Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

@@ -10,34 +10,32 @@
*
*/
\define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/cms/interface/developer/developer.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
\IPS\Dispatcher\External::i();
use IPS\Dispatcher\External;
use IPS\Output;
use IPS\Request;
if ( \IPS\IN_DEV !== true AND ! \IPS\Theme::designersModeEnabled() )
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/cms/interface/developer/developer.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
External::i();
if ( !\IPS\IN_DEV )
{
exit();
}
/* The CSS is parsed by the theme engine, and the theme engine has plugins, and those plugins need to now which theme ID we're using */
if ( \IPS\Theme::designersModeEnabled() )
if ( isset( Request::i()->file ) )
{
\IPS\Session\Front::i();
}
if ( isset( \IPS\Request::i()->file ) )
{
$realPath = realpath( \IPS\ROOT_PATH . '/themes/' . \IPS\Request::i()->file );
$realPath = realpath( \IPS\ROOT_PATH . '/themes/' . Request::i()->file );
$pathContainer = realpath(\IPS\ROOT_PATH . '/themes/' );
if( $realPath === FALSE OR mb_substr( $realPath, 0, mb_strlen( $pathContainer ) ) !== $pathContainer )
{
\IPS\Output::i()->error( 'node_error', '3C171/8', 403, '' );
Output::i()->error( 'node_error', '3C171/8', 403, '' );
exit;
}
$file = file_get_contents( \IPS\ROOT_PATH . '/themes/' . \IPS\Request::i()->file );
\IPS\Output::setCacheTime( false );
\IPS\Output::i()->sendOutput( preg_replace( '#<ips:template.+?\n#', '', $file ), 200, ( mb_substr( \IPS\Request::i()->file, -4 ) === '.css' ) ? 'text/css' : 'text/javascript' );
$file = file_get_contents( \IPS\ROOT_PATH . '/themes/' . Request::i()->file );
Output::i()->pageCaching = FALSE;
Output::i()->sendOutput( preg_replace( '#<ips:template.+?\n#', '', $file ), 200, ( mb_substr( Request::i()->file, -4 ) === '.css' ) ? 'text/css' : 'text/javascript' );
}
+25 -18
View File
@@ -10,28 +10,35 @@
*
*/
\define('REPORT_EXCEPTIONS', TRUE);
use IPS\cms\Blocks\Block;
use IPS\Dispatcher\External;
use IPS\Output;
use IPS\Request;
use IPS\Settings;
use IPS\Theme;
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/cms/interface/external/external.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
\IPS\Dispatcher\External::i();
External::i();
$id = \IPS\Request::i()->blockid;
$k = \IPS\Request::i()->widgetid;
$blockHtml = \IPS\cms\Blocks\Block::display( $id );
$id = Request::i()->blockid;
$k = Request::i()->widgetid;
$blockHtml = Block::display( $id );
\IPS\Output::i()->jsFiles = array_merge( \IPS\Output::i()->jsFiles, \IPS\Output::i()->js( 'front_external.js', 'cms', 'front' ) );
\IPS\Output::i()->globalControllers[] = 'cms.front.external.communication';
Output::i()->jsFiles = array_merge( Output::i()->jsFiles, Output::i()->js( 'front_external.js', 'cms', 'front' ) );
Output::i()->globalControllers[] = 'cms.front.external.communication';
$cache = FALSE;
try
{
if ( \is_numeric( $id ) )
if ( is_numeric( $id ) )
{
$block = \IPS\cms\Blocks\Block::load( $id );
$block = Block::load( $id );
}
else if ( \is_string( $id ) )
else if ( is_string( $id ) )
{
$block = \IPS\cms\Blocks\Block::load( $id, 'block_key' );
$block = Block::load( $id, 'block_key' );
}
if ( $block->active )
@@ -39,25 +46,25 @@ try
$cache = ( $block->type == 'custom' ) ? $block->cache : TRUE;
}
}
catch( \OutOfRangeException $ex ){}
catch(OutOfRangeException $ex ){}
if( !$cache OR !\IPS\Settings::i()->widget_cache_ttl )
if( !$cache OR !Settings::i()->widget_cache_ttl )
{
\IPS\Output::setCacheTime( false );
Output::i()->pageCaching = FALSE;
$headers = array();
}
else
{
$headers = \IPS\Output::getCacheHeaders( time(), \IPS\Settings::i()->widget_cache_ttl );
$headers = Output::getCacheHeaders( time(), Settings::i()->widget_cache_ttl );
}
/* Remove protection headers. This is fine in this case because we only output */
if( isset( \IPS\Output::i()->httpHeaders['X-Frame-Options'] ) )
if( isset( Output::i()->httpHeaders['X-Frame-Options'] ) )
{
foreach( [ 'Content-Security-Policy','X-Content-Security-Policy', 'X-Frame-Options' ] as $toRemove )
