2014-12-23 18:49:37 +00:00
< ? php
/**
2015-11-03 13:53:50 +00:00
* Geolocation class
2014-12-23 18:49:37 +00:00
*
* Handles geolocation and updating the geolocation database .
*
2015-02-18 12:53:24 +00:00
* This product includes GeoLite data created by MaxMind , available from http :// www . maxmind . com .
2014-12-23 18:49:37 +00:00
*
2015-02-11 17:57:16 +00:00
* @ author WooThemes
* @ category Admin
* @ package WooCommerce / Classes
2015-05-26 17:41:13 +00:00
* @ version 2.4 . 0
2014-12-23 18:49:37 +00:00
*/
if ( ! defined ( 'ABSPATH' ) ) {
exit ;
}
/**
2015-11-03 13:31:20 +00:00
* WC_Geolocation Class .
2014-12-23 18:49:37 +00:00
*/
class WC_Geolocation {
2017-11-22 16:13:59 +00:00
/**
* GeoLite IPv4 DB .
*/
const GEOLITE_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoLiteCountry/GeoIP.dat.gz' ;
/**
* GeoLite IPv6 DB .
*/
2015-05-26 17:41:13 +00:00
const GEOLITE_IPV6_DB = 'http://geolite.maxmind.com/download/geoip/database/GeoIPv6.dat.gz' ;
2014-12-23 18:49:37 +00:00
2017-11-22 16:13:59 +00:00
/**
* API endpoints for looking up user IP address .
*
* @ var array
*/
2014-12-30 11:11:17 +00:00
private static $ip_lookup_apis = array (
2015-05-26 20:32:47 +00:00
'icanhazip' => 'http://icanhazip.com' ,
2014-12-30 11:11:17 +00:00
'ipify' => 'http://api.ipify.org/' ,
'ipecho' => 'http://ipecho.net/plain' ,
2015-05-26 20:32:47 +00:00
'ident' => 'http://ident.me' ,
2014-12-30 11:11:17 +00:00
'whatismyipaddress' => 'http://bot.whatismyipaddress.com' ,
2016-08-27 01:46:45 +00:00
'ip.appspot' => 'http://ip.appspot.com' ,
2014-12-30 11:11:17 +00:00
);
2017-11-22 16:13:59 +00:00
/**
* API endpoints for geolocating an IP address
*
* @ var array
*/
2014-12-30 11:11:17 +00:00
private static $geoip_apis = array (
2016-12-20 11:30:38 +00:00
'freegeoip' => 'https://freegeoip.net/json/%s' ,
'ipinfo.io' => 'https://ipinfo.io/%s/json' ,
'ip-api.com' => 'http://ip-api.com/json/%s' ,
2014-12-30 11:11:17 +00:00
);
2014-12-23 18:49:37 +00:00
/**
* Hook in tabs .
*/
public static function init () {
2017-11-22 16:13:59 +00:00
// Only download the database from MaxMind if the geolocation function is enabled, or a plugin specifically requests it.
2015-02-18 12:53:24 +00:00
if ( 'geolocation' === get_option ( 'woocommerce_default_customer_address' ) || apply_filters ( 'woocommerce_geolocation_update_database_periodically' , false ) ) {
add_action ( 'woocommerce_geoip_updater' , array ( __CLASS__ , 'update_database' ) );
}
add_filter ( 'pre_update_option_woocommerce_default_customer_address' , array ( __CLASS__ , 'maybe_update_database' ), 10 , 2 );
}
/**
2015-11-03 13:31:20 +00:00
* Maybe trigger a DB update for the first time .
2017-11-22 16:13:59 +00:00
*
* @ param string $new_value New value .
* @ param string $old_value Old value .
2015-02-18 12:53:24 +00:00
* @ return string
*/
public static function maybe_update_database ( $new_value , $old_value ) {
if ( $new_value !== $old_value && 'geolocation' === $new_value ) {
self :: update_database ();
}
return $new_value ;
2014-12-23 18:49:37 +00:00
}
2014-12-23 22:03:10 +00:00
/**
2015-11-03 13:31:20 +00:00
* Get current user IP Address .
2017-11-22 16:13:59 +00:00
*
2014-12-23 22:03:10 +00:00
* @ return string
*/
public static function get_ip_address () {
2017-11-22 16:13:59 +00:00
if ( isset ( $_SERVER [ 'HTTP_X_REAL_IP' ] ) ) { // WPCS: input var ok, CSRF ok.
return sanitize_text_field ( wp_unslash ( $_SERVER [ 'HTTP_X_REAL_IP' ] ) ); // WPCS: input var ok, CSRF ok.
