_myGrading($total_score);
178 + $services["score"] = [
179 + "total_score" => $total_score."%",
180 + "tested_on" => convertTimeToReadable($site['lastTest']['time']),
181 + "server_ip" => $site['result']['ip'],
182 + "location" => $site['result']['country'],
183 + "description" => wtsec_locale("score.description"),
184 + "information" => wtsec_locale("score.higher_than_percent", ['percent' => $site['result']['isHigherThan']]),
185 + "grade" => $my_grading['grade'],
186 + "color" => $my_grading['color'],
187 + ];
188 + break;
189 +
190 +
191 + case "serverStatus":
192 + $services["serverStatus"] = [
193 + "info" => $site['info'],
194 + "ramChart" => (!empty($site['ramChart']))?wtsec_chartData($site['ramChart'],7):false,
195 + "cpuChart" => (!empty($site['cpuChart']))?wtsec_chartData($site['cpuChart'],7):false,
196 +
197 + "discUsage" => $site['discUsage'],
198 + ];
199 + $services["serverStatus"]['discUsage']['use'] = $site['discUsage']['total'] - $site['discUsage']['free'];
200 + break;
201 +
202 +
203 + case "availability":
204 + $services["wa"] = [
149 205 // "pause" => wtsec_getStatusStartPauseIcon($site['config']['isActive'], $site['config']['id'], $host['id']),
150 - "pause" => "",
151 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
152 - "response_time" => ceil($site['responseTime'] / 1000000) . ' ' . WTSEC_LIBRARY_Localization::lmsg('ms'),
153 - "availability" => $site['percent'] . '%',
154 - "availability_percent" => $site['percent'],
155 - "last_test" => convertTimeToReadable($site['lastTest']['time']),
156 - "downtime" => ceil($site['downTime'] / 1000000) . ' ' . WTSEC_LIBRARY_Localization::lmsg('ms'),
157 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.availability')
158 - ];
159 - break;
160 - case "ssl":
161 - if ((int)$site['expiryDate'] === 0) {
162 - $days_left = 0;
163 - } else {
164 - $earlier = new DateTime();
165 - $later = new DateTime($site['expiryDate']);
166 - $days_left = $later->diff($earlier)->format("%a");
167 - }
168 - $services["ssl"] = [
169 - "pause" => "",
170 - "information" => wtsec_getInformation($service, $site['status']),
171 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
172 - "days_left" => $days_left,
173 - "issue_date" => convertTimeToReadable($site['issueDate']),
174 - "expiry_date" => convertTimeToReadable($site['expiryDate']),
175 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.ssl'),
176 - "solve_it" => in_array($site['status'],['clean','pending']) ? '' : wtsec_locale('solve_it'),
177 - ];
178 - break;
179 - case "domain":
180 - if ((int)$site['expiredDate'] === 0) {
181 - $days_left = 0;
182 - } else {
183 - $earlier = new DateTime();
184 - $later = new DateTime($site['expiredDate']);
185 - $days_left = $later->diff($earlier)->format("%a");
186 - }
206 + "pause" => "",
207 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
208 + "response_time" => ceil($site['responseTime'] / 1000000) . ' ' . WTSEC_LIBRARY_Localization::lmsg('ms'),
209 + "availability" => $site['percent'] . '%',
210 + "availability_percent" => $site['percent'],
211 + "last_test" => convertTimeToReadable($site['lastTest']['time']),
212 + "downtime" => ceil($site['downTime'] / 1000000) . ' ' . WTSEC_LIBRARY_Localization::lmsg('ms'),
213 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.availability')
214 + ];
215 + break;
216 + case "ssl":
217 + if ((int)$site['expiryDate'] === 0) {
218 + $days_left = 0;
219 + } else {
220 + $earlier = new DateTime();
221 + $later = new DateTime($site['expiryDate']);
222 + $days_left = $later->diff($earlier)->format("%a");
223 + }
224 + $services["ssl"] = [
225 + "pause" => "",
226 + "information" => wtsec_getInformation($service, $site['status']),
227 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
228 + "days_left" => $days_left,
229 + "issue_date" => convertTimeToReadable($site['issueDate']),
230 + "expiry_date" => convertTimeToReadable($site['expiryDate']),
231 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.ssl'),
232 + "solve_it" => in_array($site['status'],['clean','pending']) ? '' : wtsec_locale('solve_it'),
233 + ];
234 + break;
235 + case "domain":
236 + if ((int)$site['expiredDate'] === 0) {
237 + $days_left = 0;
238 + } else {
239 + $earlier = new DateTime();
240 + $later = new DateTime($site['expiredDate']);
241 + $days_left = $later->diff($earlier)->format("%a");
242 + }
187 243
188 - $services["dec"] = [
189 - "pause" => "",
190 - "registrar" => $site['registrar'],
191 - "owner" => $site['owner'],
192 - "information" => wtsec_getInformation($service, $site['status']),
193 - "email" => $site['email'],
194 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
195 - "days_left" => $days_left,
196 - "created" => convertTimeToReadable($site['createdDate']),
197 - "expiry_date" => convertTimeToReadable($site['expiredDate']),
198 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.domain')
199 - ];
200 - break;
201 - case "reputation":
202 - $count = 0;
203 - if ($site['status'] != "clean") {
204 - foreach ($site['virusList'] as &$list) {
205 - if (!empty($list['virus']['type'])) {
206 - $count++;
207 - }
244 + $services["dec"] = [
245 + "pause" => "",
246 + "registrar" => $site['registrar'],
247 + "owner" => $site['owner'],
248 + "information" => wtsec_getInformation($service, $site['status']),
249 + "email" => $site['email'],
250 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
251 + "days_left" => $days_left,
252 + "created" => convertTimeToReadable($site['createdDate']),
253 + "expiry_date" => convertTimeToReadable($site['expiredDate']),
254 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.domain')
255 + ];
256 + break;
257 + case "reputation":
258 + $count = 0;
259 + if ($site['status'] != "clean") {
260 + foreach ($site['virusList'] as &$list) {
261 + if (!empty($list['virus']['type'])) {
262 + $count++;
208 263 }
209 264 }
210 - $services["av"] = [
211 - "pause" => "",
212 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
213 - "time_of_the_last_test" => convertTimeToReadable($site['lastTest']['time']),
214 - "blacklists_entries" => $count,
215 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.reputation'),
216 - "reputation" => $site['status'] === "infected" ? wtsec_locale('bad_reputation') : wtsec_locale('good_reputation'),
217 - ];
218 - break;
