PluginProbe
WebTotem Security / 2.4.2
WebTotem Security v2.4.2
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | lib/Helper.php +254 -1021 3.0.02.4.2 View file →
@@ -11,12 +11,8 @@
11 11 * WebTotem Base class for Wordpress.
12 12 */
13 13 class WebTotem {
14 14
15 - public static function log($notice){
16 - file_put_contents(WEBTOTEM_PLUGIN_PATH . '/wtotem_log.txt', date('Y-m-d H:i:s') . ' ' . $notice . PHP_EOL, FILE_APPEND);
17 - }
18 -
19 15 /**
20 16 * Returns an URL from the admin dashboard.
21 17 *
22 18 * @param string $url
@@ -31,37 +27,8 @@
31 27 return admin_url($url);
32 28 }
33 29
34 30 /**
35 - * Define role of current user.
36 - *
37 - */
38 - public static function getUserRole() {
39 -
40 - if (defined('WEBTOTEM_USER_ROLE')) {
41 - return true;
42 - }
43 - $current_user = wp_get_current_user();
44 - if ( !($current_user instanceof WP_User) ){
45 - $user_role = 0;
46 - } else {
47 - $roles = $current_user->roles;
48 -
49 - if(in_array('administrator', $roles)) {
50 - $user_role = 1;
51 - } elseif(in_array('editor', $roles) or current_user_can('publish_posts')) {
52 - $user_role = 2;
53 - } else {
54 - $user_role = 0;
55 - }
56 - }
57 -
58 - define( 'WEBTOTEM_USER_ROLE', $user_role );
59 -
60 - return true;
61 - }
62 -
63 - /**
64 31 * Check whether the current site is working as a multi-site instance.
65 32 *
66 33 * @return bool
67 34 * Either TRUE or FALSE in case WordPress is being used as a multi-site instance.
@@ -66,29 +33,11 @@
66 33 * @return bool
67 34 * Either TRUE or FALSE in case WordPress is being used as a multi-site instance.
68 35 */
69 36 public static function isMultiSite() {
70 - return (bool) ( (function_exists('is_multisite') && is_multisite()) || (defined('MULTISITE') && MULTISITE == true) );
37 + return (bool) (function_exists('is_multisite') && is_multisite());
71 38 }
72 39
73 -
74 - /**
75 - * Get user email.
76 - *
77 - * @return string
78 - * Returns user email.
79 - */
80 - public static function getUserEmail() {
81 - $email = WebTotemOption::getOption( "user_email" );
82 - if(!$email){
83 - if(WebTotemOption::isActivated()) {
84 -// $email = WebTotemAPI::getEmail();
85 - }
86 - WebTotemOption::setOptions(['user_email' => $email]);
87 - }
88 - return $email;
89 - }
90 -
91 40 /**
92 41 * Returns the md5 hash representing the content of a file.
93 42 *
94 43 * @param string $file
@@ -100,197 +49,29 @@
100 49 return substr(md5_file(WEBTOTEM_PLUGIN_PATH . '/' . $file), 0, 7);
101 50 }
102 51
103 52 /**
104 - * Returns full path to image.
53 + * Returns the md5 hash representing the content of a file.
105 54 *
106 - * @param string $image
55 + * @param string $file
107 56 * Relative path to the file.
108 57 * @return string
109 - * Full path to image.
58 + * Seven first characters in the hash of the file.
110 59 */
111 60 public static function getImagePath($image) {
112 61 return WEBTOTEM_URL. '/includes/img/' . $image;
113 62 }
114 63
115 - /**
116 - * Checking whether the current domain belongs to the kz domain zone.
117 - *
118 - * @return bool
119 - * true is returned if the domain belongs to the kz domain zone.
120 - */
121 - public static function isKz() {
122 - $is_kz = json_decode(WebTotemOption::getOption('is_kz'), true);
123 - if(is_array($is_kz)){
124 - return $is_kz['value'];
125 - }
126 -
127 - if(function_exists('idn_to_utf')){
128 - $host = idn_to_utf8($_SERVER['HTTP_HOST']);
129 - } else {
130 - $host = $_SERVER['HTTP_HOST'];
131 - }
132 -
133 - $parts = explode('.', $host);
134 - $domain_zone = $parts[count($parts)-1];
135 -
136 - if($domain_zone === 'kz' or $domain_zone === 'қаз'){
137 - $is_kz['value'] = true;
138 - } else {
139 - $is_kz['value'] = false;
140 - }
141 -
142 - WebTotemOption::setOptions(['is_kz' => $is_kz]);
143 -
144 - return $is_kz['value'];
145 - }
146 -
147 - /**
148 - * Convert object to array.
149 - *
150 - * @param array $data
151 - * Array.
152 - * @return array
153 - * Returns array.
154 - */
155 - public static function convertObjectToArray($data){
156 -
157 - if(!is_array($data)) $data = (array)$data;
158 - array_walk_recursive($data, function(&$item){
159 - if(is_object($item)) $item = (array)$item;
160 - });
161 -
162 - return $data;
163 - }
164 -
165 - /**
166 - * Decodes a Base64URL-encoded string into a regular string.
167 - *
168 - * Base64URL is a URL-safe variant of Base64 commonly used in JWT and other web standards.
169 - * In Base64URL, the '+' and '/' characters are replaced with '-' and '_', and the '=' padding is often omitted.
170 - * This function converts Base64URL back to standard Base64 and then decodes it.
171 - *
172 - * @param string $data The input string encoded in Base64URL format.
173 - *
174 - * @return string|false Returns the decoded string, or false if decoding fails.
175 - */
176 - public static function base64UrlDecode($data) {
177 - $remainder = strlen($data) % 4;
178 - if ($remainder) {
179 - $data .= str_repeat('=', 4 - $remainder);
180 - }
181 - return base64_decode(strtr($data, '-_', '+/'));
182 - }
183 -
184 64 /**
185 - * Removing duplicates by one key.
186 - *
187 - * @param array $array
188 - * Array.
189 - * @param string $key
190 - * Delete duplicates with the same key.
191 - *
192 - * @return array
193 - * Returns array.
194 - */
195 - public static function arrayUniqueKey($array, $key) {
196 - $tmp = $key_array = array();
197 - $i = 0;
198 -
199 - foreach ($array as $val) {
200 - if (!in_array($val[$key], $key_array)) {
201 - $key_array[$i] = $val[$key];
202 - $tmp[$i] = $val;
203 - }
204 - $i++;
205 - }
206 - return $tmp;
207 - }
208 -
209 - /**
210 - * Returns user IP address.
211 - *
212 - * @return string
213 - * Returns user IP address.
214 - */
215 - public static function getUserIP() {
216 - $arr = [
217 - 'HTTP_CLIENT_IP',
218 - 'HTTP_X_FORWARDED_FOR',
219 - 'HTTP_X_FORWARDED',
220 - 'HTTP_X_CLUSTER_CLIENT_IP',
221 - 'HTTP_FORWARDED_FOR',
222 - 'HTTP_FORWARDED',
223 - 'HTTP_CF_CONNECTING_IP',
224 - 'REMOTE_ADDR'
225 - ];
226 -
227 - foreach ($arr as $key){
228 - if (array_key_exists($key, $_SERVER) === true) {
229 - foreach (explode(',', $_SERVER[$key]) as $ip) {
230 - $ip = trim($ip);
231 - $ip = filter_var($ip, FILTER_VALIDATE_IP);
232 - if (!empty($ip)) {
233 - return $ip;
234 - }
235 - }
236 - }
237 - }
238 - return false;
239 - }
240 -
241 - /**
242 - * Convert the file size to а human-readable format.
65 + * Check that the training period has passed for the firewall.
243 66 *
244 - * @param string $bytes
245 - * File size in bytes.
246 - * @param string $decimals
247 - * The number of characters after the decimal point.
67 + * @param string $created_at
68 + * Date when the waf configuration was created.
248 69 *
249 - * @return string
250 - * Returns the file size in a human-readable format.
