woocommerce/includes/class-wc-geolocation.php

381 lines
12 KiB
PHP
Raw Normal View History

2014-12-23 18:49:37 +00:00
<?php
/**
2015-11-03 13:53:50 +00:00
* Geolocation class
2014-12-23 18:49:37 +00:00
*
* Handles geolocation and updating the geolocation database.
*
* This product includes GeoLite data created by MaxMind, available from http://www.maxmind.com.
2014-12-23 18:49:37 +00:00
*
2015-02-11 17:57:16 +00:00
* @author WooThemes
* @category Admin
* @package WooCommerce/Classes
* @version 2.4.0
2014-12-23 18:49:37 +00:00
*/
if ( ! defined( 'ABSPATH' ) ) {
exit;
}
/**
2015-11-03 13:31:20 +00:00
* WC_Geolocation Class.
2014-12-23 18:49:37 +00:00
*/
class WC_Geolocation {
/** URL to the geolocation database we're using */
const GEOLITE_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz';
const GEOLITE_IPV6_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoIPv6.dat.gz';
2014-12-23 18:49:37 +00:00
2014-12-30 11:11:17 +00:00
/** @var array API endpoints for looking up user IP address */
private static $ip_lookup_apis = array(
'icanhazip' => 'http://icanhazip.com',
2014-12-30 11:11:17 +00:00
'ipify' => 'http://api.ipify.org/',
'ipecho' => 'http://ipecho.net/plain',
'ident' => 'http://ident.me',
2014-12-30 11:11:17 +00:00
'whatismyipaddress' => 'http://bot.whatismyipaddress.com',
'ip.appspot' => 'http://ip.appspot.com',
2014-12-30 11:11:17 +00:00
);
/** @var array API endpoints for geolocating an IP address */
private static $geoip_apis = array(
2016-12-20 11:30:38 +00:00
'freegeoip' => 'https://freegeoip.net/json/%s',
'ipinfo.io' => 'https://ipinfo.io/%s/json',
'ip-api.com' => 'http://ip-api.com/json/%s',
2014-12-30 11:11:17 +00:00
);
2014-12-23 18:49:37 +00:00
/**
* Hook in tabs.
*/
public static function init() {
// Only download the database from MaxMind if the geolocation function is enabled, or a plugin specifically requests it
if ( 'geolocation' === get_option( 'woocommerce_default_customer_address' ) || apply_filters( 'woocommerce_geolocation_update_database_periodically', false ) ) {
add_action( 'woocommerce_geoip_updater', array( __CLASS__, 'update_database' ) );
}
add_filter( 'pre_update_option_woocommerce_default_customer_address', array( __CLASS__, 'maybe_update_database' ), 10, 2 );
}
/**
2015-11-03 13:31:20 +00:00
* Maybe trigger a DB update for the first time.
* @param string $new_value
* @param string $old_value
* @return string
*/
public static function maybe_update_database( $new_value, $old_value ) {
if ( $new_value !== $old_value && 'geolocation' === $new_value ) {
self::update_database();
}
return $new_value;
2014-12-23 18:49:37 +00:00
}
2017-05-05 19:58:08 +00:00
/**
* Check if is a valid IP address.
*
* @since 3.0.6
* @param string $ip_address IP address.
* @return string|bool The valid IP address, otherwise false.
*/
private static function is_ip_address( $ip_address ) {
2017-05-05 19:58:08 +00:00
// WP 4.7+ only.
if ( function_exists( 'rest_is_ip_address' ) ) {
return rest_is_ip_address( $ip_address );
}
// Support for WordPress 4.4 to 4.6.
if ( ! class_exists( 'Requests_IPv6', false ) ) {
include_once( dirname( __FILE__ ) . '/vendor/class-requests-ipv6.php' );
}
$ipv4_pattern = '/^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$/';
2017-05-23 06:20:30 +00:00
if ( ! preg_match( $ipv4_pattern, $ip_address ) && ! Requests_IPv6::check_ipv6( $ip_address ) ) {
2017-05-05 19:58:08 +00:00
return false;
}
2017-05-23 06:20:30 +00:00
return $ip_address;
2017-05-05 19:58:08 +00:00
}
2014-12-23 22:03:10 +00:00
/**
2015-11-03 13:31:20 +00:00
* Get current user IP Address.