219 - case "maliciousScript":
220 - $services["cms"] = [
221 - "pause" => "",
222 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
223 - "time_of_the_last_test" => $site['lastTest']['time'],
224 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.malicious')
225 - ];
226 - break;
227 - case "deface":
228 - $services["dc"] = [
229 - "pause" => "",
230 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
231 - "time_of_the_last_test" => convertTimeToReadable($site['lastTest']['time']),
232 - "number" => $site['count'],
233 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.deface')
234 - ];
235 - break;
236 - case "ports":
237 - $services["ps"] = [
238 - "pause" => "",
239 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
240 - "ip" => $site['ip'],
241 - "last_test" => convertTimeToReadable($site['lastTest']['time']),
242 - "number" => count($site['tcp']),
243 - "tcp" => !empty($site['tcp']) ? implode(",", $site['tcp']) : '',
244 - "udp" => "",
245 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.port')
246 - ];
247 - break;
248 - case "firewall":
249 - $service = "WAF";
250 - $_service = strtolower($service);
251 - $domain = $host['hostname'];
252 - $uid = $host['id'];
265 + }
266 + $status_text = wtsec_locale('na_reputation');
267 + if($site['status'] === "infected") $status_text = wtsec_locale('bad_reputation');
268 + if($site['status'] === "clean") $status_text = wtsec_locale('good_reputation');
253 269
254 - $chart = generateChart($site['chart'], 30);
270 + $services["av"] = [
271 + "pause" => "",
272 + 'status_' => $site['status'],
273 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
274 + "time_of_the_last_test" => convertTimeToReadable($site['lastTest']['time']),
275 + "blacklists_entries" => $count,
276 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.reputation'),
277 + "reputation" => $status_text,
278 + ];
279 + break;
280 + case "maliciousScript":
281 + $services["cms"] = [
282 + "pause" => "",
283 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
284 + "time_of_the_last_test" => $site['lastTest']['time'],
285 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.malicious')
286 + ];
287 + break;
288 + case "deface":
289 + $services["dc"] = [
290 + "pause" => "",
291 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
292 + "time_of_the_last_test" => convertTimeToReadable($site['lastTest']['time']),
293 + "number" => $site['count'],
294 + "words" => !empty($site['words']) ? implode(",", $site['words']) : '',
295 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.deface')
296 + ];
297 + break;
298 + case "ports":
299 + $services["ps"] = [
300 + "pause" => "",
301 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
302 + "ip" => $site['ip'],
303 + "last_test" => convertTimeToReadable($site['lastTest']['time']),
304 + "number" => count($site['tcp']),
305 + "tcp" => !empty($site['tcp']) ? implode(",", $site['tcp']) : '',
306 + "udp" => "",
307 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.port')
308 + ];
309 + break;
310 + case "firewall":
311 + $service = "WAF";
312 + $_service = strtolower($service);
313 + $domain = $host['hostname'];
314 + $uid = $host['id'];
315 +
316 + $chart = wtsec_generateChart($site['chart'], 30);
255 317 // $status = wtsec_checkStatus($uid, $service);
256 318
257 - $data = WTSEC_LIBRARY_WT::getFirewall($host['id']);
258 - $data = $data['data']['auth']['viewer']['sites']['one']['firewall'];
319 + $countryAttacks = wtsec_getCountryAttacks($site['map'], $chart['count_attacks']);
320 + $edges = $site['logs']['edges'];
259 321
260 - $countryAttacks = getCountryAttacks($data['map'], $chart['count_attacks']);
261 - $edges = $data['logs']['edges'];
322 + $services["waf"] = [
323 + "pause" => "",
324 + "site_address" => $domain,
325 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
326 + "_status" => $site['status'],
327 + "installed_status" => in_array($site['status'], ["not_installed", "error", "down", "not_supported", "not_registered"]) ? false : true,
328 + "time_of_the_last_check" => convertTimeToReadable($site['lastTest']['time']),
329 + "attacks" => $chart['count_attacks'],
330 + "blocking" => $chart['count_blocks'],
331 + "non-blocking" => $chart['count_attacks'] - $chart['count_blocks'],
332 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.firewall'),
333 + "actions" => wtsec_generateButtons($uid, $_service, $service, $site['status'], WTSEC_SITE_URL),
334 + "chart" => $chart['chart'],
335 + "edges" => $edges,
336 + "countryAttacks" => $countryAttacks,
337 + "hasNextPage" => null,
338 + ];
339 + break;
340 + case "agentManager":
341 + $wafTestingTime = strtotime('+2 day',strtotime($site['createdAt']));
342 + $today = strtotime('today');
343 + $services["wafTraining"] = ($wafTestingTime < $today) ? false : true;
262 344
263 - $services["waf"] = [
264 - "pause" => "",
265 - "site_address" => $domain,
266 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
267 - "_status" => $site['status'],
268 - "installed_status" => in_array($site['status'], ["not_installed", "error", "down", "not_supported", "not_registered"]) ? false : true,
269 - "time_of_the_last_check" => convertTimeToReadable($site['lastTest']['time']),
270 - "attacks" => $chart['count_attacks'],
271 - "blocking" => $chart['count_blocks'],
272 - "non-blocking" => $chart['count_attacks'] - $chart['count_blocks'],
273 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.firewall'),
274 - "actions" => wtsec_generateButtons($uid, $_service, $service, $site['status'], WTSEC_SITE_URL),
275 - "chart" => json_encode($chart['chart'], true),
276 - "edges" => $edges,
277 - "countryAttacks" => $countryAttacks,
278 - ];
279 - break;
280 - case "antivirus":
281 - $service = "AV";
282 - $_service = strtolower($service);
283 - $domain = $host['hostname'];
284 - $uid = $host['id'];
345 + break;
346 + case "antivirus":
347 + $service = "AV";
348 + $_service = strtolower($service);
349 + $domain = $host['hostname'];
350 + $uid = $host['id'];
285 351 // $status = wtsec_checkStatus($uid, $service);
286 - $services["vc"] = [
287 - "pause" => "",
288 - "site_address" => $domain,
289 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
290 - "installed_status" => in_array($site['status'], ["not_installed", "error", "down", "not_supported", "not_registered"]) ? false : true,