251 - */
252 - public static function humanFilesize($bytes, $decimals = 2) {
253 - $factor = floor((strlen($bytes) - 1) / 3);
254 - $unit_of_measurement = ($factor > 0) ? substr("KMGT", $factor - 1, 1) : '';
255 - $size = sprintf("%.{$decimals}f", $bytes / pow(1024, $factor)) . $unit_of_measurement . 'B';
256 - return str_replace(".00", "", $size);
257 - }
258 -
259 - /**
260 - * Check whether the file is publicly accessible.
261 - *
262 - * @param string $url
263 - * http link to the file.
264 - * @param string $path
265 - * The path to the file.
266 - *
267 70 * @return bool
268 - */
269 - public static function isPubliclyAccessible($url, $path) {
270 - $response = wp_remote_get($url);
271 -
272 - if ((int) floor(((int) wp_remote_retrieve_response_code($response) / 100)) === 2) {
273 - $handle = @fopen($path, 'r');
274 - if ($handle) {
275 - $contents = fread($handle, 700);
276 - fclose($handle);
277 - $remoteContents = substr(wp_remote_retrieve_body($response), 0, 700);
278 -
279 - return $contents === $remoteContents;
280 - }
281 - }
282 - return false;
283 - }
284 -
285 - /**
286 - * Check that the training period has passed for the firewall.
287 - *
288 - * @return bool
289 71 * Returns boolean.
290 72 */
291 - public static function isWafTraining() {
292 - $created_at = WebTotemOption::getOption('am_created_at');
73 + public static function isWafTraining($created_at) {
293 74 if($created_at) {
294 75 $when_waf_trained = strtotime('+2 day', strtotime($created_at));
295 76 $today = strtotime('today');
296 77
@@ -298,70 +79,30 @@
298 79 }
299 80 return FALSE;
300 81 }
301 82
302 - /**
303 - * Check if the data for the period is available.
304 - *
305 - * @param string $created_at
306 - * Date when the agent manager was created.
307 - *
308 - * @return array
309 - * Returns an array with periods.
310 - */
311 - public static function isPeriodAvailable() {
83 + /**
84 + * Converting a date to the appropriate format.
85 + *
86 + * @param string $date
87 + * Date in any format.
88 + * @param string $format
89 + * The format to which you want to convert the date.
90 + *
91 + * @return string
92 + * Returns converted Date.
93 + */
94 + public static function dateFormatter($date, $format = 'M j, Y \/ H:i') {
95 + if (!$date) {
96 + return __('Unknown', 'wtotem');
97 + }
312 98
313 - $created_at = WebTotemOption::getOption('am_created_at');
314 - if(!$created_at){
315 - return [
316 - 'monthly' => false,
317 - 'yearly' => false,
318 - ];
319 - }
320 - $diff = strtotime(gmdate("Y-m-d H:i:s")) - strtotime($created_at);
321 - $daysCount = floor($diff / 86400);
99 + $time_zone = WebTotemOption::getOption('time_zone_offset');
100 + $user_time = ($time_zone) ? strtotime($time_zone . 'hours', strtotime($date)) : strtotime($date);
322 101
323 - return [
324 - 'monthly' => $daysCount > 7,
325 - 'yearly' => $daysCount > 30,
326 - ];
102 + return date_i18n($format, $user_time);
103 + }
327 104
328 - }
329 -
330 - /**
331 - * Converting a date to the appropriate format.
332 - *
333 - * @param string $date
334 - * Date in any format.
335 - * @param string $format
336 - * The format to which you want to convert the date.
337 - *
338 - * @return string
339 - * Returns converted Date.
340 - * @throws Exception
341 - */
342 - public static function dateFormatter($date, $format = 'M j, Y \/ H:i') {
343 - if (!$date) {
344 - return __('Unknown', 'wtotem');
345 - }
346 -
347 - if ( is_numeric($date) && (int)$date == $date ){
348 - $date = date('Y-m-d H:i', $date);
349 - }
350 -
351 - if($wp_timezone = wp_timezone()){
352 - $UTC = new DateTimeZone("UTC");
353 - $date = new DateTime( $date, $UTC );
354 - $date->setTimezone( new DateTimeZone($wp_timezone->getName()) );
355 - return date_i18n($format,strtotime($date->format('Y-m-d H:i')));
356 - }
357 -
358 - $time_zone = WebTotemOption::getOption('time_zone_offset');
359 - $user_time = ($time_zone) ? strtotime($time_zone . 'hours', strtotime($date)) : strtotime($date);
360 -
361 - return date_i18n($format, $user_time);
362 - }
363 -
364 105 /**
365 106 * Get theme mode data.
366 107 *
367 108 * @return array
@@ -406,24 +147,24 @@
406 147
407 148 case is_array($days):
408 149 $to = $days[1] ?: $days[0];
409 150 $period = [
410 - 'from' => date('Y-m-d 00:00:01', strtotime(self::formatDate($days[0]))),
411 - 'to' => date('Y-m-d 23:59:59', strtotime(self::formatDate($to))),
151 + 'from' => strtotime(date('Y-m-d 00:00:01', strtotime($days[0]))),
152 + 'to' => strtotime(date('Y-m-d 23:59:59', strtotime($to))),
412 153 ];
413 154 break;
414 155
415 156 case $days <= 1:
416 157 $period = [
417 - 'from' => date('Y-m-d H:m:i', strtotime('-24 hours')),
418 - 'to' => date('Y-m-d H:m:i', time()),
158 + 'from' => strtotime('-24 hours'),
159 + 'to' => time(),
419 160 ];
420 161 break;
421 162
422 163 default:
423 164 $period = [
424 - 'from' => date('Y-m-d H:m:i', time() - ($days * 86400)),
425 - 'to' => date('Y-m-d H:m:i'),
165 + 'from' => time() - ($days * 86400),
166 + 'to' => time(),
426 167 ];
427 168 }
428 169
429 170 return $period;
@@ -428,48 +169,8 @@
428 169
429 170 return $period;
430 171 }
431 172
432 - /**
433 - * Converting a date from "j M, Y" format to 'd-m-Y' format.
434 - *
435 - * @return string
436 - * Returns date in new format
437 - */
438 - public static function formatDate($date){
439 - $month = [
440 - 'Jan' => 'Янв',
441 - 'Feb' => 'Фев',
442 - 'Mar' => 'Мар',
443 - 'Apr' => 'Апр',
444 - 'May' => 'Май',
445 - 'Jun' => 'Июн',
446 - 'Jul' => 'Июл',
447 - 'Aug' => 'Авг',
448 - 'Sep' => 'Сен',
449 - 'Oct' => 'Окт',
450 - 'Nov' => 'Ноя',
451 - 'Dec' => 'Дек',
452 - ];
453 -
454 - foreach ($month as $key => $value) {
455 - if (strpos($date, $value)) {
456 - $date = str_replace($value, $key, $date);
457 - }
458 - }
459 -
460 - $pattern = '/^(\d{1,2})\s+([a-zA-Z]+),\s+(\d{4})$/';
461 -
462 - if (preg_match($pattern, $date, $matches)) {
463 - $monthNumber = date_parse($matches[2])['month'];
464 -
465 - return sprintf('%02d-%02d-%04d', $matches[1], $monthNumber, $matches[3]);
466 - }
467 -
468 - return $date;
469 -
470 - }
471 -
472 173 /**
473 174 * Convert an array to a string with quotation marks.
