PluginProbe
WebTotem Security / 2.3.36
WebTotem Security v2.3.36
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
wt-security / wt-security.php

wt-security.php in WebTotem Security 2.3.36, at wt-security.php

196 lines 8.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php defined('ABSPATH') or die("Protected By WT!");
2
3 /*
4 Plugin Name: WebTotem Security
5 Description: WebTotem is a SaaS which provides powerful tools for securing and monitoring your website in one place in easy and flexible way.
6 Author: WebTotem
7 Version: 2.3.36
8 Text Domain: wtotem
9 Domain Path: /languages
10 */
11
12 __( 'WebTotem Security', 'wtotem' );
13 __( 'WebTotem is a SaaS which provides powerful tools for securing and monitoring your website in one place in easy and flexible way.', 'wtotem' );
14
15 define("WTSEC_PAGE_TITLE", 'Dashboard');
16 define("WTSEC_MENU_TITLE", 'WT Security');
17 define("WTSEC_PLUGIN_PATH", plugin_dir_path(__FILE__));
18 define("WTSEC_PLUGIN_NAME", 'wt-security');
19 define("WTSEC_PLUGIN_PREFIX", 'wtsec_');
20 define("WTSEC_PAGE_PREFIX", WTSEC_PLUGIN_NAME . '-');
21 define("WTSEC_FILE_URL", "https://api.wtotem.com/agent");
22 define("WTSEC_MODULES_DIR", WTSEC_PLUGIN_PATH . 'uploads/');
23
24 if (is_dir(WTSEC_MODULES_DIR) && is_writable(WTSEC_MODULES_DIR)) {
25 define("WTSEC_INSTALLATION_DIR", WTSEC_MODULES_DIR);
26 } else {
27 define("WTSEC_INSTALLATION_DIR", wp_upload_dir()['basedir'] . '/');
28 }
29
30 define("WTSEC_PLUGIN_URL", plugins_url("", __FILE__));
31 define("WTSEC_PLUGIN_BASENAME", plugin_basename( __FILE__));
32 define("WTSEC_SITE_URL", str_replace(['http://', 'https://', '//', '://', 'www.'], '', get_site_url()));
33
34 define("WTSEC_PLUGIN_INFORMATION_VERSION", "2.3");
35
36 $curLang = substr(get_bloginfo('language'), 0,2);
37 $language = (in_array($curLang,['ru','en','pl'])) ? $curLang : 'en' ;
38 define("WTSEC_LANGUAGE", $language);
39
40 add_action( 'plugins_loaded', function(){
41 load_plugin_textdomain( 'wtotem', false, dirname( plugin_basename(__FILE__) ) . '/languages' );
42 } );
43
44 add_action('wp_loaded', 'wtsec_init');
45 add_action('admin_init', 'wtsec_admin_init');
46 add_filter( 'authenticate', 'wtsec_login_check', 30, 3 );
47
48 add_action( 'upgrader_process_complete', 'wtsec_generate_file', 10, 2 );
49
50 function wtsec_init()
51 {
52 require_once WTSEC_PLUGIN_PATH . 'library/App.php';
53 require_once WTSEC_PLUGIN_PATH . 'library/Request.php';
54
55 // WAF include (Если не админка и статус waf = "start", "uninstalled")
56 // && in_array(WTSEC_LIBRARY_App::getOption('waf_status'), ["start", "uninstalled"])
57
58 $current_user = wp_get_current_user();
59 if ( !($current_user instanceof WP_User) )
60 return;
61 $roles = $current_user->roles;
62
63 if(!in_array('administrator',$roles) && !in_array('editor',$roles) && WTSEC_LIBRARY_App::getOption('authorized')){
64 if (!function_exists('wt_logs') && $waf = WTSEC_LIBRARY_App::getOption(("waf_installed_file"))) {
65 $path_to_waf = $_SERVER['DOCUMENT_ROOT'] . '/_include_' . $waf;
66 if (is_file($path_to_waf) && is_readable($path_to_waf)) {
67 include_once $path_to_waf;
68 }
69 }
70 }
71
72 if (is_admin()) {
73 require_once WTSEC_PLUGIN_PATH . 'library/WT.php';
74 require_once WTSEC_PLUGIN_PATH . 'library/Idn.php';
75 require_once WTSEC_PLUGIN_PATH . 'library/Session.php';
76 require_once WTSEC_PLUGIN_PATH . 'routes.php';
77 require_once WTSEC_PLUGIN_PATH . 'services.php';
78 require_once WTSEC_PLUGIN_PATH . 'helpers.php';
79
80 function wtsec_request()
81 {
82 return new WTSEC_LIBRARY_Request();
83 }
84
85 function wtsec_app()
86 {
87 return new WTSEC_LIBRARY_App();
88 }
89
90 function wtsec_filesystem_init($form_url, $method, $context, $fields = null)
91 {
92 global $wp_filesystem;
93 if (!$creds = request_filesystem_credentials($form_url, $method, false, $context, $fields)) {
94 return false;
95 }
96 if (!WP_Filesystem($creds)) {
97 request_filesystem_credentials($form_url, $method, true, $context);
98 return false;
99 }
100 return true;
101 }
102