291 - "_status" => $site['status'],
292 - "signatures" => (int)$site['stats']['infected'],
293 - "changes" => (int)$site['stats']['changed'],
294 - "scanned" => (int)$site['stats']['scaned'],
295 - "deleted" => (int)$site['stats']['deleted'],
296 - "list" => $site['stats']["infected"],
297 - "actions" => wtsec_generateButtons($uid, $_service, $service, $site['status'], WTSEC_SITE_URL),
298 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.antivirus')
299 - ];
300 - break;
301 - }
352 + $services["vc"] = [
353 + "pause" => "",
354 + "site_address" => $domain,
355 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
356 + "installed_status" => in_array($site['status'], ["not_installed", "error", "down", "not_supported", "not_registered"]) ? false : true,
357 + "_status" => $site['status'],
358 + "signatures" => (int)$site['stats']['infected'],
359 + "changes" => (int)$site['stats']['changed'],
360 + "scanned" => (int)$site['stats']['scaned'],
361 + "deleted" => (int)$site['stats']['deleted'],
362 + "list" => $site['stats']["infected"],
363 + "actions" => wtsec_generateButtons($uid, $_service, $service, $site['status'], WTSEC_SITE_URL),
364 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.antivirus'),
365 + "hasNextPage" => null
366 + ];
367 + break;
302 368 }
369 + }
303 370
304 - //check AM, if not installed , run install
305 - $process = "installing";
306 - $check_am_file = wtsec_checkInstalledFile("AM");
307 - $am_installed = $check_am_file["status"];
308 - $am_installed_status = wtsec_app()->get('am_installed');
371 + //check AM, if not installed , run install
372 + $process = "installing";
373 + $check_am_file = wtsec_checkInstalledFile("am");
374 + $am_installed = $check_am_file["status"];
375 + $am_installed_status = wtsec_app()->get('am_installed');
309 376
310 - if (!$am_installed || !$am_installed_status) {
311 - $am_is_installed = wtsec_cmd("am_install", "AM", "am", $host['id'], [], WTSEC_SITE_URL);
312 - if (!$am_is_installed) {
313 - $process = "failed";
314 - wtsec_app()->set('am_installed', false);
315 - } else {
316 - wtsec_app()->set('am_installed', true);
317 - }
318 - } elseif ($services["vc"]["_status"] === "not_installed" || $services["waf"]["_status"] === "not_installed") {
319 - $process = "installing";
377 + if (!$am_installed || !$am_installed_status) {
378 + $am_is_installed = wtsec_cmd("am_install", "AM", "am", $host['id'], [], WTSEC_SITE_URL);
379 + if (!$am_is_installed) {
380 + $process = "failed";
381 + wtsec_app()->set('am_installed', false);
320 382 } else {
321 - $process = "installed";
383 + wtsec_app()->set('am_installed', true);
322 384 }
385 + } elseif ($services["vc"]["_status"] === "not_installed" || !$services["vc"]["_status"] ||
386 + $services["waf"]["_status"] === "not_installed"|| !$services["waf"]["_status"] ||
387 + !isset($services["vc"]["_status"]) || !isset($services["waf"]["_status"])) {
388 + $process = "installing";
389 + } else {
390 + $process = "installed";
391 + }
323 392
324 - $services["am"] = [
325 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($am_installed ? "working" : "not_installed"),
326 - "actions" => wtsec_generateButtons($host['id'], "am", "AM", ["active" => $check_am_file], WTSEC_SITE_URL),
327 - "process_status" => $process,
328 - "installed" => $am_installed,
329 - ];
330 - }
393 + $services["am"] = [
394 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($am_installed ? "working" : "not_installed"),
395 + "actions" => wtsec_generateButtons($host['id'], "am", "AM", ["active" => $check_am_file], WTSEC_SITE_URL),
396 + "process_status" => $process,
397 + "installed" => $am_installed,
398 + ];
331 399
332 - wtsec_layout("dashboard", $services);
400 + return $services;
333 401 }
334 402
335 -function getCountryAttacks($map, $countAttacks){
403 +function wtsec_reinstall(){
404 + wtsec_app()->set('am_installed', false);
405 + echo wtsec_getUrl('dashboard');
406 + wp_die();
407 +}
336 408
409 +function wtsec_getCountryAttacks($map, $countAttacks){
410 +
337 411 if($map){
338 412 $attackKey = array_search(max(array_column($map, 'attacks')), array_column($map, 'attacks'));
339 413 $map[$attackKey]['percent'] = ($countAttacks) ? round($map[$attackKey]['attacks'] / $countAttacks * 100) : 0;
340 414 $map[$attackKey]['country'] = wtsec_getCountryName($map[$attackKey]['country']);
@@ -341,11 +415,11 @@
341 415 return $map[$attackKey];
342 416 }
343 417
344 418 return ['percent' => 0, 'country' => false];
419 +}
345 420
346 -}
347 -function getAttacksMap($map){
421 +function wtsec_getAttacksMap($map){
348 422 $attacks = [];
349 423 $countries = [];
350 424 foreach ($map as $value){
351 425 $attacks[] = $value['attacks'];
@@ -353,65 +427,64 @@
353 427 }
354 428 return ['attacks' => $attacks, 'countries' => $countries];
355 429 }
356 430
357 -
358 -function generateChart($charts, $days = 7)
431 +// Server Status chart
432 +function wtsec_chartData($charts, $days)
359 433 {
360 434
361 - if(is_array($days)) {
362 - $beginDate = new DateTime( $days['begin'] );
363 - $endDate = new DateTime( $days['end'] );
364 - $dateDiff = strtotime($days['end'] - strtotime($days['begin']));
365 - $days = floor($dateDiff / (60 * 60 * 24));
435 + $sum = 0;
436 + foreach ($charts as $chart){
437 + $sum += $chart['value'];
366 438 }
439 + if($sum == 0){
440 + return false;
441 + }
367 442
368 - if($days <= 1){
369 - $begin = new DateTime( date('Y-m-d 00:00:00') );
370 - $end = new DateTime( date('Y-m-d 23:59:59') );
371 - $step = 'hour';
372 - } elseif($days <= 31){
373 - $begin = new DateTime( date('Y-m-d', strtotime('-'.($days - 1).' day')) );
374 - $end = new DateTime( date('Y-m-d') );
375 - $step = 'day';
376 - } else {
377 - $begin = new DateTime( date('Y-m-01', strtotime('- 11 month')) );
378 - $end = new DateTime( date('Y-m-01', time()) );
379 - $step = 'month';
443 + if($days <= 1) {$time_zone = WTSEC_LIBRARY_App::_get('time_zone');}
444 + $result = [];
445 + foreach ($charts as $chart){
446 + if($days <= 1) {$userTime = ($time_zone) ? strtotime( $time_zone . 'hours', strtotime($chart['time'])) : strtotime($chart['time']);}
447 + $result[] = [
448 + 'date' => ($days <= 1) ? date("Y-m-d H:00:00", $userTime) : date("Y-m-d", strtotime($chart['time'])),
449 + 'value' => $chart['value'],
450 + ];
380 451 }
