Version 5.0.0 beta 1

This commit is contained in:
Neo committed 2025-12-19 16:27:35 -08:00
1 parent 25ddeb65d6
commit 15c7beabc5
6736 files changed
+627902 -497943

No files matched your search

@@ -13,38 +13,54 @@ namespace IPS\core\modules\admin\members;
/* To prevent PHP errors (extending class does not exist) revealing path */
use IPS\DateTime;
use IPS\Db;
use IPS\Dispatcher;
use IPS\Dispatcher\Controller;
use IPS\Helpers\Form;
use IPS\Helpers\Form\Radio;
use IPS\Helpers\Form\Url as FormUrl;
use IPS\Helpers\Table\Db as TableDb;
use IPS\Http\Url;
use IPS\Member;
use IPS\Member\PrivacyAction;
use IPS\Output;
use IPS\Request;
use IPS\Session;
use IPS\Settings;
use IPS\Theme;
use OutOfRangeException;
use function defined;
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* privacy
*/
class _privacy extends \IPS\Dispatcher\Controller
class privacy extends Controller
{
/**
* @brief Has been CSRF-protected
*/
public static $csrfProtected = TRUE;
public static bool $csrfProtected = TRUE;
/**
* Execute
*
* @return void
*/
public function execute()
public function execute() : void
{
\IPS\Dispatcher::i()->checkAcpPermission( 'privacy_manage' );
\IPS\Output::i()->sidebar['actions']['settings'] = array(
Dispatcher::i()->checkAcpPermission( 'privacy_manage' );
Output::i()->sidebar['actions']['settings'] = array(
'icon' => 'cog',
'title' => 'settings',
'link' => $this->url->setQueryString( 'do', 'settings' ),
'data' => array( 'ipsDialog' => '', 'ipsDialog-title' => \IPS\Member::loggedIn()->language()->addToStack('settings') )
'data' => array( 'ipsDialog' => '', 'ipsDialog-title' => Member::loggedIn()->language()->addToStack('settings') )
);
parent::execute();
}
@@ -54,19 +70,19 @@ class _privacy extends \IPS\Dispatcher\Controller
*
* @return void
*/
protected function manage()
protected function manage() : void
{
/* Some advanced search links may bring us here */
\IPS\Output::i()->bypassCsrfKeyCheck = true;
Output::i()->bypassCsrfKeyCheck = true;
/* Create the table */
$where = [ [ \IPS\Db::i()->in('action', [\IPS\Member\PrivacyAction::TYPE_REQUEST_DELETE, \IPS\Member\PrivacyAction::TYPE_REQUEST_PII] ) ], ['approved=?', 0] ];
$table = new \IPS\Helpers\Table\Db( 'core_member_privacy_actions', \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' ), $where );
$where = [ [ Db::i()->in('action', [ PrivacyAction::TYPE_REQUEST_DELETE, PrivacyAction::TYPE_REQUEST_PII] ) ], ['approved=?', 0] ];
$table = new TableDb( 'core_member_privacy_actions', Url::internal( 'app=core&module=members&controller=privacy' ), $where );
$table->include = [ 'photo', 'name', 'email', 'joined','action','request_date' ];
$table->filters = [
'deletion_request' => ['action=?', \IPS\Member\PrivacyAction::TYPE_REQUEST_DELETE],
'pii_data' => ['action=?', \IPS\Member\PrivacyAction::TYPE_REQUEST_PII],
'deletion_request' => ['action=?', PrivacyAction::TYPE_REQUEST_DELETE],
'pii_data' => ['action=?', PrivacyAction::TYPE_REQUEST_PII],
];
$table->joins = [
@@ -76,50 +92,51 @@ class _privacy extends \IPS\Dispatcher\Controller
$table->parsers = [
'photo' => function( $val, $row )
{
return \IPS\Theme::i()->getTemplate( 'global', 'core' )->userPhoto( \IPS\Member::constructFromData( $row ), 'tiny' );
return Theme::i()->getTemplate( 'global', 'core' )->userPhoto( Member::constructFromData( $row ), 'tiny' );
},
'name' => function( $val, $row ){
if( $val )
{
$member = \IPS\Member::constructFromData( $row );
$member = Member::constructFromData( $row );
if( $banned = $member->isBanned() )
{
if( $banned instanceof \IPS\DateTime )
if( $banned instanceof DateTime )
{
$title = \IPS\Member::loggedIn()->language()->addToStack( 'suspended_until', FALSE, array( 'sprintf' => array( $banned->localeDate() ) ) );
