j*jsۤj\> Accept-Encoding,User-Agent4RSb/6D KEY: https://avaliareassessoria.com.br/Ven-SS/root/proc/self/cwd/opt/imunify360/venv/lib/python3.11/site-packages/defence360agent/wordpress/__pycache__/incident_sender.cpython-311.pyc HTTP/1.1 200 OK Date: Sat, 12 Sep 2026 04:56:19 GMT Server: Apache Last-Modified: Tue, 01 Sep 2026 01:29:56 GMT Accept-Ranges: bytes Content-Length: 14925 Vary: Accept-Encoding,User-Agent Connection: close Content-Type: text/plain *jY*dZddlZddlZddlZddlZddlmZddlmZddlm Z ddl m Z ddl m Z mZddlmZdd lmZdd lmZdd lmZmZejeZGd d ZdS)z3Send WordPress incidents to the correlation server.N)datetime)partial) monotonic)MappingProxyType)AnyMapping)SensorWordpressIncidentList) MessageSink) delivery_ack)get_unsent_wordpress_incidents#settle_wordpress_incidents_reportedc XeZdZdZdZdZddZdedeee ffdZ d ede efd Z d e dzdefd Zd e dzd e edefdZeifd e de edeeeffdZdedeeefddfdZdeddfdZdedeeefddfdZddZdeefdZdS)IncidentSenderai Send WordPress incidents to the correlation server. WordPress incidents are already in the Incident table (visible to UI). This class sends them to correlation via Reportable messages, which are handled by the SendToServer/SendToServerNATS/SendToServerFGW plugins. Those plugins queue a message rather than deliver it, and a send round can lose its batch or be force-cancelled mid-publish while the agent shuts down. Each incident therefore keeps a count of the occurrences the transport has not acknowledged, and every collection cycle sends whatever is still outstanding. ii,returnNci|_dSN) _inflightselfs `/opt/imunify360/venv/versions/imunify-core-8.12.1-2/defence360agent/wordpress/incident_sender.py__init__zIncidentSender.__init__/s BDincidentctd||dpi}t|dpd}t |}|r't j|dnd}id|d|d|d d |d pd d |d d |dd|dd|dpdd|dpdd|dpdd|dpdd|dpdd|dpdd|dr|ddkndd|d pdd!|d"pdd#|||d$pd|d%pd|d&pd|d'pd|d(S))aJ Prepare an incident for sending to the correlation server. WordPress incidents use extra_info JSON field to store plugin-specific data. Args: incident: WordpressIncident dictionary (with extra_info populated) Returns: Dictionary formatted for correlation server z&Preparing incident for correlation: %s extra_info timestamprz%Y-%m-%ddt plugin_idpluginruleunknownnamemessage descriptionseverity attackers_ipabuserdomainretriesunsent_retriesuri request_uri user_agenthttp_user_agent http_methodrequest_methoduser_logged_intrueN file_path site_pathuserusernametagtargetslugversionmode)r:r;r<r=details) loggerinfogetfloatintr fromtimestampstrftime _build_tags)rrextratimestamp_valuerrs r!_prepare_incident_for_correlationz0IncidentSender._prepare_incident_for_correlation3s  z1IncidentSender.send_incidents..s7     2 28 < <   rcfg|].}|d|dpdf/S)idr+r,)rA)r`rs rraz1IncidentSender.send_incidents..sK   d##X\\2B%C%C%HqI   rci|] \}}||| Srr_)r` incident_id occurrencess r z1IncidentSender.send_incidents..s20 [#.  /..r) r?rVlendebugr@iterr batched _send_batch itertoolsislice)rrQr[correlation_batchpendingbatchs` rrZzIncidentSender.send_incidentssi < NNH I I I1 y>>Q   LL9 : : :1 8#i..       %      )      189JKK  E""4=4DU55          $%%%rroreportedcKtdt|tdtj|dt |}t jtjt| |gd  }||d<| || | |d{Vtd t||dS#t$r6}||td |d}~wwxYw) zSend a batch of incidents to correlation server. Uses SensorIncidentList Reportable message which is sent to correlation via the SendToServer/SendToServerNATS/SendToServerFGW plugins. z3Sending batch of %d incidents to correlation serverzCorrelation batch json: %s)indentT) sort_keys message_idNzCQueued %d wordpress incident(s) for correlation server (message %s)z"Failed to queue incident batch: %s)r?r@rhjsondumpsr hashlibsha1sorteditemsencode hexdigest_watchprocess_message Exception_unwatcherror)rrQrorrr$rwes rrlzIncidentSender._send_batchs  A ! " "     ( J( 3 3 3   ..?@@ \ J(())+<=   fhh   )++  !+  J))) &&w// / / / / / / / KK %&&          MM* % % % LL4     s2AD88 E81E33E8rwc|sdSt|}|t|jzf|j|<tj|t|j||dSr) dictr ACK_TIMEOUTrr registrywatchr _on_delivered)rrwrrs rrzIncidentSender._watchsv  F>>  KK$* *& z" ##  D& H = =     rcz|j|dtj|dSr)rpopr runwatch)rrws rrzIncidentSender._unwatchs7 :t,,,%%j11111rc|j|dt|}td|dS)Nz.s2   ) MQ3 rz]No delivery confirmation for %d wordpress incident(s) (message %s) in %ds, sending them againN) rrr}rr rrr?rVrhr)rexpiredrwrrrrs @rrWzIncidentSender._expire_inflightskk    -1^-A-A-C-C    "  J.,,Z88KHa  ! ) )* 5 5 5 NN;H        rcHd|jDS)Nc"h|] \}}|D]}| Sr_r_)r`rrrres r z/IncidentSender._inflight_ids..&sC   !'       r)rvaluesrs rrYzIncidentSender._inflight_ids%s1  #~4466    r)rN)__name__ __module__ __qualname____doc__rXrrrstrrrIlistrFr rCr\rZrrrlrrrrWsetrYr_rrrrs   #KEEEE8 8 c3h8 8 8 8 t  $s)    :t1C:::::(2&$&2&37:2& 2&2&2&2&p'7&6r&:&: 222 :2#s(# 2222h    S0A  d     23242222    tCH~  $     ( s3x      rr)rrzrmrxloggingr functoolsrtimertypesrtypingrr"defence360agent.contracts.messagesr !defence360agent.contracts.pluginsr defence360agent.internalsr (defence360agent.model.wordpress_incidentr r getLoggerrr?rr_rrrs@99 """"""JJJJJJ999999222222  8 $ $R R R R R R R R R R r