474 175 *
475 176 * @param array $array
@@ -496,9 +197,21 @@
496 197 */
497 198 public static function messageForHuman($message) {
498 199
499 200 $definition = $message;
201 + $excepts = [
202 + 'RESOURCE_NOT_FOUND',
203 + 'DUPLICATE_HOST',
204 + 'INVALID_CREDENTIALS',
205 + 'INVALID_API_KEY',
206 + 'INVALID_TOKEN',
207 + 'PORT_ALREADY_ADDED',
208 + ];
500 209
210 + if (in_array($message, $excepts)) {
211 + return FALSE;
212 + }
213 +
501 214 switch ($message) {
502 215 case 'HOSTS_LIMIT_EXCEEDED':
503 216 $definition = __('Limit of adding sites exceeded.', 'wtotem');
504 217 break;
@@ -513,11 +226,8 @@
513 226
514 227 case 'INVALID_DOMAIN_NAME':
515 228 $definition = __('Invalid Domain Name', 'wtotem');
516 229 break;
517 - default:
518 - $definition = str_replace("_", " ", $definition);
519 - $definition = ucfirst(strtolower($definition));
520 230
521 231 }
522 232 return $definition;
523 233 }
@@ -539,12 +249,9 @@
539 249
540 250 case 'clean':
541 251 case 'up':
542 252 case 'installed':
543 - case 'available':
544 - case 'enable':
545 253 case 'working':
546 - case 'good':
547 254 $status_data = [
548 255 'class' => 'is--status--ok',
549 256 'image' => $path . 'check-mark.svg',
550 257 'icon' => $path . 'icon_success_status.svg',
@@ -571,9 +278,8 @@
571 278 case 'expired':
572 279 case 'no_cert':
573 280 case 'expires':
574 281 case 'open_ports':
575 - case 'warning':
576 282 case 'not_supported':
577 283 case 'not_registered':
578 284 $status_data = [
579 285 'class' => 'is--status--warning',
@@ -582,12 +288,8 @@
582 288 ];
583 289 break;
584 290
585 291 case 'invalid':
586 - case 'revoked':
587 - case 'untrusted':
588 - case 'not_found':
589 - case 'wrong_host':
590 292 case 'error':
591 293 case 'down':
592 294 case 'expires_today':
593 295 case 'infected':
@@ -673,14 +375,8 @@
673 375 "changed" => __('Changed', 'wtotem'),
674 376 "new" => __('New', 'wtotem'),
675 377 "scanned" => __('Scanned', 'wtotem'),
676 378 "quarantine" => __('In quarantine', 'wtotem'),
677 - "good" => __('Good', 'wtotem'),
678 - "wrong_host" => __('Wrong host', 'wtotem'),
679 - "revoked" => __('Revoked', 'wtotem'),
680 - "untrusted" => __('Untrusted', 'wtotem'),
681 - "not_found" => __('Not found', 'wtotem'),
682 - "enable" => __('Enable', 'wtotem'),
683 379 ];
684 380
685 381 return (array_key_exists($status, $statuses)) ? $statuses[$status] : $status;
686 382 }
@@ -717,12 +413,9 @@
717 413 'session_error' => __('This means that the agent did not create a secure session. Possible causes include network issues, wrong server configuration, third-party firewalls. Please contact our support..', 'wtotem'),
718 414 'internal_error' => __('It means that the server is overloaded or there might be some problems with the connection. Usually, the issue resolves itself within 10-15 minutes. If the status does not change during two hours, please cordially contact our support..', 'wtotem'),
719 415 'working' => __('Everything is alright.', 'wtotem'),
720 416 'installed' => __('Everything is alright.', 'wtotem'),
721 - 'available' => __('Everything is alright.', 'wtotem'),
722 417 'not_installed' => __('You need to install agent manager to activate antivirus and firewall.', 'wtotem'),
723 - 'enable' => __('Enabled — the module is active; information is being collected and updated.', 'wtotem'),
724 -
725 418 ];
726 419
727 420 return (array_key_exists($status, $tooltips)) ? $tooltips[$status] : '';
728 421 }
@@ -747,9 +440,9 @@
747 440 $domains[$domain] = $domain;
748 441 }
749 442
750 443 $sites = [];
751 - if(array_key_exists('edges', $data)){
444 + if(isset($data)){
752 445 foreach ($data['edges'] as $site) {
753 446 $site = $site['node'];
754 447 // Take sites only from the multisite network.
755 448 if(array_key_exists($site['hostname'], $domains)) {
@@ -785,10 +478,10 @@
785 478 * @return array
786 479 * Converted data.
787 480 */
788 481 protected static function getStacksData($stacks) {
789 - $apps = file_get_contents(WEBTOTEM_PLUGIN_PATH . '/includes/js/apps.json');
790 - $apps = json_decode($apps, true);
482 + $apps = wp_remote_get(WEBTOTEM_URL . '/includes/js/apps.json');
483 + $apps = json_decode($apps['body'], true);
791 484
792 485 $path = 'https://assets.wtotem.net/images/apps/';
793 486 $defaultIcon = WEBTOTEM_URL . '/includes/img/defaultTechnologiesIcon.svg';
794 487
@@ -839,28 +532,24 @@
839 532
840 533 $list = [];
841 534 $other['count'] = 0;
842 535 $other['names'] = [];
843 -
844 536 foreach ($services as $key => $service){
845 - if(array_key_exists($key, $data) and is_array($data[$key]) and array_key_exists('status', $data[$key])){
846 - $status = self::getServiceStatus($data[$key]['status']);
537 + $status = self::getServiceStatus($data[$key]['status']);
847 538
848 - if(in_array($status['color'], ['red', 'yellow'])){
849 - if(count($list) < 2){
850 - $color = $status['color'] == 'red' ? 'white/' : '';
539 + if(in_array($status['color'], ['red', 'yellow'])){
540 + if(count($list) < 2){
541 + $color = $status['color'] == 'red' ? 'white/' : '';
851 542
852 - $list[$key] = [
853 - 'status' => $status,
854 - 'icon' => 'services/'. $color . $service . '.svg',
855 - 'name' => self::getServiceName( $service ),
856 - ];
857 - } else {
858 - $other['names'][] = self::getServiceName( $service );
859 - $other['count']++;
860 - }
543 + $list[$key] = [
544 + 'status' => $status,
545 + 'icon' => 'services/'. $color . $service . '.svg',
546 + 'name' => self::getServiceName( $service ),
547 + ];
548 + } else {
549 + $other['names'][] = self::getServiceName( $service );
550 + $other['count']++;
861 551 }
862 -
863 552 }
864 553 }
865 554 if($other['names']){
866 555 $other['names'] = implode(",", $other['names']);
@@ -1143,32 +832,16 @@
1143 832 */
1144 833 public static function wafLogs(array $logs_) {
1145 834 $logs = [];
1146 835 foreach ($logs_ as $key => $log) {
836 + $log = $log['node'];
1147 837
1148 838 $logs[$key]['ip'] = $log['ip'];
1149 - $logs[$key]['request'] = urldecode($log['request']);
1150 - $logs[$key]['time'] = self::dateFormatter($log['date']);
1151 - $logs[$key]['country_code'] = strtoupper($log['country']);
1152 - $logs[$key]['country'] = self::getCountryName($log['country']);
1153 - $logs[$key]['blocked'] = $log['blocked'] ? __('Blocked', 'wtotem') : __('Not blocked', 'wtotem');
1154 -
1155 - $more = [
1156 - 'ip' => $log['ip'],
1157 - 'proxy_ip' => $log['proxy_ip'],
1158 - 'source' => $log['source'],
1159 - 'request' => urldecode($log['request']),
1160 - 'user_agent' => $log['user_agent'],
1161 - 'time' => self::dateFormatter($log['date']),
1162 - 'type' => $log['type'],
1163 - 'category' => $log['signature_category'],
1164 - 'country' => self::getCountryName($log['country']),
1165 - 'payload' => urldecode($log['payload']),
1166 - 'hostname' => urldecode($log['hostname']),
1167 - 'is_trusted' => urldecode($log['is_trusted']),
1168 - ];
1169 -
1170 - $logs[$key]['more'] = json_encode($more);
839 + $logs[$key]['request'] = htmlspecialchars(urldecode($log['request']));
840 + $logs[$key]['time'] = self::dateFormatter($log['time']);
841 + $logs[$key]['country_code'] = strtolower($log['country']);
842 + $logs[$key]['country'] = $log['location']['country']['nameEn'];
843 + $logs[$key]['blocked'] = $log['blocked'] ? __('Blocked IP', 'wtotem') : __('Not blocked', 'wtotem');
1171 844 }
1172 845 return $logs;
1173 846 }
1174 847
@@ -1183,25 +856,38 @@
1183 856 */
1184 857 public static function generateWafChart(array $charts) {
1185 858 $sum = 0;
1186 859 foreach ($charts as $chart) {
1187 - $sum += $chart['total_attacks'];
860 + $sum += $chart['attacks'];
1188 861 }
1189 862 if ($sum == 0) {
1190 - return [
1191 - 'chart' => FALSE,
1192 - 'count_attacks' => 0,
1193 - 'count_blocks' => 0,
1194 - 'days' => 0,
1195 - ];
863 + return ['chart' => FALSE, 'count_attacks' => 0, 'count_blocks' => 0];
1196 864 }
1197 865
866 + // Get days count.