} elseif ( isset ( $_SERVER [ 'HTTP_X_FORWARDED_FOR' ] ) ) { // WPCS: input var ok, CSRF ok.
2015-02-11 10:07:12 +00:00
// Proxy servers can send through this header like this: X-Forwarded-For: client1, proxy1, proxy2
// Make sure we always only send through the first IP in the list which should always be the client IP.
2018-01-02 00:54:26 +00:00
return ( string ) rest_is_ip_address ( trim ( current ( preg_split ( '/[,:]/' , sanitize_text_field ( wp_unslash ( $_SERVER [ 'HTTP_X_FORWARDED_FOR' ] ) ) ) ) ) ); // WPCS: input var ok, CSRF ok.
2017-11-22 16:13:59 +00:00
} elseif ( isset ( $_SERVER [ 'REMOTE_ADDR' ] ) ) { // @codingStandardsIgnoreLine
return sanitize_text_field ( wp_unslash ( $_SERVER [ 'REMOTE_ADDR' ] ) ); // @codingStandardsIgnoreLine
2015-02-11 10:07:12 +00:00
}
return '' ;
2014-12-23 22:03:10 +00:00
}
/**
2016-02-26 13:34:51 +00:00
* Get user IP Address using an external service .
* This is used mainly as a fallback for users on localhost where
* get_ip_address () will be a local IP and non - geolocatable .
2017-11-22 16:13:59 +00:00
*
2014-12-23 22:03:10 +00:00
* @ return string
*/
public static function get_external_ip_address () {
2017-05-05 19:58:08 +00:00
$external_ip_address = '0.0.0.0' ;
if ( '' !== self :: get_ip_address () ) {
$transient_name = 'external_ip_address_' . self :: get_ip_address ();
$external_ip_address = get_transient ( $transient_name );
}
2014-12-23 22:03:10 +00:00
if ( false === $external_ip_address ) {
2014-12-30 11:11:17 +00:00
$external_ip_address = '0.0.0.0' ;
$ip_lookup_services = apply_filters ( 'woocommerce_geolocation_ip_lookup_apis' , self :: $ip_lookup_apis );
$ip_lookup_services_keys = array_keys ( $ip_lookup_services );
shuffle ( $ip_lookup_services_keys );
2014-12-23 22:03:10 +00:00
2014-12-30 11:11:17 +00:00
foreach ( $ip_lookup_services_keys as $service_name ) {
$service_endpoint = $ip_lookup_services [ $service_name ];
2015-05-21 13:45:28 +00:00
$response = wp_safe_remote_get ( $service_endpoint , array ( 'timeout' => 2 ) );
2014-12-23 22:03:10 +00:00
if ( ! is_wp_error ( $response ) && $response [ 'body' ] ) {
2015-02-09 23:54:26 +00:00
$external_ip_address = apply_filters ( 'woocommerce_geolocation_ip_lookup_api_response' , wc_clean ( $response [ 'body' ] ), $service_name );
2014-12-23 22:03:10 +00:00
break ;
}
}
set_transient ( $transient_name , $external_ip_address , WEEK_IN_SECONDS );
}
return $external_ip_address ;
}
/**
2015-11-03 13:31:20 +00:00
* Geolocate an IP address .
2017-11-22 16:13:59 +00:00
*
* @ param string $ip_address IP Address .
* @ param bool $fallback If true , fallbacks to alternative IP detection ( can be slower ) .
2016-03-30 12:02:21 +00:00
* @ param bool $api_fallback If true , uses geolocation APIs if the database file doesn ' t exist ( can be slower ) .
2014-12-23 22:03:10 +00:00
* @ return array
*/
2016-03-30 12:02:21 +00:00
public static function geolocate_ip ( $ip_address = '' , $fallback = true , $api_fallback = true ) {
2016-06-08 11:18:09 +00:00
// Filter to allow custom geolocation of the IP address.
$country_code = apply_filters ( 'woocommerce_geolocate_ip' , false , $ip_address , $fallback , $api_fallback );
2015-05-26 17:41:13 +00:00
2016-06-08 11:18:09 +00:00
if ( false === $country_code ) {
2017-11-22 16:13:59 +00:00
// If GEOIP is enabled in CloudFlare, we can use that (Settings -> CloudFlare Settings -> Settings Overview).
if ( ! empty ( $_SERVER [ 'HTTP_CF_IPCOUNTRY' ] ) ) { // WPCS: input var ok, CSRF ok.