381 452
453 + return json_encode($result, true);
454 +}
382 455
456 +// WAF chart
457 +function wtsec_generateChart($charts, $days = 7)
458 +{
459 + $sum = 0;
460 + foreach ($charts as $chart){
461 + $sum += $chart['attacks'];
462 + }
463 + if($sum == 0){
464 + return ['chart' => false, 'count_attacks' => 0, 'count_blocks' => 0];
465 + }
466 +
467 + $result = [];
383 468 $count_attacks = 0;
384 469 $count_blocks = 0;
385 - $c = [];
386 470
387 - for($i = $begin; $i <= $end; $i->modify('+1 '.$step)){
471 + if($days <= 1) {$time_zone = WTSEC_LIBRARY_App::_get('time_zone');}
388 472
389 - $c[$i->format('U')] = [
390 - 'date' => ($days <= 1) ? $i->format("Y-m-d H:00:00") : $i->format("Y-m-d"),
391 - 'count' => 0,
392 - 'attacks' => 0,
393 - 'blocked' => 0,
473 + foreach ($charts as $chart){
474 + if($days <= 1) {$userTime = ($time_zone) ? strtotime( $time_zone . 'hours', strtotime($chart['time'])) : strtotime($chart['time']);}
475 + $result[] = [
476 + 'date' => ($days <= 1) ? date("Y-m-d H:00:00", $userTime) : date("Y-m-d", strtotime($chart['time'])),
477 + 'count' => $chart['blocked'],
478 + 'attacks' => $chart['attacks'],
479 + 'blocked' => $chart['blocked'],
394 480 ];
395 - }
396 -
397 - foreach ($charts as $chart) {
398 - $d = strtotime($chart['time']);
399 - $c[$d]['count'] = $chart['blocked'];
400 - $c[$d]['attacks'] = $chart['attacks'];
401 - $c[$d]['blocked'] = $chart['blocked'];
402 481 $count_attacks += $chart['attacks'];
403 482 $count_blocks += $chart['blocked'];
404 483 }
405 484
406 485
407 - //unset keys, because the js parser sorting by key in integer
408 - $result = [];
409 - foreach ($c as $d) {
410 - $result[] = $d;
411 - }
412 -
413 - return ['chart' => $result, 'count_attacks' => $count_attacks, 'count_blocks' => $count_blocks];
486 + return ['chart' => json_encode($result), 'count_attacks' => $count_attacks, 'count_blocks' => $count_blocks];
414 487 }
415 488
416 489 function wtsec_getInformation($service, $status)
417 490 {
@@ -447,24 +520,21 @@
447 520 }
448 521
449 522 function wtsec_options_page()
450 523 {
524 + $options = [];
451 525 $host = WTSEC_LIBRARY_WT::getOwnSite();
452 - $result = WTSEC_LIBRARY_WT::getOptions($host['id']);
453 - $options = [];
454 - if (isset($result['data']['userHost']['services'])) {
455 - foreach ($result['data']['userHost']['services'] as $service) {
456 - $configs = $service['configs'][0];
457 - $options[$service['name']] = ['config_id' => $configs['id'], 'is_active' => $configs['isActive']];
458 - }
526 + if(!empty($host)){
527 + $options = wtsec_getConfigs($host['id']);
528 + $options['settings']['login_attempt'] = WTSEC_LIBRARY_App::_get('check_login_attempt');
459 529 }
460 - $options['host_id'] = $host['id'];
530 +
461 531 wtsec_layout("options", $options);
462 532 }
463 533
464 -function wtsec_services_page()
534 +function wtsec_information_page()
465 535 {
466 - wtsec_layout("services");
536 + wtsec_layout("information");
467 537 }
468 538
469 539 function wtsec_antivirus_page()
470 540 {
@@ -470,38 +540,61 @@
470 540 {
471 541 $host = WTSEC_LIBRARY_WT::getOwnSite();
472 542 $services = [];
473 543 if (!empty($host)) {
474 - $site = WTSEC_LIBRARY_WT::getAntivirus($host['id']);
475 - if (isset($site['data']['auth']['viewer']['sites']['one']['antivirus']['log'])) {
476 - $site = $site['data']['auth']['viewer']['sites']['one']['antivirus'];
544 + $services = wtsec_antivirus_getData($host);
545 + }
546 + wtsec_layout("antivirus", $services);
477 547
478 - $_SESSION['antivirus_endCursor'] = $site['log']['pageInfo']['endCursor'];
479 - $_SESSION['antivirus_hasNextPage'] = $site['log']['pageInfo']['hasNextPage'];
548 +}
480 549
481 - $service = "AV";
482 - $_service = strtolower($service);
483 - $domain = $host['hostname'];
484 - $uid = $host['id'];
485 - $status = wtsec_checkStatus($uid, $service);
486 - $services["vc"] = [
487 - "pause" => "",
488 - "site_address" => $domain,
489 - "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
490 - "signatures" => (int)$site['stats']['infected'],
491 - "changes" => (int)$site['stats']['changed'],
492 - "scanned" => (int)$site['stats']['scaned'],
493 - "deleted" => (int)$site['stats']['deleted'],
494 - "list" => $site["log"]['edges'],
495 - "actions" => $buttons = wtsec_generateButtons($uid, $_service, $service, $status, WTSEC_SITE_URL),
496 - "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.antivirus')
497 - ];
498 - }
550 +
551 +
552 +function wtsec_antivirus_getData($host){
553 +
554 + $params = [
555 + 'host_id' => $host['id'],
556 + 'limit' => 10,
557 + 'endCursor' => null,
558 + 'days' => 365,
559 + 'event' => false,
560 + 'permissionsChanged' => false,
561 + ];
562 +
563 + $site = WTSEC_LIBRARY_WT::getAntivirus($params);
564 + $quarantine = WTSEC_LIBRARY_WT::getQuarantineList($host['id']);
565 + if(isset($quarantine['data']['auth']['viewer']['sites']['one']['antivirus']['quarantine'])){
566 + $services["quarantine"]['list'] = $quarantine['data']['auth']['viewer']['sites']['one']['antivirus']['quarantine'];
567 + $services["quarantine"]['count'] = count($services["quarantine"]['list']);
499 568 }
500 - wtsec_layout("antivirus", $services);
569 + if (isset($site['data']['auth']['viewer']['sites']['one']['antivirus']['log'])) {
570 + $site = $site['data']['auth']['viewer']['sites']['one']['antivirus'];
571 +
572 + WTSEC_LIBRARY_App::_set('antivirus_endCursor', $site['log']['pageInfo']['endCursor']);
573 + WTSEC_LIBRARY_App::_set('antivirus_hasNextPage', $site['log']['pageInfo']['hasNextPage']);
574 +
575 + $service = "AV";
576 + $_service = strtolower($service);
577 + $domain = $host['hostname'];
578 + $uid = $host['id'];
579 + $status = wtsec_checkStatus($uid, $service);
580 + $services["vc"] = [
581 + "pause" => "",
582 + "site_address" => $domain,
583 + "status" => WTSEC_LIBRARY_WT::getStatusIcon($site['status']),
584 + "signatures" => (int)$site['stats']['infected'],
585 + "changes" => (int)$site['stats']['changed'],
586 + "scanned" => (int)$site['stats']['scaned'],
587 + "deleted" => (int)$site['stats']['deleted'],
588 + "list" => wtsec_AVLogsData($site["log"]['edges']),
589 + "actions" => $buttons = wtsec_generateButtons($uid, $_service, $service, $status, WTSEC_SITE_URL),
590 + "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.antivirus'),