867 + $charts_ = $charts;
868 + $first = array_shift($charts_);
869 + $last = array_pop($charts_);
870 + $days = ceil((strtotime($last['time']) - strtotime($first['time'])) / 86400);
1198 871
1199 872 // Set variables.
1200 873 $count_attacks = $count_blocks = 0;
1201 874
1202 875 foreach ($charts as $chart) {
1203 - $result[$chart["type"]] = $chart["statistics"];
876 + if ($days <= 1) {
877 + $time_zone = WebTotemOption::getOption('time_zone_offset');
878 + $userTime = ($time_zone) ? strtotime($time_zone . ' hours', strtotime($chart['time'])) : strtotime($chart['time']);
879 + }
880 + if (($chart['attacks'] and $days == 2) or $days != 2) {
881 + $result[] = [
882 + 'date' => ($days <= 1) ? date("Y-m-d H:00:00", $userTime) : date("Y-m-d", strtotime($chart['time'])),
883 + 'count' => $chart['blocked'],
884 + 'attacks' => $chart['attacks'],
885 + 'blocked' => $chart['blocked'],
886 + ];
887 + $count_attacks += $chart['attacks'];
888 + $count_blocks += $chart['blocked'];
889 + }
1204 890 }
1205 891
1206 892 if (!isset($result)) {
1207 893 return [
@@ -1207,9 +893,8 @@
1207 893 return [
1208 894 'chart' => FALSE,
1209 895 'count_attacks' => 0,
1210 896 'count_blocks' => 0,
1211 - 'days' => 0,
1212 897 ];
1213 898 }
1214 899
1215 900 return [
@@ -1215,8 +900,9 @@
1215 900 return [
1216 901 'chart' => json_encode($result),
1217 902 'count_attacks' => $count_attacks,
1218 903 'count_blocks' => $count_blocks,
904 + 'days' => $days,
1219 905 ];
1220 906 }
1221 907
1222 908 /**
@@ -1268,11 +954,11 @@
1268 954 $attacks = [];
1269 955 $countries = [];
1270 956 $labels = [];
1271 957 foreach ($data as $value) {
1272 - $attacks[] = $value['total_attack'];
1273 - $labels[] = self::getCountryName($value['name']);
1274 - $countries[] = self::getCountryName($value['name'], 'en-US');
958 + $attacks[] = $value['attacks'];
959 + $labels[] = self::getCountryName($value['country']);
960 + $countries[] = $value['location']['country']['nameEn'];
1275 961 }
1276 962 $result = ['attacks' => $attacks, 'countries' => $countries, 'labels' => $labels];
1277 963
1278 964 if (!$attacks) {
@@ -1281,167 +967,72 @@
1281 967
1282 968 return json_encode($result, TRUE);
1283 969 }
1284 970
1285 - /**
1286 - * Reassembling the antivirus logs.
1287 - *
1288 - * @param array $logs_
1289 - * Antivirus logs from WebTotem.
1290 - *
1291 - * @return array
1292 - * Reassembled array of logs.
1293 - */
1294 - public static function getAntivirusLogsData(array $logs_) {
1295 - if(!$logs_){
1296 - return [];
1297 - }
1298 - $logs = [];
1299 - foreach ($logs_ as $key => $log) {
971 + /**
972 + * Reassembling the antivirus logs.
973 + *
974 + * @param array $logs_
975 + * Antivirus logs from WebTotem.
976 + *
977 + * @return array
978 + * Reassembled array of logs.
979 + */
980 + public static function getAntivirusLogs(array $logs_) {
981 + $logs = [];
982 + foreach ($logs_ as $key => $log) {
983 + $log = $log['node'];
1300 984
1301 - if(isset($log['infectedNum']) and $log['infectedNum']){
1302 - $log['status_info'] = 'infected';
1303 - $log['status_name'] = __('Infected', 'wtotem');
1304 - } else {
1305 - $log['status_info'] = 'clean';
1306 - $log['status_name'] = __('Clean', 'wtotem');
1307 - }
985 + $file_info = new SplFileInfo(urldecode($log['filePath']));
1308 986
1309 - $log['date'] = self::dateFormatter($log['date'], 'd M Y');
1310 - $log['data'] = json_encode($log);
987 + $log['original_path'] = $log['filePath'];
988 + $log['file_path'] = $file_info->getPath() . '/';
989 + $log['file_name'] = $file_info->getFilename();
990 + $log['time'] = self::dateFormatter($log['time']);
991 + $log['permissions_changed'] = $log['permissionsChanged'];
992 + $log['status'] = self::getStatusData($log['event']);
993 + $log['class'] = 'wt-text--green';
1311 994
1312 - $logs[$key] = $log;
1313 - }
1314 - return $logs;
1315 - }
995 + switch ($log['event']) {
996 + case 'modified':
997 + case 'quarantine':
998 + $log['class'] = "wt-text--yellow";
999 + break;
1316 1000
1317 - /**
1318 - * Reassembling the Infected Files logs.
1319 - *
1320 - * @param array $logs_
1321 - * Antivirus logs from WebTotem.
1322 - *
1323 - * @return array
1324 - * Reassembled array of Infected Files logs.
1325 - */
1326 - public static function getInfectedFilesData(array $logs_) {
1327 - $logs = [];
1328 - foreach ($logs_ as $key => $log) {
1329 - $full_path = urldecode($log['name']);
1330 - $log['file_name'] = $name = basename($full_path);
1331 - $log['file_path'] = str_replace($name, "", $full_path);
1332 - $log['id'] = $key;
1001 + case 'deleted':
1002 + $log['class'] = "wt-text--light-gray";
1003 + break;
1333 1004
1334 - $logs[$key] = $log;
1335 - }
1336 - return $logs;
1337 - }
1005 + case 'infected':
1006 + $log['class'] = "wt-text--red";
1007 + break;
1008 + }
1338 1009
1339 - /**
1340 - * Reassembling the antivirus logs.
1341 - *
1342 - * @param array $logs_
1343 - * Antivirus logs from WebTotem.
1344 - *
1345 - * @return array
1346 - * Reassembled array of logs.
1347 - */
1348 - public static function getAntivirusAlerts(array $logs_) {
1349 - $logs = [];
1350 - foreach ($logs_ as $key => $log) {
1351 -
1352 - switch ($log['type']) {
1353 - case 'file':
1354 - $log['type_text'] = "Suspicious file";
1355 - break;
1356 -
1357 - case 'skippedPaths':
1358 - $log['type_text'] = "Unscanned Paths";
1359 - break;
1360 -
1361 - default:
1362 - $log['type_text'] = $log['type'];
1363 - }
1364 -
1365 - $logs[$key] = $log;
1366 - }
1367 - return $logs;
1010 + $logs[$key] = $log;
1368 1011 }
1012 + return $logs;
1013 + }
1369 1014
1370 - /**
1371 - * Get open path data.
1372 - *
1373 - * @param array $_ports
1374 - * Open ports array.
1375 - *
1376 - * @return array
1377 - * Reassembled array of open ports.