$country_code = strtoupper ( sanitize_text_field ( wp_unslash ( $_SERVER [ 'HTTP_CF_IPCOUNTRY' ] ) ) ); // WPCS: input var ok, CSRF ok.
} elseif ( ! empty ( $_SERVER [ 'GEOIP_COUNTRY_CODE' ] ) ) { // WPCS: input var ok, CSRF ok.
// WP.com VIP has a variable available.
$country_code = strtoupper ( sanitize_text_field ( wp_unslash ( $_SERVER [ 'GEOIP_COUNTRY_CODE' ] ) ) ); // WPCS: input var ok, CSRF ok.
} elseif ( ! empty ( $_SERVER [ 'HTTP_X_COUNTRY_CODE' ] ) ) { // WPCS: input var ok, CSRF ok.
// VIP Go has a variable available also.
$country_code = strtoupper ( sanitize_text_field ( wp_unslash ( $_SERVER [ 'HTTP_X_COUNTRY_CODE' ] ) ) ); // WPCS: input var ok, CSRF ok.
2016-03-30 12:02:21 +00:00
} else {
2016-06-08 11:18:09 +00:00
$ip_address = $ip_address ? $ip_address : self :: get_ip_address ();
2017-11-22 16:13:59 +00:00
if ( self :: is_ipv6 ( $ip_address ) ) {
2016-06-08 11:18:09 +00:00
$database = self :: get_local_database_path ( 'v6' );
} else {
$database = self :: get_local_database_path ();
}
if ( file_exists ( $database ) ) {
$country_code = self :: geolocate_via_db ( $ip_address );
} elseif ( $api_fallback ) {
$country_code = self :: geolocate_via_api ( $ip_address );
} else {
$country_code = '' ;
}
2015-01-01 12:43:49 +00:00
2016-06-08 11:18:09 +00:00
if ( ! $country_code && $fallback ) {
2017-11-22 16:13:59 +00:00
// May be a local environment - find external IP.
2016-06-08 11:18:09 +00:00
return self :: geolocate_ip ( self :: get_external_ip_address (), false , $api_fallback );
}
2015-01-01 12:43:49 +00:00
}
2014-12-23 22:03:10 +00:00
}
return array (
'country' => $country_code ,
2016-08-27 01:46:45 +00:00
'state' => '' ,
2014-12-23 22:03:10 +00:00
);
}
/**
2015-11-03 13:31:20 +00:00
* Path to our local db .
2017-11-22 16:13:59 +00:00
*
* @ param string $version Version .
2014-12-23 22:03:10 +00:00
* @ return string
*/
2016-03-30 12:11:26 +00:00
public static function get_local_database_path ( $version = 'v4' ) {
2017-11-22 16:13:59 +00:00
$version = 'v4' === $version ? '' : 'v6' ;
2014-12-23 22:03:10 +00:00
$upload_dir = wp_upload_dir ();
2015-05-26 17:41:13 +00:00
2016-03-30 12:11:26 +00:00
return apply_filters ( 'woocommerce_geolocation_local_database_path' , $upload_dir [ 'basedir' ] . '/GeoIP' . $version . '.dat' , $version );
2014-12-23 22:03:10 +00:00
}
2014-12-23 18:49:37 +00:00
/**
* Update geoip database . Adapted from https :// wordpress . org / plugins / geoip - detect /.
*/
public static function update_database () {
2016-08-08 12:59:23 +00:00
$logger = wc_get_logger ();
2015-02-17 16:20:26 +00:00
2015-02-17 16:19:33 +00:00
if ( ! is_callable ( 'gzopen' ) ) {
2016-12-21 19:15:19 +00:00
$logger -> notice ( 'Server does not support gzopen' , array ( 'source' => 'geolocation' ) );
2015-02-17 16:19:33 +00:00
return ;
}
2017-11-22 16:13:59 +00:00
require_once ABSPATH . 'wp-admin/includes/file.php' ;
2014-12-23 18:49:37 +00:00
2015-05-26 17:41:13 +00:00
$tmp_databases = array (
'v4' => download_url ( self :: GEOLITE_DB ),
2016-08-27 01:46:45 +00:00
'v6' => download_url ( self :: GEOLITE_IPV6_DB ),
2015-05-26 17:41:13 +00:00
);
2014-12-23 18:49:37 +00:00
2015-05-26 17:41:13 +00:00
foreach ( $tmp_databases as $tmp_database_version => $tmp_database_path ) {
if ( ! is_wp_error ( $tmp_database_path ) ) {
2017-11-22 16:13:59 +00:00
$gzhandle = @ gzopen ( $tmp_database_path , 'r' ); // @codingStandardsIgnoreLine
$handle = @ fopen ( self :: get_local_database_path ( $tmp_database_version ), 'w' ); // @codingStandardsIgnoreLine
2014-12-23 18:49:37 +00:00
2015-05-26 17:41:13 +00:00
if ( $gzhandle && $handle ) {
2017-11-22 16:13:59 +00:00
while ( $string = gzread ( $gzhandle , 4096 ) ) { // @codingStandardsIgnoreLine
fwrite ( $handle , $string , strlen ( $string ) ); // @codingStandardsIgnoreLine
2015-05-26 17:41:13 +00:00
}
gzclose ( $gzhandle );
2017-11-08 14:28:03 +00:00
$s_array = fstat ( $handle );
2017-11-22 16:13:59 +00:00
fclose ( $handle ); // @codingStandardsIgnoreLine
2017-11-08 14:28:03 +00:00
if ( ! isset ( $s_array [ 'size' ] ) || 0 === $s_array [ 'size' ] ) {
$logger -> notice ( 'Empty database file, deleting local copy.' , array ( 'source' => 'geolocation' ) );
// Delete empty DB, we do not want to keep empty files around.