$title = Member::loggedIn()->language()->addToStack( 'suspended_until', FALSE, array( 'sprintf' => array( $banned->localeDate() ) ) );
}else
{
$title = \IPS\Member::loggedIn()->language()->addToStack( 'banned' );
$title = Member::loggedIn()->language()->addToStack( 'banned' );
}
return "<a href='".\IPS\Http\Url::internal( 'app=core&module=members&controller=members&do=view&id=' ).$row[ 'member_id' ]."'>".htmlentities( $val, ENT_DISALLOWED, 'UTF-8', FALSE )."</a> &nbsp; <span class='ipsBadge ipsBadge_negative'>".$title.'</span> ';
return "<a href='". Url::internal( 'app=core&module=members&controller=members&do=view&id=' ).$row[ 'member_id' ]."'>".htmlentities( $val, ENT_DISALLOWED, 'UTF-8', FALSE )."</a> &nbsp; <span class='ipsBadge ipsBadge--negative'>".$title.'</span> ';
}else
{
return "<a href='".\IPS\Http\Url::internal( 'app=core&module=members&controller=members&do=view&id=' ).$row[ 'member_id' ]."'>".htmlentities( $val, ENT_DISALLOWED, 'UTF-8', FALSE ).'</a>';
return "<a href='". Url::internal( 'app=core&module=members&controller=members&do=view&id=' ).$row[ 'member_id' ]."'>".htmlentities( $val, ENT_DISALLOWED, 'UTF-8', FALSE ).'</a>';
}
}
else
{
return \IPS\Theme::i()->getTemplate( 'members', 'core', 'admin' )->memberReserved( \IPS\Member::constructFromData( $row ) );
return Theme::i()->getTemplate( 'members', 'core', 'admin' )->memberReserved( Member::constructFromData( $row ) );
}
},
'joined' => function( $val, $row )
'joined' => function( $val )
{
return \IPS\DateTime::ts( $val )->localeDate();
return DateTime::ts( $val )->localeDate();
},
'request_date' => function( $val, $row )
'request_date' => function( $val )
{
return \IPS\DateTime::ts( $val )->localeDate();
return DateTime::ts( $val )->localeDate();
},
'action' => function( $val, $row )
'action' => function( $val )
{
switch ( $val )
{
case \IPS\Member\PrivacyAction::TYPE_REQUEST_PII:
return \IPS\Member::loggedIn()->language()->addToStack('pii_download_requested');
case \IPS\Member\PrivacyAction::TYPE_REQUEST_DELETE:
return \IPS\Member::loggedIn()->language()->addToStack('account_deletion_requested');
case PrivacyAction::TYPE_REQUEST_PII:
return Member::loggedIn()->language()->addToStack('pii_download_requested');
case PrivacyAction::TYPE_REQUEST_DELETE:
return Member::loggedIn()->language()->addToStack('account_deletion_requested');
}
return '';
}
];
@@ -127,33 +144,33 @@ class _privacy extends \IPS\Dispatcher\Controller
{
$return = [];
if( $row['action'] == \IPS\Member\PrivacyAction::TYPE_REQUEST_PII )
if( $row['action'] == PrivacyAction::TYPE_REQUEST_PII )
{
$return[ 'approve' ] = [
'title' => 'approve',
'icon' => 'check-circle',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy&do=approvePii&id='.$row[ 'id' ] )->csrf()->getSafeUrlFromFilters(),
'link' => Url::internal( 'app=core&module=members&controller=privacy&do=approvePii&id='.$row[ 'id' ] )->csrf()->getSafeUrlFromFilters(),
];
$return['reject'] = [
'icon' => 'times',
'title' => 'reject',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy&do=rejectPii&id=' . $row['id'] )->csrf()->getSafeUrlFromFilters(),
'link' => Url::internal( 'app=core&module=members&controller=privacy&do=rejectPii&id=' . $row['id'] )->csrf()->getSafeUrlFromFilters(),
];
}
else if( $row['action'] == \IPS\Member\PrivacyAction::TYPE_REQUEST_DELETE )
else if( $row['action'] == PrivacyAction::TYPE_REQUEST_DELETE )
{
$member = \IPS\Member::constructFromData( $row );
$member = Member::constructFromData( $row );
$return[ 'approveDeletion' ] = [
'title' => 'approve',
'icon' => 'check-circle',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy&do=approveDeletion&id='.$row[ 'id' ] )->csrf()->getSafeUrlFromFilters(),