591 + "hasNextPage" => $site['log']['pageInfo']['hasNextPage']
592 + ];
593 + }
594 + return $services;
501 595 }
502 596
503 -
504 597 function wtsec_firewall_page()
505 598 {
506 599 $host = WTSEC_LIBRARY_WT::getOwnSite();
507 600 $services = [];
@@ -513,19 +606,17 @@
513 606 $logs = $site['data']['auth']['viewer']['sites']['one']['firewall']['logs'];
514 607 $firewall = $site['data']['auth']['viewer']['sites']['one']['firewall'];
515 608 $edges = $logs['edges'];
516 609
517 - $chart = $chart['data']['auth']['viewer']['sites']['one']['firewall']['chart'];
610 + $chart_ = wtsec_generateChart($chart, 30);
518 611
519 - $chart = generateChart($chart, 30);
520 -
521 612 $domain = $host['hostname'];
522 613
523 - $_SESSION['firewall_endCursor'] = $logs['pageInfo']['endCursor'];
524 - $_SESSION['firewall_hasNextPage'] = $logs['pageInfo']['hasNextPage'];
614 + WTSEC_LIBRARY_App::_set('firewall_endCursor', $logs['pageInfo']['endCursor']);
615 + WTSEC_LIBRARY_App::_set('firewall_hasNextPage', $logs['pageInfo']['hasNextPage']);
525 616
526 - $countryAttacks = getCountryAttacks($firewall['map'], $chart['count_attacks']);
527 - $attacksMap = getAttacksMap($firewall['map']);
617 + $countryAttacks = wtsec_getCountryAttacks($firewall['map'], $chart_['count_attacks']);
618 + $attacksMap = ($firewall['map'])?wtsec_getAttacksMap($firewall['map']):false;
528 619
529 620 $services["waf"] = [
530 621 "pause" => "",
531 622 "site_address" => $domain,
@@ -532,16 +623,18 @@
532 623 "status" => WTSEC_LIBRARY_WT::getStatusIcon($firewall['status']),
533 624 "_status" => $firewall['status'],
534 625 "installed_status" => in_array($firewall['status'], ["not_installed", "error", "down", "not_supported", "not_registered"]) ? false : true,
535 626 "time_of_the_last_check" => convertTimeToReadable($firewall['lastTest']['time']),
536 - "attacks" => $chart['count_attacks'],
537 - "blocking" => $chart['count_blocks'],
538 - "non-blocking" => $chart['count_attacks'] - $chart['count_blocks'],
627 + "attacks" => $chart_['count_attacks'],
628 + "blocking" => $chart_['count_blocks'],
629 + "non-blocking" => $chart_['count_attacks'] - $chart_['count_blocks'],
539 630 "description" => WTSEC_LIBRARY_Localization::lmsg('descriptions.firewall'),
540 - "chart" => json_encode($chart['chart'], true),
631 + "chart" => $chart_['chart'],
541 632 "edges" => $edges,
542 633 "countryAttacks" => $countryAttacks,
543 634 "attacksMap" => $attacksMap,
635 + "hasNextPage" => $logs['pageInfo']['hasNextPage'],
636 + 'settings' => $firewall['settings']
544 637 ];
545 638 }
546 639 }
547 640 wtsec_layout("firewall", $services);
@@ -546,8 +639,123 @@
546 639 }
547 640 wtsec_layout("firewall", $services);
548 641 }
549 642
643 +
644 +function wtsec_firewall_config()
645 +{
646 + $host = WTSEC_LIBRARY_WT::getOwnSite();
647 + $data = WTSEC_LIBRARY_WT::wafGetIpList($host['id']);
648 + $arguments = $data['data']['auth']['viewer']['sites']['one']['firewall'];
649 +
650 + wtsec_layout("firewall_configuration", $arguments);
651 +}
652 +
653 +
654 +
655 +function wtsec_reports_page()
656 +{
657 +
658 + $arguments = [];
659 + $host = WTSEC_LIBRARY_WT::getOwnSite();
660 + if(!empty($host)){
661 + $result = WTSEC_LIBRARY_WT::reportsList($host['id']);
662 +
663 + if (isset($result['data']['auth']['viewer']['reports']['list']['edges'])) {
664 + $arguments = $result['data']['auth']['viewer']['reports']['list'];
665 +
666 + $arguments['edges'] = wtsec_check_modules($arguments['edges']);
667 +
668 + WTSEC_LIBRARY_App::_set('reports_endCursor', $arguments['pageInfo']['endCursor']);
669 + WTSEC_LIBRARY_App::_set('reports_hasNextPage', $arguments['pageInfo']['hasNextPage']);
670 + }
671 + }
672 +
673 +
674 + wtsec_layout("reports", $arguments);
675 +}
676 +
677 +
678 +function wtsec_check_modules($edges){
679 + $modulesLang = [
680 + 'wa' => WTSEC_LIBRARY_Localization::lmsg('reports_page.wa_log'),
681 + 'dc' => WTSEC_LIBRARY_Localization::lmsg('reports_page.dc_log'),
682 + 'ps' => WTSEC_LIBRARY_Localization::lmsg('reports_page.ps_log'),
683 + 'rc' => WTSEC_LIBRARY_Localization::lmsg('reports_page.rc_log'),
684 + 'sc' => WTSEC_LIBRARY_Localization::lmsg('reports_page.sc_log'),
685 + 'av' => WTSEC_LIBRARY_Localization::lmsg('reports_page.av_log'),
686 + 'waf' => WTSEC_LIBRARY_Localization::lmsg('reports_page.waf_log')
687 + ];
688 +
689 + foreach ($edges as $key => $edge){
690 + if(in_array(false, $edge["node"])){
691 + $arr = [];
692 + foreach ($edge["node"] as $k => $v){
693 + if($v == true && array_key_exists($k,$modulesLang)){
694 + $arr[] = $modulesLang[$k];
695 + }
696 + }
697 + $modules = implode(", ", $arr);
698 + } else{
699 + $modules = WTSEC_LIBRARY_Localization::lmsg('reports_page.all_modules');
700 + }
701 +
702 + $edges[$key]["node"]['modules'] = $modules;
703 + }
704 +
705 + return $edges;
706 +
707 +}
708 +
709 +function wtsec_generate_report(){
710 +
711 + if ($_POST) {
712 + $host = WTSEC_LIBRARY_WT::getOwnSite();
713 + $post = ($_POST) ? wtsec_clean($_POST):[];;
714 +
715 + $modules = ['wa' => 'false', 'dc' => 'false', 'ps' => 'false', 'rc' => 'false', 'sc' => 'false', 'av' => 'false', 'waf' => 'false' ];
716 +
717 + foreach ($modules as $key => $module){
718 + if(array_key_exists($key, $post['modules'])){
719 + $modules[$key] = 'true';
720 + }
721 + }
722 +
723 + if($post['datePeriod']){
724 + $date = explode( ' to ', $post['datePeriod'] );
725 + $period = wtsec_period_as_time($date);
726 + }
727 +
728 + if(!$period){
729 + switch ($post['period']){
730 + case 'month-1': $period = 30;
731 + break;
732 + case 'month-3': $period = 90;
733 + break;
734 + case 'month-6': $period = 180;
735 + break;
736 + case 'year-1': $period = 365;
737 + break;
738 + default:
739 + $period = 30;
740 + break;
741 + }
742 + }
743 +
744 + $result = WTSEC_LIBRARY_WT::reportGenerate($host['id'], $period, $modules, WTSEC_LANGUAGE);
745 +
746 + if (isset($result['data']['auth']['viewer']['reports']['generate'])) {
747 + WTSEC_LIBRARY_Session::setNotification("success", WTSEC_LIBRARY_Localization::lmsg('reports_page.generate_success'));
748 + echo $result['data']['auth']['viewer']['reports']['generate'];
749 + exit;
750 + } else {
751 + WTSEC_LIBRARY_Session::setNotification("error", WTSEC_LIBRARY_Localization::lmsg("reports_page.generate_error"));
752 + }
753 + }
754 + echo 'false';