2017-11-22 16:13:59 +00:00
@ unlink ( self :: get_local_database_path ( $tmp_database_version ) ); // @codingStandardsIgnoreLine
2017-11-08 14:28:03 +00:00
// Reschedule download of DB.
wp_clear_scheduled_hook ( 'woocommerce_geoip_updater' );
wp_schedule_event ( strtotime ( 'first tuesday of next month' ), 'monthly' , 'woocommerce_geoip_updater' );
}
2015-05-26 17:41:13 +00:00
} else {
2016-12-21 19:15:19 +00:00
$logger -> notice ( 'Unable to open database file' , array ( 'source' => 'geolocation' ) );
2014-12-23 18:49:37 +00:00
}
2017-11-22 16:13:59 +00:00
@ unlink ( $tmp_database_path ); // @codingStandardsIgnoreLine
2014-12-23 18:49:37 +00:00
} else {
2016-11-22 18:52:16 +00:00
$logger -> notice (
'Unable to download GeoIP Database: ' . $tmp_database_path -> get_error_message (),
2016-12-21 19:15:19 +00:00
array ( 'source' => 'geolocation' )
2016-11-22 18:52:16 +00:00
);
2014-12-23 18:49:37 +00:00
}
}
}
/**
* Use MAXMIND GeoLite database to geolocation the user .
2017-11-22 16:13:59 +00:00
*
* @ param string $ip_address IP address .
2014-12-23 18:49:37 +00:00
* @ return string
*/
2014-12-30 11:11:17 +00:00
private static function geolocate_via_db ( $ip_address ) {
2017-02-16 11:46:01 +00:00
if ( ! class_exists ( 'WC_Geo_IP' , false ) ) {
2017-11-22 16:13:59 +00:00
include_once WC_ABSPATH . 'includes/class-wc-geo-ip.php' ;
2014-12-23 18:49:37 +00:00
}
2015-02-11 17:51:50 +00:00
2015-05-26 17:41:13 +00:00
$gi = new WC_Geo_IP ();
2017-11-22 16:13:59 +00:00
if ( self :: is_ipv6 ( $ip_address ) ) {
2015-05-26 17:41:13 +00:00
$database = self :: get_local_database_path ( 'v6' );
2017-11-08 14:28:03 +00:00
if ( ! self :: get_file_size ( $database ) ) {
return false ;
}
2015-05-26 17:41:13 +00:00
$gi -> geoip_open ( $database , 0 );
$country_code = $gi -> geoip_country_code_by_addr_v6 ( $ip_address );
} else {
$database = self :: get_local_database_path ();
2017-11-08 14:28:03 +00:00
if ( ! self :: get_file_size ( $database ) ) {
return false ;
}
2015-05-26 17:41:13 +00:00
$gi -> geoip_open ( $database , 0 );
$country_code = $gi -> geoip_country_code_by_addr ( $ip_address );
}
2015-02-11 17:51:50 +00:00
$gi -> geoip_close ();
2014-12-23 18:49:37 +00:00
2014-12-30 11:11:17 +00:00
return sanitize_text_field ( strtoupper ( $country_code ) );
2014-12-23 18:49:37 +00:00
}
2017-11-08 14:28:03 +00:00
/**
* Check file size
* Check the file size , if empty file also delete it .
*
* @ param string $filename Name of the file to check .