2014-12-23 22:03:10 +00:00
* @return string
*/
public static function get_ip_address() {
2017-08-04 21:27:22 +00:00
if ( isset( $_SERVER['HTTP_X_REAL_IP'] ) ) {
return $_SERVER['HTTP_X_REAL_IP'];
} elseif ( isset( $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) {
// Proxy servers can send through this header like this: X-Forwarded-For: client1, proxy1, proxy2
// Make sure we always only send through the first IP in the list which should always be the client IP.
2017-05-05 19:58:08 +00:00
return (string) self::is_ip_address( trim( current( explode( ',', $_SERVER['HTTP_X_FORWARDED_FOR'] ) ) ) );
} elseif ( isset( $_SERVER['REMOTE_ADDR'] ) ) {
return $_SERVER['REMOTE_ADDR'];
}
return '';
2014-12-23 22:03:10 +00:00
}
/**
2016-02-26 13:34:51 +00:00
* Get user IP Address using an external service.
* This is used mainly as a fallback for users on localhost where
* get_ip_address() will be a local IP and non-geolocatable.
2014-12-23 22:03:10 +00:00
* @return string
*/
public static function get_external_ip_address() {
2017-05-05 19:58:08 +00:00
$external_ip_address = '0.0.0.0';
if ( '' !== self::get_ip_address() ) {
$transient_name = 'external_ip_address_' . self::get_ip_address();
$external_ip_address = get_transient( $transient_name );
}
2014-12-23 22:03:10 +00:00
if ( false === $external_ip_address ) {
2014-12-30 11:11:17 +00:00
$external_ip_address = '0.0.0.0';
$ip_lookup_services = apply_filters( 'woocommerce_geolocation_ip_lookup_apis', self::$ip_lookup_apis );
$ip_lookup_services_keys = array_keys( $ip_lookup_services );
shuffle( $ip_lookup_services_keys );
2014-12-23 22:03:10 +00:00
2014-12-30 11:11:17 +00:00
foreach ( $ip_lookup_services_keys as $service_name ) {
$service_endpoint = $ip_lookup_services[ $service_name ];
$response = wp_safe_remote_get( $service_endpoint, array( 'timeout' => 2 ) );
2014-12-23 22:03:10 +00:00
if ( ! is_wp_error( $response ) && $response['body'] ) {
$external_ip_address = apply_filters( 'woocommerce_geolocation_ip_lookup_api_response', wc_clean( $response['body'] ), $service_name );
2014-12-23 22:03:10 +00:00
break;
}
}
set_transient( $transient_name, $external_ip_address, WEEK_IN_SECONDS );
}
return $external_ip_address;
}
/**
2015-11-03 13:31:20 +00:00
* Geolocate an IP address.
2014-12-23 22:03:10 +00:00
* @param string $ip_address
* @param bool $fallback If true, fallbacks to alternative IP detection (can be slower).
* @param bool $api_fallback If true, uses geolocation APIs if the database file doesn't exist (can be slower).
2014-12-23 22:03:10 +00:00
* @return array
*/
public static function geolocate_ip( $ip_address = '', $fallback = true, $api_fallback = true ) {
// Filter to allow custom geolocation of the IP address.
$country_code = apply_filters( 'woocommerce_geolocate_ip', false, $ip_address, $fallback, $api_fallback );
if ( false === $country_code ) {
// If GEOIP is enabled in CloudFlare, we can use that (Settings -> CloudFlare Settings -> Settings Overview)
if ( ! empty( $_SERVER['HTTP_CF_IPCOUNTRY'] ) ) {
$country_code = sanitize_text_field( strtoupper( $_SERVER['HTTP_CF_IPCOUNTRY'] ) );
2016-12-20 15:24:30 +00:00
// WP.com VIP has a variable available.
2016-12-20 11:35:28 +00:00
} elseif ( ! empty( $_SERVER['GEOIP_COUNTRY_CODE'] ) ) {
$country_code = sanitize_text_field( strtoupper( $_SERVER['GEOIP_COUNTRY_CODE'] ) );
2016-12-20 15:24:30 +00:00
// VIP Go has a variable available also.