755 + wp_die();
756 +}
757 +
550 758 /**
551 759 * ajax load firewall
552 760 */
553 761 function wtsec_ajax_firewall()
@@ -552,30 +760,33 @@
552 760 */
553 761 function wtsec_ajax_firewall()
554 762 {
555 763 $host = WTSEC_LIBRARY_WT::getOwnSite();
556 - $services = [];
764 + $arguments = [];
557 765
558 766 $post = ($_POST) ? wtsec_clean($_POST):[];
559 - $days = ($post['period']) ? wtsec_period_as_time($post['period']) : 7;
767 + $days = ($post['value']) ? wtsec_period_as_time($post['value']) : 365;
560 768
561 769 if (!empty($host)) {
562 770
563 - if(!$_SESSION['firewall_endCursor'] || $post['filter'] == 'period_filter') $_SESSION['firewall_endCursor'] = null;
771 + $endCursor = WTSEC_LIBRARY_App::_get('firewall_endCursor');
564 772
565 - $site = WTSEC_LIBRARY_WT::getFirewall($host['id'],10, $_SESSION['firewall_endCursor'], $days);
773 + if(!$endCursor || $post['filter'] == 'period_filter') $endCursor = null;
774 +
775 + $site = WTSEC_LIBRARY_WT::getFirewall($host['id'],10, $endCursor, $days);
566 776 if (isset($site['data']['auth']['viewer']['sites']['one']['firewall']['logs'])) {
567 777 $logs = $site['data']['auth']['viewer']['sites']['one']['firewall']['logs'];
568 778
569 - $services["waf"]['edges'] = $logs['edges'];
779 + $arguments["waf"]['edges'] = $logs['edges'];
780 + $arguments["waf"]['hasNextPage'] = $logs['pageInfo']['hasNextPage'];
570 781
571 - $_SESSION['firewall_endCursor'] = $logs['pageInfo']['endCursor'];
572 - $_SESSION['firewall_hasNextPage'] = $logs['pageInfo']['hasNextPage'];
782 + WTSEC_LIBRARY_App::_set('firewall_endCursor', $logs['pageInfo']['endCursor']);
783 + WTSEC_LIBRARY_App::_set('firewall_hasNextPage', $logs['pageInfo']['hasNextPage']);
573 784 }
574 785
575 786 }
576 787
577 - wtsec_layout_part("_firewall_lazy", $services);
788 + wtsec_layout_part("_firewall_lazy", $arguments);
578 789 wp_die();
579 790 }
580 791
581 792 /**
@@ -583,57 +794,186 @@
583 794 */
584 795 function wtsec_ajax_antivirus()
585 796 {
586 797 $host = WTSEC_LIBRARY_WT::getOwnSite();
587 - $services = [];
798 + $arguments = [];
588 799
589 800 $post = ($_POST) ? wtsec_clean($_POST):[];
590 - $days = ($post['period']) ? wtsec_period_as_time($post['period']) : 7;
591 801
592 802 if (!empty($host)) {
803 + $endCursor = WTSEC_LIBRARY_App::_get('antivirus_endCursor');
593 804
594 - if(!$_SESSION['antivirus_endCursor'] || $post['filter'] == 'period_filter') $_SESSION['antivirus_endCursor'] = null;
595 - if($post['event'] || $_SESSION['antivirus_event']){
596 - if($post['event']){
597 - $_SESSION['antivirus_event'] = $post['event'];
598 - }
599 - $site = WTSEC_LIBRARY_WT::getAntivirus($host['id'],10, $_SESSION['antivirus_endCursor'],$days, $_SESSION['antivirus_event']);
805 + if($post['event']){
806 + WTSEC_LIBRARY_App::_set('antivirus_event', $post['event']);
807 + $event = $post['event'];
600 808 } else {
601 - $site = WTSEC_LIBRARY_WT::getAntivirus($host['id'],10, $_SESSION['antivirus_endCursor'],$days);
809 + $event = WTSEC_LIBRARY_App::_get('antivirus_event');
602 810 }
603 811
812 + $days = ($post['filter'] == 'period_filter' && $post['value']) ? wtsec_period_as_time($post['value']) : 365;
813 + $permissionsChanged = ($post['filter'] == 'permission-changed' && $post['value']) ? true : false;
814 + if(!$endCursor || $post['filter'] == 'period_filter' || $permissionsChanged) $endCursor = null;
815 +
816 + $params = [
817 + 'host_id' => $host['id'],
818 + 'limit' => 10,
819 + 'endCursor' => $endCursor,
820 + 'days' => $days,
821 + 'event' => ($permissionsChanged) ? false : $event,
822 + 'permissionsChanged' => $permissionsChanged,
823 + ];
824 +
825 + $site = WTSEC_LIBRARY_WT::getAntivirus($params);
826 +
604 827 if (isset($site['data']['auth']['viewer']['sites']['one']['antivirus']['log'])) {
605 828 $logs = $site['data']['auth']['viewer']['sites']['one']['antivirus']['log'];
606 829
607 - $services["vc"]['list'] = $logs['edges'];
830 + $arguments["vc"]['list'] = wtsec_AVLogsData($logs['edges']);
831 + $arguments["vc"]['hasNextPage'] = $logs['pageInfo']['hasNextPage'];
608 832
609 - $_SESSION['antivirus_endCursor'] = $logs['pageInfo']['endCursor'];
610 - $_SESSION['antivirus_hasNextPage'] = $logs['pageInfo']['hasNextPage'];
833 + WTSEC_LIBRARY_App::_set('antivirus_endCursor', $logs['pageInfo']['endCursor']);
834 + WTSEC_LIBRARY_App::_set('antivirus_hasNextPage', $logs['pageInfo']['hasNextPage']);
611 835
612 836 }
613 837 }
614 - wtsec_layout_part("_antivirus_lazy", $services);
838 + wtsec_layout_part("_antivirus_lazy", $arguments);
615 839
616 840 wp_die();
617 841 }
618 842
843 +function wtsec_move_to_quarantine(){
844 + $host = WTSEC_LIBRARY_WT::getOwnSite();
845 + $result = WTSEC_LIBRARY_WT::moveToQuarantine($host['id'], wtsec_request()->path);
846 + if($result['data']['auth']['sites']['av']['moveToQuarantine']){
847 + $host = WTSEC_LIBRARY_WT::getOwnSite();
848 + $arguments = [];
849 + if (!empty($host)) {
850 + $arguments = wtsec_antivirus_getData($host);
851 + }
852 + wtsec_layout_part("antivirus", $arguments,false);
853 + } else{
854 + echo 'false';
855 + }
856 +
857 + wp_die();
858 +}
859 +
860 +function wtsec_force_check_av(){
861 + $host = WTSEC_LIBRARY_WT::getOwnSite();
862 + $result = WTSEC_LIBRARY_WT::forceCheck($host['id'], 'av');
863 + if($result['data']['auth']['sites']['forceCheck']){
864 + echo 'true';
865 + }
866 +
867 + wp_die();
868 +}
869 +
870 +
871 +function wtsec_av_export(){
872 + $host = WTSEC_LIBRARY_WT::getOwnSite();
873 + $result = WTSEC_LIBRARY_WT::avExport($host['id']);
874 + if($result['data']['auth']['sites']['av']['export']){
875 + echo $result['data']['auth']['sites']['av']['export'];
876 + }else{
877 + echo 'false';
878 + }
879 +
880 + wp_die();
881 +}
882 +
883 +
884 +function wtsec_move_from_quarantine(){
885 + $result = WTSEC_LIBRARY_WT::moveFromQuarantine(wtsec_request()->id);
886 + if($result['data']['auth']['sites']['av']['moveFromQuarantine']){
887 + $host = WTSEC_LIBRARY_WT::getOwnSite();
888 + $arguments = [];
889 + if (!empty($host)) {
890 + $arguments = wtsec_antivirus_getData($host);
891 + }
892 + wtsec_layout_part("antivirus", $arguments,false);
893 + } else{
894 + echo 'false';
895 + }
896 +
897 + wp_die();
898 +}
899 +
900 +function wtsec_ajax_reports()
901 +{
902 + $host = WTSEC_LIBRARY_WT::getOwnSite();