103 function wtsec_getImagePath($image)
104 {
105 return plugins_url('/htdocs/img/' . $image, __FILE__);
106 }
107
108 }
109 }
110
111 function wtsec_admin_init()
112 {
113 if(!function_exists('wtsec_request')){
114 function wtsec_request(){
115 return new WTSEC_LIBRARY_Request();
116 }
117 }
118
119 $rand = '?rand='.rand();
120 if (is_admin() && stripos(wtsec_request()->page, WTSEC_PLUGIN_NAME) !== false) {
121 if(WTSEC_LIBRARY_App::authorized()){
122 wp_enqueue_script('subscriber', plugins_url('/htdocs/js/wtsec_subscriber.js'.$rand, __FILE__), [], false, true);
123 wp_enqueue_script('amplitude', plugins_url( '/htdocs/js/wtsec_amplitude.js', __FILE__ ), array(),false, true );
124 wp_enqueue_script('d3-v4', plugins_url('/htdocs/js/wtsec_d3.v4.js', __FILE__), array( 'jquery' ), false, true);
125 wp_enqueue_script('jsdelivr', plugins_url('/htdocs/js/wtsec_jsdelivr_chart.js', __FILE__), array( 'jquery' ), false, true);
126 wp_enqueue_script('chart', plugins_url('/htdocs/js/wtsec_Chart.js'.$rand, __FILE__), [], false, true);
127 wp_enqueue_script('circle-progress', plugins_url('/htdocs/js/wtsec_circle-progress.js', __FILE__), [], false, true);
128 wp_enqueue_script('range-plugin', plugins_url('/htdocs/js/wtsec_rangePlugin.js', __FILE__), array( 'jquery' ), false, true);
129 wp_enqueue_script('flatpickr', plugins_url('/htdocs/js/wtsec_flatpickr.js', __FILE__), array( 'jquery' ), false, true);
130 wp_enqueue_script('filter-calendar', plugins_url('/htdocs/js/wtsec_filterCalendar.js', __FILE__), array( 'jquery' ), false, true);
131 wp_enqueue_script('line-progress', plugins_url('/htdocs/js/wtsec_line-progress.js', __FILE__), [], false, true);
132 wp_enqueue_script('main', plugins_url('/htdocs/js/wtsec_main.js'.$rand, __FILE__), [], false, true);
133 wp_enqueue_script('ajax', plugins_url( '/htdocs/js/wtsec_ajax.js'.$rand, __FILE__ ), array( 'jquery' ),false, true );
134 wp_enqueue_script('subscriber');
135 wp_enqueue_script('amplitude');
136 wp_enqueue_script('d3-v4');
137 wp_enqueue_script('jsdelivr');
138 wp_enqueue_script('chart');
139 wp_enqueue_script('circle-progress');
140 wp_enqueue_script('range-plugin');
141 wp_enqueue_script('flatpickr');
142 wp_enqueue_script('filter-calendar');
143 wp_enqueue_script('line-progress');
144 wp_enqueue_script('main');
145 wp_enqueue_script('ajax');
146 }
147
148 wp_register_style('flatpickr-css', 'https://cdn.jsdelivr.net/npm/flatpickr/dist/flatpickr.min.css');
149 wp_register_style('font', 'https://fonts.googleapis.com/css2?family=Inter:wght@400;500;700&display=swap');
150 wp_register_style('main', plugins_url('/htdocs/css/wtsec_main.css'.$rand, __FILE__));
151 wp_enqueue_style('flatpickr-css');
152 wp_enqueue_style('font');
153 wp_enqueue_style('main');
154
155 $page = wtsec_request()->page;
156 if ($page === wtsec_getRoute("login")) {
157 if (WTSEC_LIBRARY_App::authorized()) {
158 wp_safe_redirect(wtsec_getUrl('dashboard'));
159 }
160 } elseif ($page === wtsec_getRoute("logout")) {
161 WTSEC_LIBRARY_App::_set('am_installed', false);
162 WTSEC_LIBRARY_App::logout();
163 wp_safe_redirect(wtsec_getUrl('login'));
164 } else {
165 if (!WTSEC_LIBRARY_App::authorized()) {
166 wp_safe_redirect(wtsec_getUrl('login'));
167 }
168 }
169 }
170 }
171
172 function wtsec_login_check($user, $username, $password) {
173 require_once WTSEC_PLUGIN_PATH . 'library/App.php';
174 $app = new WTSEC_LIBRARY_App;
175 if($app::getOption('authorized')){
176 return $app->wtsec_login_check($user, $username, $password);
177 }
178 return $user;
179 }
180
181 // Create file generate.php after plugin update
182 function wtsec_generate_file( $upgrader_object, $options ) {
183
184 if( $options['action'] == 'update' && $options['type'] == 'plugin' && isset( $options['plugins'] ) ) {
185 foreach( $options['plugins'] as $plugin ) {
186 if( $plugin == WTSEC_PLUGIN_BASENAME ) {
187 require_once WTSEC_PLUGIN_PATH . 'library/App.php';
188 $fileName = WTSEC_LIBRARY_App::getOption('am_installed_file');
189
190 wtsec_addCheckFile($fileName);
191 }
192 }
193 }
194 }
195
196