'data' => [ 'confirm' => '', 'confirmSubMessage' => \IPS\Member::loggedIn()->language()->addToStack( 'delete_member_confirm', FALSE, array( 'sprintf' => $member->name ) ) ]
'link' => Url::internal( 'app=core&module=members&controller=privacy&do=approveDeletion&id='.$row[ 'id' ] )->csrf()->getSafeUrlFromFilters(),
'data' => [ 'confirm' => '', 'confirmSubMessage' => Member::loggedIn()->language()->addToStack( 'delete_member_confirm', FALSE, array( 'sprintf' => $member->name ) ) ]
];
$return['rejectDeletion'] = [
'icon' => 'times',
'title' => 'reject',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy&do=rejectDeletion&id=' . $row['id'] )->csrf()->getSafeUrlFromFilters(),
'link' => Url::internal( 'app=core&module=members&controller=privacy&do=rejectDeletion&id=' . $row['id'] )->csrf()->getSafeUrlFromFilters(),
'data' => array(
)
@@ -165,8 +182,8 @@ class _privacy extends \IPS\Dispatcher\Controller
};
/* Display */
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'menu__core_members_privacy');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global', 'core' )->block( 'title', (string) $table );
Output::i()->title = Member::loggedIn()->language()->addToStack( 'menu__core_members_privacy');
Output::i()->output = Theme::i()->getTemplate( 'global', 'core' )->block( 'title', (string) $table );
}
/**
@@ -174,20 +191,20 @@ class _privacy extends \IPS\Dispatcher\Controller
*
* @return void
*/
protected function approvePii()
protected function approvePii() : void
{
\IPS\Session::i()->csrfCheck();
Session::i()->csrfCheck();
try
{
$request = \IPS\Member\PrivacyAction::load( \IPS\Request::i()->id );
$request = PrivacyAction::load( Request::i()->id );
$request->approvePiiRequest();
\IPS\Session::i()->log( 'acplog__piirequest_approved', array( $request->member->name => FALSE ) );
Session::i()->log( 'acplog__piirequest_approved', array( $request->member->name => FALSE ) );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2C432/1', 404, '' );
Output::i()->error( 'node_error', '2C432/1', 404, '' );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'approved' );
Output::i()->redirect( Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'approved' );
}
/**
@@ -195,20 +212,20 @@ class _privacy extends \IPS\Dispatcher\Controller
*
* @return void
*/
protected function rejectPii()
protected function rejectPii() : void
{
\IPS\Session::i()->csrfCheck();
Session::i()->csrfCheck();
try
{
$request = \IPS\Member\PrivacyAction::load( \IPS\Request::i()->id );
$request = PrivacyAction::load( Request::i()->id );
$request->rejectPiiRequest();
\IPS\Session::i()->log( 'acplog__piirequest_rejected', array( $request->member->name => FALSE ) );
Session::i()->log( 'acplog__piirequest_rejected', array( $request->member->name => FALSE ) );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2C432/2', 404, '' );
Output::i()->error( 'node_error', '2C432/2', 404, '' );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'pii_request_rejected' );
Output::i()->redirect( Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'pii_request_rejected' );
}
/**
@@ -216,24 +233,24 @@ class _privacy extends \IPS\Dispatcher\Controller
*
* @return void
*/
protected function approveDeletion()
protected function approveDeletion() : void
{
\IPS\Session::i()->csrfCheck();
Session::i()->csrfCheck();
try
{
$request = \IPS\Member\PrivacyAction::load( \IPS\Request::i()->id );
$request = PrivacyAction::load( Request::i()->id );
\IPS\Request::i()->confirmedDelete( message: \IPS\Member::loggedIn()->language()->addToStack( 'delete_member_confirm', FALSE, array( 'sprintf' => $request->member->name ) ) );