} elseif ( ! empty( $_SERVER['HTTP_X_COUNTRY_CODE'] ) ) {
$country_code = sanitize_text_field( strtoupper( $_SERVER['HTTP_X_COUNTRY_CODE'] ) );
} else {
$ip_address = $ip_address ? $ip_address : self::get_ip_address();
if ( self::is_IPv6( $ip_address ) ) {
$database = self::get_local_database_path( 'v6' );
} else {
$database = self::get_local_database_path();
}
if ( file_exists( $database ) ) {
$country_code = self::geolocate_via_db( $ip_address );
} elseif ( $api_fallback ) {
$country_code = self::geolocate_via_api( $ip_address );
} else {
$country_code = '';
}
2015-01-01 12:43:49 +00:00
if ( ! $country_code && $fallback ) {
// May be a local environment - find external IP
return self::geolocate_ip( self::get_external_ip_address(), false, $api_fallback );
}
2015-01-01 12:43:49 +00:00
}
2014-12-23 22:03:10 +00:00
}
return array(
'country' => $country_code,
'state' => '',
2014-12-23 22:03:10 +00:00
);
}
/**
2015-11-03 13:31:20 +00:00
* Path to our local db.
* @param string $version
2014-12-23 22:03:10 +00:00
* @return string
*/
2016-03-30 12:11:26 +00:00
public static function get_local_database_path( $version = 'v4' ) {
$version = ( 'v4' == $version ) ? '' : 'v6';
2014-12-23 22:03:10 +00:00
$upload_dir = wp_upload_dir();
2016-03-30 12:11:26 +00:00
return apply_filters( 'woocommerce_geolocation_local_database_path', $upload_dir['basedir'] . '/GeoIP' . $version . '.dat', $version );
2014-12-23 22:03:10 +00:00
}
2014-12-23 18:49:37 +00:00
/**
* Update geoip database. Adapted from https://wordpress.org/plugins/geoip-detect/.
*/
public static function update_database() {
$logger = wc_get_logger();
2015-02-17 16:20:26 +00:00
2015-02-17 16:19:33 +00:00
if ( ! is_callable( 'gzopen' ) ) {
2016-12-21 19:15:19 +00:00
$logger->notice( 'Server does not support gzopen', array( 'source' => 'geolocation' ) );
2015-02-17 16:19:33 +00:00
return;
}
2014-12-23 18:49:37 +00:00
require_once( ABSPATH . 'wp-admin/includes/file.php' );
$tmp_databases = array(
'v4' => download_url( self::GEOLITE_DB ),
'v6' => download_url( self::GEOLITE_IPV6_DB ),
);
2014-12-23 18:49:37 +00:00
foreach ( $tmp_databases as $tmp_database_version => $tmp_database_path ) {
if ( ! is_wp_error( $tmp_database_path ) ) {
$gzhandle = @gzopen( $tmp_database_path, 'r' );
$handle = @fopen( self::get_local_database_path( $tmp_database_version ), 'w' );
2014-12-23 18:49:37 +00:00
if ( $gzhandle && $handle ) {
2015-07-15 15:34:13 +00:00
while ( $string = gzread( $gzhandle, 4096 ) ) {
fwrite( $handle, $string, strlen( $string ) );
}
gzclose( $gzhandle );
$s_array = fstat( $handle );
fclose( $handle );
if ( ! isset( $s_array['size'] ) || 0 === $s_array['size'] ) {
$logger->notice( 'Empty database file, deleting local copy.', array( 'source' => 'geolocation' ) );
// Delete empty DB, we do not want to keep empty files around.
@unlink( self::get_local_database_path( $tmp_database_version ) );
// Reschedule download of DB.
wp_clear_scheduled_hook( 'woocommerce_geoip_updater' );
wp_schedule_event( strtotime( 'first tuesday of next month' ), 'monthly', 'woocommerce_geoip_updater' );
}
} else {
2016-12-21 19:15:19 +00:00
$logger->notice( 'Unable to open database file', array( 'source' => 'geolocation' ) );
2014-12-23 18:49:37 +00:00
}
@unlink( $tmp_database_path );
2014-12-23 18:49:37 +00:00
} else {
2016-11-22 18:52:16 +00:00
$logger->notice(
'Unable to download GeoIP Database: ' . $tmp_database_path->get_error_message(),
2016-12-21 19:15:19 +00:00
array( 'source' => 'geolocation' )
2016-11-22 18:52:16 +00:00
);
2014-12-23 18:49:37 +00:00
}
}
}
/**
* Use MAXMIND GeoLite database to geolocation the user.