1378 - */
1379 - public static function getOpenPortsData($ports) {
1380 - if(!$ports){
1381 - return [];
1382 - }
1383 - foreach ($ports as $key => $port) {
1384 - $summary = '';
1385 - if($port['cves']){
1386 - foreach ($port['cves'] as $item){
1387 - $summary .= '<p>' . $item['summary'] . '</p>';
1388 - }
1389 - }
1390 - $ports[$key]['cve_summary'] = $summary;
1391 - }
1392 - return $ports;
1015 + /**
1016 + * Reassembling the quarantine logs.
1017 + *
1018 + * @param array $logs_
1019 + * Quarantine logs from WebTotem.
1020 + *
1021 + * @return array
1022 + * Reassembled array of logs.
1023 + */
1024 + public static function getQuarantineLogs(array $logs_) {
1025 + $logs = [];
1026 + foreach ($logs_ as $key => $log) {
1027 + $logs[$key] = $log;
1028 + $logs[$key]['path'] = urldecode($log['path']);
1029 + $logs[$key]['date'] = self::dateFormatter($log['date']);
1393 1030 }
1394 1031
1032 + return $logs;
1033 + }
1395 1034
1396 -// /**
1397 -// * Reassembling the quarantine logs.
1398 -// *
1399 -// * @param array $logs_
1400 -// * Quarantine logs from WebTotem.
1401 -// *
1402 -// * @return array
1403 -// * Reassembled array of logs.
1404 -// */
1405 -// public static function getQuarantineLogs(array $logs_) {
1406 -// $logs = [];
1407 -// foreach ($logs_ as $key => $log) {
1408 -// $logs[$key] = $log;
1409 -// $logs[$key]['path'] = urldecode($log['name']);
1410 -// $logs[$key]['date'] = self::dateFormatter($log['date']);
1411 -// }
1412 -//
1413 -// return $logs;
1414 -// }
1415 -
1416 - /**
1417 - * Reassembling the Quarantine logs.
1418 - *
1419 - * @param array $list_
1420 - * Quarantine path list from WebTotem.
1421 - *
1422 - * @return array
1423 - * Reassembled array of Quarantine logs.
1424 - */
1425 - public static function getQuarantineListData(array $list_) {
1426 - if(!$list_){
1427 - return [];
1428 - }
1429 - $list = [];
1430 -
1431 - foreach ($list_ as $key => $log) {
1432 -
1433 - $full_path = urldecode($log['name']);
1434 - $log['path'] = $full_path;
1435 - $log['file_name'] = $name = basename($full_path);
1436 - $log['file_path'] = str_replace($name, "", $full_path);
1437 - $log['id'] = $key;
1438 -
1439 - $list[$key] = $log;
1440 - }
1441 - return $list;
1442 - }
1443 -
1444 1035 /**
1445 1036 * Generate an array of IP address data.
1446 1037 *
1447 1038 * @param array $data
@@ -1455,9 +1046,11 @@
1455 1046 public static function getIpList(array $data, $list_name) {
1456 1047 $list = [];
1457 1048 foreach ($data as $item) {
1458 1049 $list[] = [
1459 - 'ip' => $item,
1050 + 'ip' => $item['ip'],
1051 + 'id' => $item['id'],
1052 + 'created_at' => self::dateFormatter($item['createdAt']),
1460 1053 'list_name' => $list_name,
1461 1054 ];
1462 1055 }
1463 1056 return $list;
@@ -1463,8 +1056,30 @@
1463 1056 return $list;
1464 1057 }
1465 1058
1466 1059 /**
1060 + * Generate an array of URL address data.
1061 + *
1062 + * @param array $data
1063 + * URL addresses data from WebTotem.
1064 + *
1065 + * @return array
1066 + * Returns array of data.
1067 + */
1068 + public static function getUrlAllowList(array $data) {
1069 + $list = [];
1070 + foreach ($data as $item) {
1071 + $list[] = [
1072 + 'url' => $item['url'],
1073 + 'id' => $item['id'],
1074 + 'created_at' => self::dateFormatter($item['createdAt']),
1075 + 'list_name' => 'url_allow',
1076 + ];
1077 + }
1078 + return $list;
1079 + }
1080 +
1081 + /**
1467 1082 * Convert IP list to be transferred to WebTotem.
1468 1083 *
1469 1084 * @param string $data
1470 1085 * IP list.
@@ -1476,48 +1091,26 @@
1476 1091 if (!$data) {
1477 1092 return FALSE;
1478 1093 }
1479 1094
1480 - return preg_split("/(?(?=[\s,])[^.]|^$)/", $data);
1095 + $ips = preg_split("/(?(?=[\s,])[^.]|^$)/", $data);
1481 1096
1482 - }
1483 - /**
1484 - * Validate Ip or Cidr.
1485 - *
1486 - * @param string $input
1487 - * IP address. (IPv4 / IPv6 + CIDR)
1488 - *
1489 - * @return bool
1490 - * Returns the converted string.
1491 - */
1492 - public static function validateIpOrCidr(string $input): bool {
1493 -
1494 - if (strpos($input, '/') !== false) {
1495 - [$ip, $mask] = explode('/', $input, 2);
1496 -
1497 - if (!filter_var($ip, FILTER_VALIDATE_IP)) {
1498 - return false;
1499 - }
1500 -
1501 - if (!ctype_digit($mask)) {
1502 - return false;
1503 - }
1504 -
1505 - $mask = (int)$mask;
1506 -
1507 - if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4)) {
1508 - return $mask >= 0 && $mask <= 32;
1509 - }
1510 -
1511 - if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6)) {
1512 - return $mask >= 0 && $mask <= 128;
1513 - }
1514 -
1515 - return false;
1097 + if (is_array($ips)) {
1098 + $ips_ = '[';
1099 + foreach ($ips as $ip) {
1100 + if (!empty($ip)) {
1101 + $ips_ .= '"' . $ip . '",';
1516 1102 }
1103 + }
1104 + $ips_ = substr($ips_, 0, -1);
1105 + $ips_ .= ']';
1106 + }
1107 + else {
1108 + $ips_ = '"' . $ips . '"';
1109 + }
1517 1110
1518 - return filter_var($input, FILTER_VALIDATE_IP) !== false;
1519 - }
1111 + return $ips_;
1112 + }
1520 1113
1521 1114 /**
1522 1115 * Get data of the country with the most attacks.
1523 1116 *
@@ -1522,8 +1115,10 @@
1522 1115 * Get data of the country with the most attacks.
1523 1116 *
1524 1117 * @param array $map
1525 1118 * Map logs from WebTotem.
1119 + * @param int $count_attacks
1120 + * Total attacks.
1526 1121 *
1527 1122 * @return array
1528 1123 * Returns array of data.
1529 1124 */
@@ -1529,13 +1124,13 @@
1529 1124 */
1530 1125 public static function getMostAttacksData($map) {
1531 1126
1532 1127 if ($map) {
1533 - $most_attacks_key = array_search(max(array_column($map, 'total_attack')), array_column($map, 'total_attack'));
1534 - $total_attacks = array_sum(array_column($map, 'total_attack'));
1128 + $most_attacks_key = array_search(max(array_column($map, 'attacks')), array_column($map, 'attacks'));
1129 + $total_attacks = array_sum(array_column($map, 'attacks'));
1535 1130
1536 - $data['percent'] = ($total_attacks) ? round($map[$most_attacks_key]['total_attack'] / $total_attacks * 100) : 0;
1537 - $data['country'] = self::getCountryName($map[$most_attacks_key]['name']);
1131 + $data['percent'] = ($total_attacks) ? round($map[$most_attacks_key]['attacks'] / $total_attacks * 100) : 0;
1132 + $data['country'] = self::getCountryName($map[$most_attacks_key]['country']);
1538 1133 $data['offset'] = 176 / 100 * (100 - $data['percent']);
1539 1134
1540 1135 return $data;
1541 1136 }
@@ -1542,35 +1137,8 @@
1542 1137
1543 1138 return ['percent' => 0, 'country' => FALSE, 'offset' => 0];
1544 1139 }
1545 1140
1546 - /**
1547 - * Get data on the three most attacking countries.