{
unset( \IPS\Output::i()->httpHeaders[$toRemove] );
unset( Output::i()->httpHeaders[$toRemove] );
}
}
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core' )->blankTemplate( $blockHtml ), 200, 'text/html', $headers );
Output::i()->sendOutput( Theme::i()->getTemplate( 'global', 'core' )->blankTemplate( $blockHtml ), 200, 'text/html', $headers );
+33 -26
View File
@@ -9,22 +9,30 @@
* @since 27 May 2015
*/
\define('REPORT_EXCEPTIONS', TRUE);
use IPS\cms\Databases;
use IPS\Dispatcher\External;
use IPS\Dispatcher\Front;
use IPS\File;
use IPS\Member;
use IPS\Output;
use IPS\Request;
define('REPORT_EXCEPTIONS', TRUE);
require_once str_replace( 'applications/cms/interface/file/file.php', '', str_replace( '\\', '/', __FILE__ ) ) . 'init.php';
\IPS\Dispatcher\External::i();
External::i();
try
{
/* Load member */
$member = \IPS\Member::loggedIn();
$member = Member::loggedIn();
/* Set up autoloader for CMS */
/* Init */
$databaseId = \intval( \IPS\Request::i()->database );
$database = \IPS\cms\Databases::load( $databaseId );
$recordId = \intval( \IPS\Request::i()->record );
$fileName = urldecode( \IPS\Request::i()->file );
$databaseId = intval( Request::i()->database );
$database = Databases::load( $databaseId );
$recordId = intval( Request::i()->record );
$fileName = urldecode( Request::i()->file );
$recordClass = '\IPS\cms\Records' . $databaseId;
$realFileName = NULL;
@@ -32,53 +40,52 @@ try
{
$record = $recordClass::load( $recordId );
}
catch( \OutOfRangeException $ex )
catch(OutOfRangeException $ex )
{
\IPS\Output::i()->error( 'no_module_permission', '2T279/1', 403, '' );
Output::i()->error( 'no_module_permission', '2T279/1', 403, '' );
}
if ( ! $record->canView() )
{
\IPS\Output::i()->error( 'no_module_permission', '2T279/2', 403, '' );
Output::i()->error( 'no_module_permission', '2T279/2', 403, '' );
}
$realFileName = \IPS\Text\Encrypt::fromTag( \IPS\Request::i()->fileKey )->decrypt();
$realFileName = \IPS\Text\Encrypt::fromTag( Request::i()->fileKey )->decrypt();
if ( ! $realFileName )
{
\IPS\Output::i()->error( 'no_module_permission', '2T279/4', 403, '' );
Output::i()->error( 'no_module_permission', '2T279/4', 403, '' );
}
/* Get file and data */
try
{
$file = \IPS\File::get( 'cms_Records', $realFileName );
$file = File::get( 'cms_Records', $realFileName );
}
catch( \Exception $ex )
catch(Exception $ex )
{
\IPS\Output::i()->error( 'no_module_permission', '2T279/3', 404, '' );
Output::i()->error( 'no_module_permission', '2T279/3', 404, '' );
}
$headers = array_merge( \IPS\Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => \IPS\Output::getContentDisposition( 'attachment', \IPS\Request::i()->file ), "X-Content-Type-Options" => "nosniff" ) );
$headers = array_merge( Output::getCacheHeaders( time(), 360 ), array( "Content-Disposition" => Output::getContentDisposition( 'attachment', Request::i()->file ), "X-Content-Type-Options" => "nosniff" ) );
/* Send headers and print file */
\IPS\Output::i()->sendStatusCodeHeader( 200 );
\IPS\Output::i()->sendHeader( "Content-type: " . \IPS\File::getMimeType( \IPS\Request::i()->file ) . ";charset=UTF-8" );
Output::i()->sendStatusCodeHeader( 200 );
Output::i()->sendHeader( "Content-type: " . File::getMimeType( Request::i()->file ) . ";charset=UTF-8" );
foreach( $headers as $key => $header )
{
\IPS\Output::i()->sendHeader( $key . ': ' . $header );
Output::i()->sendHeader( $key . ': ' . $header );
}
\IPS\Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
\IPS\Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
\IPS\Output::i()->sendHeader( "Cross-Origin-Opener-Policy: same-origin" );
Output::i()->sendHeader( "Content-Length: " . $file->filesize() );
Output::i()->sendHeader( "Content-Security-Policy: default-src 'none'; sandbox" );
Output::i()->sendHeader( "X-Content-Security-Policy: default-src 'none'; sandbox" );
$file->printFile();
exit;
}
catch ( \UnderflowException $e )
catch (UnderflowException $e )
{
\IPS\Dispatcher\Front::i();
\IPS\Output::i()->sendOutput( '', 404 );
Front::i();
Output::i()->sendOutput( '', 404 );
}