Request::i()->confirmedDelete( message: Member::loggedIn()->language()->addToStack( 'delete_member_confirm', FALSE, array( 'sprintf' => $request->member->name ) ) );
$request->deleteAccount();
\IPS\Session::i()->log( 'acplog__deletionrequest__approved', array( $request->member->name => FALSE ) );
Session::i()->log( 'acplog__deletionrequest__approved', array( $request->member->name => FALSE ) );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2C432/3', 404, '' );
Output::i()->error( 'node_error', '2C432/3', 404, '' );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'approved' );
Output::i()->redirect( Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'approved' );
}
/**
@@ -241,26 +258,26 @@ class _privacy extends \IPS\Dispatcher\Controller
*
* @return void
*/
protected function rejectDeletion()
protected function rejectDeletion() : void
{
\IPS\Session::i()->csrfCheck();
Session::i()->csrfCheck();
try
{
$request = \IPS\Member\PrivacyAction::load( \IPS\Request::i()->id );
$request = PrivacyAction::load( Request::i()->id );
$request->rejectDeletionRequest();
\IPS\Session::i()->log( 'acplog__deletionrequest__rejected', array( $request->member->name => FALSE ) );
Session::i()->log( 'acplog__deletionrequest__rejected', array( $request->member->name => FALSE ) );
}
catch( \OutOfRangeException $e )
catch( OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2C432/4', 404, '' );
Output::i()->error( 'node_error', '2C432/4', 404, '' );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'rejected' );
Output::i()->redirect( Url::internal( 'app=core&module=members&controller=privacy' )->getSafeUrlFromFilters(), 'rejected' );
}
protected function settings()
protected function settings() : void
{
$form = new \IPS\Helpers\Form();
$form->add( new \IPS\Helpers\Form\Radio( 'pii_type', \IPS\Settings::i()->pii_type, FALSE, array(
$form = new Form();
$form->add( new Radio( 'pii_type', Settings::i()->pii_type, FALSE, array(
'options' => array(
'off' => 'disabled',
'on' => 'enabled',
@@ -272,10 +289,10 @@ class _privacy extends \IPS\Dispatcher\Controller
)
) ) );
$form->add( new \IPS\Helpers\Form\Url( 'pii_link', \IPS\Settings::i()->pii_link, FALSE, array(), NULL, NULL, NULL, 'pii_link' ) );
$form->add( new FormUrl( 'pii_link', Settings::i()->pii_link, FALSE, array(), NULL, NULL, NULL, 'pii_link' ) );
$form->add( new \IPS\Helpers\Form\Radio( 'right_to_be_forgotten_type', \IPS\Settings::i()->right_to_be_forgotten_type, FALSE, array(
$form->add( new Radio( 'right_to_be_forgotten_type', Settings::i()->right_to_be_forgotten_type, FALSE, array(
'options' => array(
'off' => 'disabled',
'on' => 'enabled',
@@ -286,15 +303,15 @@ class _privacy extends \IPS\Dispatcher\Controller
'on' => array(),
)
) ) );
$form->add( new \IPS\Helpers\Form\Url( 'right_to_be_forgotten_link', \IPS\Settings::i()->right_to_be_forgotten_link, FALSE, array(), NULL, NULL, NULL, 'right_to_be_forgotten_link' ) );
$form->add( new FormUrl( 'right_to_be_forgotten_link', Settings::i()->right_to_be_forgotten_link, FALSE, array(), NULL, NULL, NULL, 'right_to_be_forgotten_link' ) );
if( $values = $form->values() )
{
$form->saveAsSettings();
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=members&controller=privacy' ), 'saved' );
Output::i()->redirect( Url::internal( 'app=core&module=members&controller=privacy' ), 'saved' );
}
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'settings');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global', 'core' )->block( 'title', (string) $form );
Output::i()->title = Member::loggedIn()->language()->addToStack( 'settings');
Output::i()->output = Theme::i()->getTemplate( 'global', 'core' )->block( 'title', (string) $form );
}
}