-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathhm-proxy-access.php
More file actions
77 lines (61 loc) · 1.99 KB
/
Copy pathhm-proxy-access.php
File metadata and controls
77 lines (61 loc) · 1.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
<?php
/**
* Plugin Name: HM Proxy Access
* Description: Limit access and check if the site is accessed though a HM Proxy
*/
namespace HM\Proxy_Access;
define( 'HM_IS_PROXIED', is_proxied() );
function get_proxy_hostnames() {
return apply_filters( 'hm_proxy_hostnames', array(
'eu.proxy.hmn.md',
'au.proxy.hmn.md',
'us-w.proxy.hmn.md',
'us-e.proxy.hmn.md',
'gb.proxy.hmn.md',
'sg.proxy.hmn.md',
// Legacy AWS proxy
'us-west-1.aws.hmn.md',
'us-east-1.aws.hmn.md',
'eu-west-1.aws.hmn.md',
'eu-west-2.aws.hmn.md',
'eu-central-1.aws.hmn.md',
'ap-southeast-1.aws.hmn.md',
'ap-southeast-2.aws.hmn.md',
) );
}
function get_proxy_ip_addresses() {
$hostnames = get_proxy_hostnames();
$cache_key = 'hm_proxy_ip_addresses_' . md5( serialize( $hostnames ) );
if ( function_exists( 'apc_fetch' ) ) {
$ip_addresses = apc_fetch( $cache_key );
if ( empty( $ip_addresses ) ) {
$ip_addresses = array_map( 'gethostbyname', $hostnames );
apc_store( $cache_key, $ip_addresses, 3600 );
}
} else {
$ip_addresses = wp_cache_get( $cache_key );
if ( empty( $ip_addresses ) ) {
$ip_addresses = array_map( 'gethostbyname', $hostnames );
wp_cache_set( $cache_key, $ip_addresses, '', DAY_IN_SECONDS );
}
}
$vpn_ip_addresses = array( '212.59.69.208', '131.226.44.47', '159.223.60.92', '108.61.251.94' );
$ip_addresses = array_merge( $ip_addresses, $vpn_ip_addresses );
return apply_filters( 'hm_proxy_ip_addresses', $ip_addresses );
}
/**
* Is the current request proxied?
*
* @return boolean
*/
function is_proxied() {
// Development should always count as proxied
if ( defined( 'HM_DEV' ) && HM_DEV && ! ( defined( 'HM_DEV_NOT_PROXIED' ) && HM_DEV_NOT_PROXIED ) ) {
return true;
}
// Is this proxied at all?
$ip = $_SERVER['REMOTE_ADDR'];
// There can be multiple IPs if there are multiple reverse proxies. E.g ELB -> Varnish -> The Server
$upstream_ips = array_map( 'trim', explode( ',', $ip ) );
return (bool) array_intersect( $upstream_ips, get_proxy_ip_addresses() );
}