1548 - *
1549 - * @param array $map
1550 - * Map logs from WebTotem.
1551 - *
1552 - * @return array
1553 - * Returns array of data.
1554 - */
1555 - public static function getTreeMostAttacksData($map) {
1556 - $total_attacks = array_sum(array_column($map, 'attacks'));
1557 -
1558 - if ($map) {
1559 - array_multisort (array_column($map, 'attacks'), SORT_DESC, $map);
1560 - $data = array_slice($map, 0, 3);
1561 -
1562 - foreach ($data as $key => $value){
1563 - $data[$key]['percent'] = round($value['attacks'] / $total_attacks * 100);
1564 - $data[$key]['country'] = self::getCountryName($value['country']);
1565 - }
1566 -
1567 - return $data;
1568 - }
1569 -
1570 - return [];
1571 - }
1572 -
1573 1141 /**
1574 1142 * Getting the country name by two-letter code.
1575 1143 *
1576 1144 * @param string $key
@@ -1578,19 +1146,16 @@
1578 1146 *
1579 1147 * @return string
1580 1148 * Returns country name.
1581 1149 */
1582 - public static function getCountryName($key, $lang = false) {
1583 - if($lang == 'en-US'){
1584 - $countries = WebTotemCountryManager::getCountiesNameByCode();
1585 - } else {
1586 - $countries = WebTotemCountryManager::getStandardList();
1587 - }
1150 + public static function getCountryName($key) {
1151 + $countries = WebTotemCountryManager::getStandardList();
1588 1152 $key = (string) $key;
1589 1153
1590 1154 return (array_key_exists($key, $countries)) ? $countries[$key] : $key;
1591 1155 }
1592 1156
1157 +
1593 1158 /**
1594 1159 * Get configs data.
1595 1160 *
1596 1161 * @param array $array
@@ -1621,44 +1186,25 @@
1621 1186 * @return array
1622 1187 * Configs data array.
1623 1188 */
1624 1189 public static function getWafSettingData(array $settings) {
1625 - $_settings['gdn']['checked'] = (isset($settings['global_defense_network']) && !$settings['global_defense_network']) ? '' : 'checked';
1190 + $_settings['gdn']['checked'] = (isset($settings['gdn']) && !$settings['gdn']) ? '' : 'checked';
1626 1191 $_settings['dos'] = [
1627 - 'checked' => (isset($settings['dos_protect']) && !$settings['dos_protect']) ? '' : 'checked',
1628 - 'visually' => (isset($settings['dos_protect']) && !$settings['dos_protect']) ? 'visually-hidden' : '',
1192 + 'checked' => (isset($settings['dosProtection']) && !$settings['dosProtection']) ? '' : 'checked',
1193 + 'visually' => (isset($settings['dosProtection']) && !$settings['dosProtection']) ? 'visually-hidden' : '',
1629 1194 ];
1630 - $_settings['dos_limit'] = $settings['dos_limit'] ?: 1000;
1195 + $_settings['dos_limit'] = $settings['dosLimit'] ?: 1000;
1631 1196
1632 1197 $_settings['login_attempt'] = [
1633 - 'checked' => (isset($settings['login_protect']) && !$settings['login_protect']) ? '' : 'checked',
1634 - 'visually' => (isset($settings['login_protect']) && !$settings['login_protect']) ? 'visually-hidden' : '',
1198 + 'checked' => (isset($settings['loginAttemptsProtection']) && !$settings['loginAttemptsProtection']) ? '' : 'checked',
1199 + 'visually' => (isset($settings['loginAttemptsProtection']) && !$settings['loginAttemptsProtection']) ? 'visually-hidden' : '',
1635 1200 ];
1636 - $_settings['login_attempt_limit'] = $settings['login_attempt_limit'] ?: 20;
1201 + $_settings['login_attempt_limit'] = $settings['loginAttemptsLimit'] ?: 20;
1637 1202
1638 1203 return $_settings;
1639 1204 }
1640 1205
1641 - /**
1642 - * Get plugin settings data.
1643 - *
1644 - * @return array
1645 - * Configs data array.
1646 - */
1647 - public static function getPluginSettingsData() {
1648 -
1649 - $settings = WebTotemOption::getPluginSettings();
1650 - $_settings = $settings;
1651 -
1652 - $_settings['hide_wp_version_checked'] = (array_key_exists('hide_wp_version', $settings) and $settings['hide_wp_version']) ? 'checked' : '';
1653 - $_settings['disable_user_enumeration_checked'] = (array_key_exists('disable_user_enumeration', $settings) and $settings['disable_user_enumeration']) ? 'checked' : '';
1654 - $_settings['recaptcha_checked'] = (array_key_exists('recaptcha', $settings) and $settings['recaptcha']) ? 'checked' : '';
1655 - $_settings['two_factor_checked'] = (array_key_exists('two_factor', $settings) and $settings['two_factor']) ? 'checked' : '';
1656 -
1657 - return $_settings;
1658 - }
1659 -
1660 - /**
1206 + /**
1661 1207 * Replace array indexes by key.
1662 1208 *
1663 1209 * @param array $array
1664 1210 * Original array.
@@ -1697,384 +1243,70 @@
1697 1243 return $randomString;
1698 1244 }
1699 1245
1700 1246 /**
1701 - * Encodes the less than, greater than, ampersand,double quote
1702 - * and single quote characters. Will never double encode entities.
1703 - *
1704 - * @see https://developer.wordpress.org/reference/functions/esc_attr/
1705 - *
1706 - * @param string $text
1707 - * The text which is to be encoded.
1708 - *
1709 - * @return string
1710 - * The encoded text with HTML entities.
1711 - */
1712 - public static function escape($text = '') {
1713 - return esc_attr($text);
1714 - }
1247 + * Encodes the less than, greater than, ampersand,double quote
1248 + * and single quote characters. Will never double encode entities.
1249 + *
1250 + * @see https://developer.wordpress.org/reference/functions/esc_attr/
1251 + *
1252 + * @param string $text
1253 + * The text which is to be encoded.
1254 + *
1255 + * @return string
1256 + * The encoded text with HTML entities.
1257 + */
1258 + public static function escape($text = '')
1259 + {
1260 + return esc_attr($text);
1261 + }
1715 1262
1716 - /**
1717 - * Throw generic exception.
1718 - *
1719 - * @throws Exception
1720 - *
1721 - * @param string $message
1722 - * Error or information message.
1723 - * @param string $type
1724 - * Either info or error.
1725 - *
1726 - * @return bool
1727 - * False all the time, used for debug.