* @ return bool | int
*/
private static function get_file_size ( $filename ) {
2017-11-22 16:13:59 +00:00
$handle = @ fopen ( $filename , 'r' ); // @codingStandardsIgnoreLine
$s_array = fstat ( $handle ); // @codingStandardsIgnoreLine
@ fclose ( $handle ); // @codingStandardsIgnoreLine
2017-11-08 14:28:03 +00:00
if ( ! isset ( $s_array [ 'size' ] ) || 0 === $s_array [ 'size' ] ) {
$logger = wc_get_logger ();
$logger -> notice ( 'Empty database file, deleting local copy.' , array ( 'source' => 'geolocation' ) );
// Delete the file as we do not want to keep empty files around.
2017-11-22 16:13:59 +00:00
@ unlink ( $filename ); // @codingStandardsIgnoreLine
2017-11-08 14:28:03 +00:00
return false ;
}
return $s_array [ 'size' ];
}
2014-12-23 18:49:37 +00:00
/**
2014-12-30 11:11:17 +00:00
* Use APIs to Geolocate the user .
2017-11-22 16:13:59 +00:00
*
* @ param string $ip_address IP address .
2014-12-30 11:11:17 +00:00
* @ return string | bool
2014-12-23 18:49:37 +00:00
*/
2014-12-30 11:11:17 +00:00
private static function geolocate_via_api ( $ip_address ) {
2014-12-23 18:49:37 +00:00
$country_code = get_transient ( 'geoip_' . $ip_address );
if ( false === $country_code ) {
2014-12-30 11:11:17 +00:00
$geoip_services = apply_filters ( 'woocommerce_geolocation_geoip_apis' , self :: $geoip_apis );
$geoip_services_keys = array_keys ( $geoip_services );
shuffle ( $geoip_services_keys );
2014-12-23 18:49:37 +00:00
2014-12-30 11:11:17 +00:00
foreach ( $geoip_services_keys as $service_name ) {
$service_endpoint = $geoip_services [ $service_name ];
2015-05-21 13:45:28 +00:00
$response = wp_safe_remote_get ( sprintf ( $service_endpoint , $ip_address ), array ( 'timeout' => 2 ) );
2014-12-30 11:11:17 +00:00
if ( ! is_wp_error ( $response ) && $response [ 'body' ] ) {
switch ( $service_name ) {
2017-11-22 16:13:59 +00:00
case 'ipinfo.io' :
2014-12-30 11:11:17 +00:00
$data = json_decode ( $response [ 'body' ] );
$country_code = isset ( $data -> country ) ? $data -> country : '' ;
2017-11-22 16:13:59 +00:00
break ;
case 'ip-api.com' :
2016-12-20 11:30:38 +00:00
$data = json_decode ( $response [ 'body' ] );
2017-11-22 16:13:59 +00:00
$country_code = isset ( $data -> countryCode ) ? $data -> countryCode : '' ; // @codingStandardsIgnoreLine
break ;
case 'freegeoip' :
2014-12-30 11:11:17 +00:00
$data = json_decode ( $response [ 'body' ] );
$country_code = isset ( $data -> country_code ) ? $data -> country_code : '' ;
2017-11-22 16:13:59 +00:00
break ;
default :
2014-12-30 11:11:17 +00:00
$country_code = apply_filters ( 'woocommerce_geolocation_geoip_response_' . $service_name , '' , $response [ 'body' ] );
2017-11-22 16:13:59 +00:00
break ;
2014-12-30 11:11:17 +00:00
}
$country_code = sanitize_text_field ( strtoupper ( $country_code ) );
if ( $country_code ) {
break ;
}
}
2014-12-23 18:49:37 +00:00
}
2014-12-30 11:11:17 +00:00
set_transient ( 'geoip_' . $ip_address , $country_code , WEEK_IN_SECONDS );
2014-12-23 18:49:37 +00:00
}
return $country_code ;
}
2015-05-26 17:41:13 +00:00
/**
2015-11-03 13:31:20 +00:00
* Test if is IPv6 .
2015-05-26 17:41:13 +00:00
*
* @ since 2.4 . 0
*
2017-11-22 16:13:59 +00:00
* @ param string $ip_address IP Address .
2015-05-26 17:41:13 +00:00
* @ return bool
*/
2017-11-22 16:13:59 +00:00
private static function is_ipv6 ( $ip_address ) {
2015-05-26 20:32:47 +00:00
return false !== filter_var ( $ip_address , FILTER_VALIDATE_IP , FILTER_FLAG_IPV6 );
2015-05-26 17:41:13 +00:00
}
2014-12-23 18:49:37 +00:00
}
WC_Geolocation :: init ();