903 + $post = ($_POST) ? wtsec_clean($_POST):[];
904 + $layout = ($post['type'] == 'mobile')? '_reports_lazy_mobile' : '_reports_lazy';
905 +
906 + $arguments = [];
907 + $endCursor = WTSEC_LIBRARY_App::_get('reports_endCursor');
908 +
909 + $result = WTSEC_LIBRARY_WT::reportsList($host['id'],10, $endCursor);
910 + if (isset($result['data']['auth']['viewer']['reports']['list']['edges'])) {
911 + $arguments = $result['data']['auth']['viewer']['reports']['list'];
912 +
913 + $arguments['edges'] = wtsec_check_modules($arguments['edges']);
914 +
915 + WTSEC_LIBRARY_App::_set('reports_endCursor', $arguments['pageInfo']['endCursor']);
916 + WTSEC_LIBRARY_App::_set('reports_hasNextPage', $arguments['pageInfo']['hasNextPage']);
917 + }
918 +
919 + wtsec_layout_part($layout, $arguments);
920 + wp_die();
921 +}
922 +
923 +function wtsec_report_link()
924 +{
925 + $post = ($_POST) ? wtsec_clean($_POST):[];
926 +
927 + $result = WTSEC_LIBRARY_WT::reportDownload($post['id']);
928 +
929 + if (isset($result['data']['auth']['viewer']['reports']['download'])) {
930 + echo $result['data']['auth']['viewer']['reports']['download'];
931 + }
932 +
933 + wp_die();
934 +}
935 +
619 936 /**
620 937 * ajax load chart
621 938 */
622 939 function wtsec_chart_filter()
623 940 {
624 - $days = (int)$_POST['days'];
625 - $days = $days ?: 7;
626 941
627 - $host = WTSEC_LIBRARY_WT::getOwnSite();
628 - $chart = WTSEC_LIBRARY_WT::getFirewallChart($host['id'], $days);
629 - $chart = $chart['data']['auth']['viewer']['sites']['one']['firewall']['chart'];
630 - $chart = generateChart($chart, $days);
631 - $res['chart'] = json_encode($chart['chart'], true);
632 - $res['days'] = $days;
942 + if (wtsec_request()->method === "POST") {
943 + $service = wtsec_request()->service;
944 + $days = (int)wtsec_request()->days;
945 + $days = $days ?: 7;
633 946
634 - wtsec_layout_part("_chart_ajax", $res);
947 + $host = WTSEC_LIBRARY_WT::getOwnSite();
635 948
949 + $arguments['days'] = $days;
950 +
951 + switch($service){
952 + case 'waf':
953 + $chart = WTSEC_LIBRARY_WT::getFirewallChart($host['id'], $days);
954 + $chart = wtsec_generateChart($chart, $days);
955 + $arguments['chart'] = $chart['chart'] ?: false;
956 + $layout = "_chart_ajax";
957 + break;
958 +
959 + case 'ram':
960 + $chart = WTSEC_LIBRARY_WT::getServerStatusChart($host['id'], $days);
961 + $arguments['chart'] = (!empty($chart['ramChart']))? wtsec_chartData($chart['ramChart'],$days) : false;
962 + $layout = "_chart_ram_ajax";
963 + break;
964 +
965 + case 'cpu':
966 + $chart = WTSEC_LIBRARY_WT::getServerStatusChart($host['id'], $days);
967 + $arguments['chart'] = (!empty($chart['cpuChart']))? wtsec_chartData($chart['cpuChart'],$days) : false;
968 + $layout = "_chart_cpu_ajax";
969 + break;
970 + }
971 +
972 + wtsec_layout_part($layout, $arguments);
973 + }
974 +
975 +
636 976 wp_die();
637 977 }
638 978
639 979 /**
@@ -647,9 +987,9 @@
647 987 $host = WTSEC_LIBRARY_WT::getOwnSite();
648 988 $site = WTSEC_LIBRARY_WT::getFirewall($host['id'],10,null,$days);
649 989 $firewall = $site['data']['auth']['viewer']['sites']['one']['firewall'];
650 990
651 - $attacksMap = getAttacksMap($firewall['map']);
991 + $attacksMap = ($firewall['map'])?wtsec_getAttacksMap($firewall['map']):false;
652 992 $res["waf"]['attacksMap'] = $attacksMap;
653 993 $res['days'] = $days;
654 994
655 995 wtsec_layout_part("_map_view", $res);
@@ -671,13 +1011,140 @@
671 1011
672 1012 wp_die();
673 1013 }
674 1014
1015 +function wtsec_configs_toggle()
1016 +{
1017 + $post = ($_POST) ? wtsec_clean($_POST):[];
1018 + $service_id = $post['service'];
1019 + $config = WTSEC_LIBRARY_WT::toggleConfigs($service_id);
1020 + echo json_encode($config['data']['auth']['configs']['toggle']);
1021 +
1022 + wp_die();
1023 +}
1024 +
1025 +function wtsec_settings(){
1026 + if (wtsec_request()->method === "POST") {
1027 + if(wtsec_request()->checked){
1028 + $check_login_attempt = 1;
1029 + } else {
1030 + $check_login_attempt = 0;
1031 + }
1032 + WTSEC_LIBRARY_App::_set('check_login_attempt', $check_login_attempt);
1033 + echo $check_login_attempt;
1034 + }
1035 +
1036 + wp_die();
1037 +}
1038 +
1039 +function wtsec_waf_settings(){
1040 + if (wtsec_request()->method === "POST") {
1041 +
1042 + $host = WTSEC_LIBRARY_WT::getOwnSite();
1043 +
1044 + $settings = [
1045 + 'gdn' => wtsec_request()->gdn ? 'true' : 'false',
1046 + 'dosProtection' => (bool)wtsec_request()->dosProtection ? 'true' : 'false',
1047 + 'dosLimit' => (int)wtsec_request()->dosLimit,
1048 + 'loginAttemptsProtection' => (bool)wtsec_request()->loginAttemptsProtection ? 'true' : 'false',
1049 + 'loginAttemptsLimit' => (int)wtsec_request()->loginAttemptsLimit,
1050 + ];
1051 +
1052 + $result = WTSEC_LIBRARY_WT::wafSettings($host['id'],$settings);
1053 + if(!$result['errors']){
1054 + echo 'true';
1055 + }
1056 +
1057 + }
1058 +
1059 + wp_die();
1060 +}
1061 +
1062 +function wtsec_waf_add_ip_to_list(){
1063 + if (wtsec_request()->method === "POST") {
1064 +
1065 + $host = WTSEC_LIBRARY_WT::getOwnSite();
1066 +
1067 + $ips = wtsec_request()->ip;
1068 + $color = wtsec_request()->list;
1069 +
1070 + if($ips && $color){
1071 + WTSEC_LIBRARY_WT::wafAddIpToList($host['id'], $ips, $color);
1072 + }
1073 +
1074 + $data = WTSEC_LIBRARY_WT::wafGetIpList($host['id']);
1075 + $arguments = $data['data']['auth']['viewer']['sites']['one']['firewall'];
1076 +
1077 + $list = ['white' => 'whiteList', 'black' => 'blackList'];
1078 + $arguments['list'] = $list[$color];
1079 +
1080 +
1081 + wtsec_layout_part('_lazy_ip_list', $arguments);
1082 + }
1083 +
1084 + wp_die();
1085 +}
1086 +
1087 +function wtsec_waf_remove_ip_to_list(){
1088 + if (wtsec_request()->method === "POST") {
1089 +
1090 + $host = WTSEC_LIBRARY_WT::getOwnSite();
1091 + $id = wtsec_request()->id ;
1092 +
1093 + if($id){
1094 + WTSEC_LIBRARY_WT::wafRemoveIpToList($id);
1095 + }
1096 +
1097 + $data = WTSEC_LIBRARY_WT::wafGetIpList($host['id']);
1098 + $arguments = $data['data']['auth']['viewer']['sites']['one']['firewall'];
1099 +
1100 + $arguments['list'] = wtsec_request()->list;
1101 +
1102 + wtsec_layout_part('_lazy_ip_list', $arguments);
1103 + }
1104 + wp_die();
1105 +}
1106 +
1107 +function wtsec_notification(){
1108 +
1109 + if (wtsec_request()->method === "POST") {
1110 + $notification = wtsec_request()->notification;