1728 - */
1729 - public static function throwException($message, $type = 'error') {
1730 - if (defined('WTOTEM_THROW_EXCEPTIONS') && WTOTEM_THROW_EXCEPTIONS === true && is_string($message) ) {
1731 - $message = str_replace( '<strong>WebTotem:</strong>', ($type === 'error' ? __('Error:', 'wtotem') : __('Info:', 'wtotem')), $message );
1732 - throw new Exception($message, $type === 'error' ? 157 : 333);
1733 - }
1734 - return false;
1735 - }
1736 -
1737 - /**
1738 - * Get audit logs data
1739 - *
1740 - * @return array
1741 - */
1742 - public static function getAuditLogs($data, $dates_count) {
1743 - $logs = [];
1744 - foreach ($data as $datum){
1745 - $date_time = strtotime($datum['created_at']);
1746 - $date = self::dateFormatter($date_time, 'M j, Y');
1747 -
1748 - $logs[$date]['date'] = $date;
1749 - $logs[$date]['count'] = $dates_count[$date];
1750 - $logs[$date]['logs'][] = [
1751 - 'time' => self::dateFormatter($date_time,'H:i'),
1752 - 'user_name' => $datum['user_name'],
1753 - 'status' => $datum['status'],
1754 - 'title' => $datum['title'],
1755 - 'event' => $datum['event'],
1756 - 'description' => $datum['description'],
1757 - 'ip' => $datum['ip'],
1758 - 'viewed' => (int) !$datum['viewed']
1759 - ];
1760 - }
1761 - return $logs;
1762 - }
1763 -
1764 - /**
1765 - * Update user's plugins cve data
1766 - *
1767 - * @return void
1768 - */
1769 - public static function updateCveData() {
1770 - require_once ABSPATH . 'wp-admin/includes/plugin.php';
1771 - $all_plugins = get_plugins();
1772 -
1773 - $list = [];
1774 - foreach ($all_plugins as $plugin) {
1775 - if($plugin['TextDomain'] and $plugin['Version']){
1776 - $list[] = '{"technology": "' . $plugin['TextDomain'] . '", "version": "' . $plugin['Version'] . '"}';
1777 - }
1778 - }
1779 - $list = implode(', ', $list ?? []);
1780 -
1781 - $response = WebTotemAPI::getCVE($list);
1782 - $cve_list = $response ? WebTotem::arrayMapIndex($response, 'technology') : [];
1783 -
1784 - $update_plugins = get_site_transient( 'update_plugins' );
1785 - $update_plugins = WebTotem::convertObjectToArray($update_plugins->response);
1786 -
1787 - $values = '';
1788 - WebTotemDB::deleteData([], 'plugins_cve_list');
1789 - foreach ($all_plugins as $key => $plugin) {
1790 - if(array_key_exists($plugin['TextDomain'], $cve_list)){
1791 - $new_version = $update_plugins[$key]['new_version'] ?? 0;
1792 - $cves = $cve_list[$plugin['TextDomain']]['cves'];
1793 - if ($cves){
1794 - foreach ($cves as $cve){
1795 - $cve['published'] = self::dateFormatter($cve['published'], 'Y-m-d');
1796 - $cve['summary'] = str_replace("'", "", $cve['summary']);
1797 - $values .= sprintf("('%s','%s','%s','%s','%s','%s'),",
1798 - $cve['cve_id'],
1799 - $plugin['Name'],
1800 - $plugin['TextDomain'],
1801 - $plugin['Version'],
1802 - $new_version,
1803 - json_encode($cve)
1804 - );
1805 - }
1806 - }
1807 - }
1808 - }
1809 -
1810 - if($values){
1811 - $values = substr_replace($values, ";", -1);
1812 - $columns = '(cve_id, plugin_name, slug, plugin_version, new_version, cve_data )';
1813 - WebTotemDB::setRows('plugins_cve_list', $columns, $values);
1814 - }
1815 -
1816 - }
1817 -
1818 - public static function getPluginVersionFromRepository($slug) {
1819 - $url = "https://api.wordpress.org/plugins/info/1.2/?action=plugin_information&request[slugs][]={$slug}";
1820 - $response = wp_remote_get($url); // WPOrg API call
1821 - $plugins = json_decode($response['body']);
1822 -
1823 - // traverse $response object
1824 - foreach($plugins as $key => $plugin) {
1825 - $version = $plugin->version;
1826 - }
1827 - return $version;
1828 - }
1829 -
1830 - /**
1831 - * Update user's plugins cve data
1832 - *
1833 - * @return bool
1834 - */
1835 - public static function updateCveDataByPluginName($plugin_data) {
1836 - if(!$plugin_data['TextDomain'] or !$plugin_data['Version']){
1837 - return false;
1838 - }
1839 -
1840 - $list = WebTotemAPI::getCVE('{"technology": "' . $plugin_data['TextDomain'] . '", "version": "' . $plugin_data['Version'] . '"}');
1841 - $cve_list = WebTotem::arrayMapIndex($list, 'technology');
1842 -
1843 - $values = '';
1844 - WebTotemDB::deleteData(['slug' => $plugin_data['TextDomain']], 'plugins_cve_list');
1845 - if(array_key_exists($plugin_data['TextDomain'], $cve_list) and $cve_list[$plugin_data['TextDomain']]['cves']){
1846 - $has_new_version = WebTotem::getPluginVersionFromRepository($plugin_data['TextDomain']);
1847 - foreach ($cve_list[$plugin_data['TextDomain']]['cves'] as $cve){
1848 - $cve['published'] = self::dateFormatter($cve['published'], 'Y-m-d');
1849 - $values .= sprintf("('%s','%s','%s','%s','%s','%s'),",
1850 - $cve['cve_id'],
1851 - $plugin_data['Name'],
1852 - $plugin_data['TextDomain'],
1853 - $plugin_data['Version'],
1854 - ($has_new_version and $has_new_version != $plugin_data['Version']) ? $has_new_version : 0,
1855 - json_encode($cve)
1856 - );
1857 - }
1858 - $values = substr_replace($values, ";", -1);
1859 - $columns = '(cve_id, plugin_name, slug, plugin_version, new_version, cve_data)';
1860 - WebTotemDB::setRows('plugins_cve_list', $columns, $values);
1861 - }
1862 -
1863 - return true;
1864 - }
1865 -
1866 - public static function get_plugin_info($plugin_slug) {
1867 - include_once(ABSPATH . 'wp-admin/includes/plugin.php');
1868 -
1869 - $all_plugins = get_plugins();
1870 - $plugin_file = "$plugin_slug/$plugin_slug.php";
1871 -
1872 - if (isset($all_plugins[$plugin_file])) {
1873 - $plugin_info = $all_plugins[$plugin_file];
1874 - return $plugin_info;
1875 - } else {
1876 - return false;
1877 - }
1878 - }
1879 -
1880 - /**
1881 - * Get confidential files data
1882 - *
1883 - * @return array
1884 - */
1885 - public static function preparePluginsCveList($data) {
1886 - foreach ($data as $key => $datum){
1887 - $data[$key]['cve_data'] = json_decode($datum['cve_data'], true);
1888 - $data[$key]['cve_data']['published'] = self::dateFormatter($data[$key]['cve_data']['published'], 'M j, Y');
1889 - }
1890 - return $data;
1891 - }
1892 1263 /**
1893 - * Get confidential files data
1264 + * Get notifications array.
1894 1265 *
1895 1266 * @return array
1267 + * Returns notifications array.