* @param string $ip_address
* @return string
*/
2014-12-30 11:11:17 +00:00
private static function geolocate_via_db( $ip_address ) {
2017-02-16 11:46:01 +00:00
if ( ! class_exists( 'WC_Geo_IP', false ) ) {
2017-02-17 18:10:15 +00:00
include_once( WC_ABSPATH . 'includes/class-wc-geo-ip.php' );
2014-12-23 18:49:37 +00:00
}
2015-02-11 17:51:50 +00:00
$gi = new WC_Geo_IP();
if ( self::is_IPv6( $ip_address ) ) {
$database = self::get_local_database_path( 'v6' );
if ( ! self::get_file_size( $database ) ) {
return false;
}
$gi->geoip_open( $database, 0 );
$country_code = $gi->geoip_country_code_by_addr_v6( $ip_address );
} else {
$database = self::get_local_database_path();
if ( ! self::get_file_size( $database ) ) {
return false;
}
$gi->geoip_open( $database, 0 );
$country_code = $gi->geoip_country_code_by_addr( $ip_address );
}
2015-02-11 17:51:50 +00:00
$gi->geoip_close();
2014-12-23 18:49:37 +00:00
2014-12-30 11:11:17 +00:00
return sanitize_text_field( strtoupper( $country_code ) );
2014-12-23 18:49:37 +00:00
}
/**
* Check file size
* Check the file size, if empty file also delete it.
*
* @param string $filename Name of the file to check.
* @return bool|int
*/
private static function get_file_size( $filename ) {
$handle = @fopen( $filename, 'r' );
$s_array = fstat( $handle );
@fclose( $handle );
if ( ! isset( $s_array['size'] ) || 0 === $s_array['size'] ) {
$logger = wc_get_logger();
$logger->notice( 'Empty database file, deleting local copy.', array( 'source' => 'geolocation' ) );
// Delete the file as we do not want to keep empty files around.
@unlink( $filename );
return false;
}
return $s_array['size'];
}
2014-12-23 18:49:37 +00:00
/**
2014-12-30 11:11:17 +00:00
* Use APIs to Geolocate the user.
2014-12-23 18:49:37 +00:00
* @param string $ip_address
2014-12-30 11:11:17 +00:00
* @return string|bool
2014-12-23 18:49:37 +00:00
*/
2014-12-30 11:11:17 +00:00
private static function geolocate_via_api( $ip_address ) {
2014-12-23 18:49:37 +00:00
$country_code = get_transient( 'geoip_' . $ip_address );
if ( false === $country_code ) {
2014-12-30 11:11:17 +00:00
$geoip_services = apply_filters( 'woocommerce_geolocation_geoip_apis', self::$geoip_apis );
$geoip_services_keys = array_keys( $geoip_services );
shuffle( $geoip_services_keys );
2014-12-23 18:49:37 +00:00
2014-12-30 11:11:17 +00:00
foreach ( $geoip_services_keys as $service_name ) {
$service_endpoint = $geoip_services[ $service_name ];
$response = wp_safe_remote_get( sprintf( $service_endpoint, $ip_address ), array( 'timeout' => 2 ) );
2014-12-30 11:11:17 +00:00
if ( ! is_wp_error( $response ) && $response['body'] ) {
switch ( $service_name ) {
2016-12-20 11:30:38 +00:00
case 'ipinfo.io' :
2014-12-30 11:11:17 +00:00
$data = json_decode( $response['body'] );
$country_code = isset( $data->country ) ? $data->country : '';
break;
2016-12-20 11:30:38 +00:00
case 'ip-api.com' :
$data = json_decode( $response['body'] );
$country_code = isset( $data->countryCode ) ? $data->countryCode : '';
break;
2014-12-30 11:11:17 +00:00
case 'freegeoip' :
$data = json_decode( $response['body'] );
$country_code = isset( $data->country_code ) ? $data->country_code : '';
break;
default :
$country_code = apply_filters( 'woocommerce_geolocation_geoip_response_' . $service_name, '', $response['body'] );
break;
}
$country_code = sanitize_text_field( strtoupper( $country_code ) );
if ( $country_code ) {
break;
}
}
2014-12-23 18:49:37 +00:00
}
2014-12-30 11:11:17 +00:00
set_transient( 'geoip_' . $ip_address, $country_code, WEEK_IN_SECONDS );
2014-12-23 18:49:37 +00:00
}
return $country_code;
}
/**
2015-11-03 13:31:20 +00:00
* Test if is IPv6.
*
* @since 2.4.0
*
* @param string $ip_address
* @return bool
*/
private static function is_IPv6( $ip_address ) {
return false !== filter_var( $ip_address, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6 );
}
2014-12-23 18:49:37 +00:00
}
WC_Geolocation::init();