1111 + $type = wtsec_request()->type; //"error","info","warning","success"
1112 +
1113 + $styles = ["error" => ["color" => "red", "class" => "wtotem_alert__img_cross", "img" => ""], "info" => ["color" => "", "class" => "", "img" => ""], "warning" => ["color" => "yellow", "class" => "", "img" => '<img src="' . wtsec_getImagePath("alert-warning.svg") . '">'], "success" => ["color" => "green", "class" => "", "img" => '<img src="' . wtsec_getImagePath("alert-success.svg") . '">']];
1114 +
1115 + $style = $styles[$type];
1116 + echo '<div class="wtotem_alert wt_card" id="wtotem_alert" style="margin-bottom:0">
1117 + <div class="wtotem_alert__desc">
1118 + <div class="wtotem_alert__img ' . $style["class"] . '">' . $style["img"] . '</div>
1119 + <div class="wtotem_alert__title wtotem_alert__title_' . $style["color"] . '">' . WTSEC_LIBRARY_Localization::lmsg('statuses.' . $type) . ': </div>
1120 + <p class="wtotem_alert__text">' . WTSEC_LIBRARY_Localization::lmsg($notification) . '</p>
1121 + </div>
1122 + <div class="wtotem_alert__close" onclick="removeAlert()"></div>
1123 + </div>';
1124 + }
1125 + wp_die();
1126 +}
1127 +
1128 +function wtsec_setTimeZone()
1129 +{
1130 + if (wtsec_request()->method === "POST") {
1131 + $timeZone = wtsec_request()->timeZone;
1132 + WTSEC_LIBRARY_App::_set('time_zone', $timeZone);
1133 +
1134 + }
1135 + wp_die();
1136 +}
1137 +
675 1138 function wtsec_login_form()
676 1139 {
677 1140 if (wtsec_request()->method === "POST") {
678 1141 $result = WTSEC_LIBRARY_WT::auth(wtsec_request()->key);
679 1142 if (isset($result['data']['guest']['apiKeys']['auth']['token']['value'])) {
1143 +
1144 + $expiresIn = $result['data']['guest']['apiKeys']['auth']['token']['expiresIn'];
1145 + wtsec_app()->set("token_expired", time() + $expiresIn - 60);
1146 +
680 1147 WTSEC_LIBRARY_Session::setNotification("success", WTSEC_LIBRARY_Localization::lmsg('successfully_activated'));
681 1148 $token = $result['data']['guest']['apiKeys']['auth']['token']['value'];
682 1149 WTSEC_LIBRARY_App::login($token);
683 1150 wtsec_app()->set("api_key", wtsec_request()->key);
@@ -696,8 +1163,9 @@
696 1163 $_service = strtolower(wtsec_request()->service);
697 1164 $uid = wtsec_request()->uid;
698 1165 $cmd = wtsec_request()->cmd;
699 1166 $status = wtsec_checkStatus($uid, $service);
1167 +
700 1168 if (stripos($cmd, "install") === false) {
701 1169 wtsec_cmd($cmd, $service, $_service, $uid, $status, WTSEC_SITE_URL);
702 1170 wp_safe_redirect(wp_get_referer());
703 1171 } else {
@@ -719,22 +1187,21 @@
719 1187 {
720 1188 WTSEC_LIBRARY_App::logout();
721 1189 }
722 1190
723 -function wtsec_layout_part($template, $arguments = [])
1191 +function wtsec_layout_part($template, $arguments = [], $components = true)
724 1192 {
725 - wp_register_script( 'ajaxHandle', get_template_directory() . 'PATH TO YOUR JS FILE', array(), false, true );
726 - wp_enqueue_script( 'ajaxHandle' );
727 - wp_localize_script( 'ajaxHandle', 'ajax_object', array( 'ajaxurl' => admin_url( 'admin-ajax.php' ) ) );
1193 + if($components){
1194 + require WTSEC_PLUGIN_PATH . "includes/components/" . $template . ".php";
1195 + } else {
1196 + require WTSEC_PLUGIN_PATH . "includes/" . $template . ".php";
1197 + }
728 1198
729 - require WTSEC_PLUGIN_PATH . "includes/components/" . $template . ".php";
730 -
731 1199 }
732 1200
733 -function wtsec_layout($template, $arguments = [], $faq = "faq")
1201 +function wtsec_layout($template, $arguments = [])
734 1202 {
735 1203 $body = WTSEC_PLUGIN_PATH . "includes/" . $template . ".php";
736 - $faq = WTSEC_PLUGIN_PATH . "includes/" . $faq . ".php";
737 1204 require_once WTSEC_PLUGIN_PATH . "includes/layout.php";
738 1205 }
739 1206
740 1207
@@ -758,8 +1225,9 @@
758 1225 }
759 1226 wp_safe_redirect(wp_get_referer());
760 1227 }
761 1228
1229 +
762 1230 function wtsec_page($page)
763 1231 {
764 1232 return wtsec_pages()[$page];
765 1233 }
@@ -778,10 +1246,10 @@
778 1246 }
779 1247
780 1248 function wtsec_period_as_time($period){
781 1249 $end = $period[1] ?: $period[0];
782 - $array['begin'] = strtotime(date('d-m-Y 00:00:00',strtotime($period[0])));
783 - $array['end'] = strtotime(date('d-m-Y 23:59:59',strtotime($end)));
1250 + $array['from'] = strtotime(date('d-m-Y 00:00:00',strtotime($period[0])));
1251 + $array['to'] = strtotime(date('d-m-Y 23:59:59',strtotime($end)));
784 1252
785 1253 return $array;
786 1254 }
787 1255
@@ -797,17 +1265,12 @@
797 1265
798 1266 function wtsec_pages()
799 1267 {
800 1268 return [
801 -// "options" => [
802 -// "page_title" => WTSEC_LIBRARY_Localization::lmsg('options'),
803 -// "menu_title" => WTSEC_LIBRARY_Localization::lmsg('options'),
804 -// "function" => "wtsec_options_page",
805 -// ],
806 - "services" => [
807 - "page_title" => WTSEC_LIBRARY_Localization::lmsg('services'),
808 - "menu_title" => WTSEC_LIBRARY_Localization::lmsg('services'),
809 - "function" => "wtsec_services_page",
1269 + "options" => [
1270 + "page_title" => WTSEC_LIBRARY_Localization::lmsg('settings'),
1271 + "menu_title" => WTSEC_LIBRARY_Localization::lmsg('settings'),
1272 + "function" => "wtsec_options_page",
810 1273 ],
811 1274 "vc" => [
812 1275 "page_title" => WTSEC_LIBRARY_Localization::lmsg('remote_antivirus'),
813 1276 "menu_title" => WTSEC_LIBRARY_Localization::lmsg('remote_antivirus'),
@@ -821,10 +1284,26 @@
821 1284 "function" => "wtsec_firewall_page",
822 1285 "vc_action" => "firewall-action",
823 1286 "vc_function" => "wtsec_firewall_function"
824 1287 ],
1288 + "waf-config" => [
1289 + "page_title" => WTSEC_LIBRARY_Localization::lmsg('firewall_configuration'),
1290 + "menu_title" => WTSEC_LIBRARY_Localization::lmsg('firewall_configuration'),
1291 + "function" => "wtsec_firewall_config",
1292 + ],
1293 + "reports" => [
1294 + "page_title" => WTSEC_LIBRARY_Localization::lmsg('reports'),
1295 + "menu_title" => WTSEC_LIBRARY_Localization::lmsg('reports'),
1296 + "function" => "wtsec_reports_page",
1297 + ],
1298 + "information" => [
1299 + "page_title" => WTSEC_LIBRARY_Localization::lmsg('information'),
1300 + "menu_title" => WTSEC_LIBRARY_Localization::lmsg('information'),
1301 + "function" => "wtsec_information_page",
1302 + ],
825 1303 ];
826 1304 }
1305 +
827 1306
828 1307 function wtsec_getCountryName($key){
829 1308 $countries = [
830 1309 'AD' => 'Andorra',