1896 1268 */
1897 - public static function getConfidentialFiles($data) {
1898 - foreach ($data as $key => $datum){
1899 - $data[$key]['modified_at'] = date_i18n('M j, Y \/ H:i', strtotime($datum['modified_at']));
1900 - $data[$key]['size'] = self::humanFilesize($datum['size']);
1901 - $data[$key]['name'] = urldecode($datum['name']);
1902 - $data[$key]['path'] = urldecode($datum['path']);
1903 - }
1904 - return $data;
1905 - }
1269 + public static function getNotifications() {
1906 1270
1907 - /**
1908 - * Get confidential files data
1909 - *
1910 - * @return array
1911 - */
1912 - public static function prepareLinksData($data) {
1913 - foreach ($data as $key => $datum){
1271 + $notifications_data = WebTotemOption::getNotificationsData();
1272 + $notifications = [];
1914 1273
1915 - $content = $datum['content'];
1916 - $source = $datum['source'];
1917 - if(strpos($content, 'http://') !== 0 and strpos($content, 'https://') !== 0 and strpos($content, '//') !== 0){
1918 - $match = substr_count($content, '../');
1919 - $content = str_replace("../", "", $content);
1920 - $content = ltrim($content, '/');
1274 + foreach ($notifications_data as $notification) {
1275 + switch ($notification['type']) {
1276 + case 'error':
1277 + $image = 'alert-error.svg';
1278 + $class = 'wtotem_alert__title_red';
1279 + break;
1921 1280
1922 - for($i=0; $i < 1+$match; $i++){
1923 - $source = substr($source, 0, strrpos($source, "/"));
1924 - }
1925 - $data[$key]['link'] = $source . '/' . $content;
1926 - } else {
1927 - $data[$key]['link'] = $content;
1928 - }
1929 - }
1930 - return $data;
1931 - }
1281 + case 'warning':
1282 + $image = 'alert-warning.svg';
1283 + $class = 'wtotem_alert__title_yellow';
1284 + break;
1932 1285
1286 + case 'success':
1287 + $image = 'alert-success.svg';
1288 + $class = 'wtotem_alert__title_green';
1289 + break;
1933 1290
1934 - /**
1935 - * Building navigation and forming a template
1936 - *
1937 - * @param integer $limit
1938 - * number of entries per 1 page
1939 - * @param integer $count_all
1940 - * total number of all entries
1941 - * @param integer $currentPage
1942 - * the number of the page being viewed
1943 - * @param integer $nextPrev
1944 - * Show the "Forward" and "Back" buttons
1945 - * @return mixed
1946 - * Generated navigation template ready for output
1947 - */
1948 - public static function paginationBuild($limit, $count_all, $currentPage = 1, $nextPrev = true) {
1949 - if( $limit < 1 OR $count_all <= $limit ) return '';
1950 - $count_pages = ceil( $count_all / $limit );
1291 + case 'info':
1292 + $image = 'info-blue.svg';
1293 + $class = 'wtotem_alert__title_blue';
1294 + break;
1295 + }
1951 1296
1952 - $spread = 3;
1953 - $separator = "<i>...</i>";
1954 - $wrap = "<div class=\"wtotem_pagination\">{pages}</div>";
1955 -
1956 - $nextTitle = '←';
1957 - $prevTitle = '→';
1958 -
1959 - $currentPage = intval( $currentPage );
1960 - if( $currentPage < 1 ) $currentPage = 1;
1961 -
1962 - $shift_start = max( $currentPage - $spread, 2 );
1963 - $shift_end = min( $currentPage + $spread, $count_pages-1 );
1964 - if( $shift_end < $spread * 2 ) {
1965 - $shift_end = min( $spread * 2, $count_pages-1 );
1966 - }
1967 - if( $shift_end == $count_pages - 1 AND $shift_start > 3 ) {
1968 - $shift_start = max( 3, min( $count_pages - $spread * 2 + 1, $shift_start ) );
1969 - }
1970 -
1971 - $list = self::getPaginationItem( 1, $currentPage );
1972 -
1973 - if ($shift_start == 3) {
1974 - $list .= self::getPaginationItem( 2, $currentPage );
1975 - } elseif ( $shift_start > 3 ) {
1976 - $list .= $separator;
1977 - }
1978 -
1979 - for( $i = $shift_start; $i <= $shift_end; $i++ ) {
1980 - $list .= self::getPaginationItem( $i, $currentPage );
1981 - }
1982 -
1983 - $last_page = $count_pages - 1;
1984 - if( $shift_end == $last_page-1 ){
1985 - $list .= self::getPaginationItem( $last_page, $currentPage );
1986 - } elseif( $shift_end < $last_page ) {
1987 - $list .= $separator;
1988 - }
1989 -
1990 - $list .= self::getPaginationItem( $count_pages, $currentPage );
1991 -
1992 - if( $nextPrev ) {
1993 - $list = self::getPaginationItem(
1994 - $currentPage > 1 ? $currentPage - 1 : 0,
1995 - $currentPage,
1996 - $nextTitle)
1997 - . $list
1998 - . self::getPaginationItem(
1999 - $currentPage < $count_pages ? $currentPage + 1 : 0,
2000 - $currentPage,
2001 - $prevTitle
2002 - );
2003 - }
2004 -
2005 - return str_replace( "{pages}", $list, $wrap );
1297 + $notifications[] = [
1298 + "text" => $notification['notice'],
1299 + "id" => self::generateRandomString(8),
1300 + "type" => self::getStatusText($notification['type']),
1301 + "image" => $image,
1302 + "class" => $class,
1303 + ];
2006 1304 }
2007 1305
2008 - /**
2009 - * Button/Link Formation
2010 - * @param int $page_num
2011 - * page number
2012 - * @param string $currentPage
2013 - * current page
2014 - * @param string $page_name
2015 - * if specified, the text will be displayed instead of the page number
2016 - * @return string
2017 - * span block with active page or link.
2018 - */
2019 - public static function getPaginationItem( $page_num, $currentPage, $page_name = '' ) {
2020 - if($page_num === 0){return '';}
2021 - $page_name = $page_name ?: $page_num;
1306 + return $notifications;
1307 + }
2022 1308
2023 - if( $currentPage == $page_num ) {
2024 - return "<span class=\"wtotem_pagination__number wtotem_pagination__number_active\">{$page_name}</span>";
2025 - } else {
2026 - return "<a href=\"#\" data-page=\"{$page_num}\" class=\"wtotem_pagination__number\">{$page_name}</a>";
2027 - }
2028 - }
2029 -
2030 - /**
2031 - * Get notifications array.
2032 - *
2033 - * @return array
2034 - * Returns notifications array.
2035 - */
2036 - public static function getNotifications() {
2037 -
2038 - $notifications_data = WebTotemOption::getNotificationsData();
2039 - $notifications = [];
2040 -
2041 - foreach ($notifications_data as $notification) {
2042 - switch ($notification['type']) {
2043 - case 'error':
2044 - $image = 'alert-error.svg';
2045 - $class = 'wtotem_alert__title_red';
2046 - break;
2047 -
2048 - case 'warning':
2049 - $image = 'alert-warning.svg';
2050 - $class = 'wtotem_alert__title_yellow';
2051 - break;
2052 -
2053 - case 'success':
2054 - $image = 'alert-success.svg';
2055 - $class = 'wtotem_alert__title_green';
2056 - break;
2057 -
2058 - case 'info':
2059 - $image = 'info-blue.svg';
2060 - $class = 'wtotem_alert__title_blue';
2061 - break;
2062 - }
2063 -
2064 - $notifications[] = [
2065 - "text" => $notification['notice'],
2066 - "id" => self::generateRandomString(8),
2067 - "type" => self::getStatusText($notification['type']),
2068 - "type_raw" => $notification['type'],
2069 - "image" => $image,
2070 - "class" => $class,
2071 - ];
2072 - }
2073 -
2074 - return $notifications;
2075 - }
2076 -
2077 1309 /**
2078 1310 * Get current agent installation statuses.
2079 1311 *
2080 1312 * @param array $agents_statuses
@@ -2085,9 +1317,10 @@
2085 1317 */
2086 1318 public static function getAgentsStatuses(array $agents_statuses) {
2087 1319 $agents = ['am', 'waf', 'av'];
2088 1320 $installing_statuses = [
2089 - 'not_available',
1321 + 'not_installed',
1322 + 'installing',
2090 1323 'internal_error',
2091 1324 'update_error',
2092 1325 'config_error',
2093 1326 'session_error',
@@ -2101,9 +1334,9 @@
2101 1334 $option_statuses[$agent] = $status['option_status'] ?: FALSE;
2102 1335
2103 1336 if ($agent == 'am') {
2104 1337 if ($status['file_status']) {
2105 - $process_statuses[$agent] = 'available';
1338 + $process_statuses[$agent] = 'installed';
2106 1339 }
2107 1340 else {
2108 1341 $process_statuses[$agent] = 'failed';
2109 1342 }
@@ -2112,13 +1345,13 @@
2112 1345 if ($status['file_status']) {
2113 1346 if (in_array($agents_statuses[$agent], $installing_statuses)) {
2114 1347 $process_statuses[$agent] = 'installing';
2115 1348 }
2116 - elseif ($agents_statuses[$agent] == 'not_available') {
1349 + elseif ($agents_statuses[$agent] == 'agent_not_available') {
2117 1350 $process_statuses[$agent] = 'failed';
2118 1351 }
2119 1352 else {
2120 - $process_statuses[$agent] = 'available';
1353 + $process_statuses[$agent] = 'installed';
2121 1354 }
2122 1355 }
2123 1356 else {
2124 1357 $process_statuses[$agent] = 'installing';