Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
@@ -11,30 +11,54 @@
|
||||
namespace IPS\core\modules\admin\settings;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use Exception;
|
||||
use IPS\Db;
|
||||
use IPS\Dispatcher;
|
||||
use IPS\Dispatcher\Controller;
|
||||
use IPS\Helpers\Form;
|
||||
use IPS\Helpers\Form\CheckboxSet;
|
||||
use IPS\Helpers\Form\Interval;
|
||||
use IPS\Helpers\Form\Number;
|
||||
use IPS\Helpers\Form\Radio;
|
||||
use IPS\Helpers\Form\Translatable;
|
||||
use IPS\Helpers\Tree\Tree;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Lang;
|
||||
use IPS\Member;
|
||||
use IPS\Member\Group;
|
||||
use IPS\MFA\MFAHandler;
|
||||
use IPS\Output;
|
||||
use IPS\Request;
|
||||
use IPS\Session;
|
||||
use IPS\Settings;
|
||||
use IPS\Theme;
|
||||
use function defined;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Multi-Factor Authentication
|
||||
*/
|
||||
class _mfa extends \IPS\Dispatcher\Controller
|
||||
class mfa extends Controller
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
public static bool $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function execute()
|
||||
public function execute() : void
|
||||
{
|
||||
\IPS\Dispatcher::i()->checkAcpPermission( 'mfa_manage' );
|
||||
Dispatcher::i()->checkAcpPermission( 'mfa_manage' );
|
||||
parent::execute();
|
||||
}
|
||||
|
||||
@@ -43,14 +67,14 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function manage()
|
||||
protected function manage() : void
|
||||
{
|
||||
$activeTabContents = '';
|
||||
$tabs = array(
|
||||
'handlers' => 'mfa_handlers',
|
||||
'settings' => 'mfa_settings'
|
||||
);
|
||||
$activeTab = ( isset( \IPS\Request::i()->tab ) and array_key_exists( \IPS\Request::i()->tab, $tabs ) ) ? \IPS\Request::i()->tab : 'handlers';
|
||||
$activeTab = ( isset( Request::i()->tab ) and array_key_exists( Request::i()->tab, $tabs ) ) ? Request::i()->tab : 'handlers';
|
||||
|
||||
if ( $activeTab === 'handlers' )
|
||||
{
|
||||
@@ -61,14 +85,14 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
$activeTabContents = $this->_manageSettings();
|
||||
}
|
||||
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('menu__core_settings_mfa');
|
||||
if( \IPS\Request::i()->isAjax() )
|
||||
Output::i()->title = Member::loggedIn()->language()->addToStack('menu__core_settings_mfa');
|
||||
if( Request::i()->isAjax() )
|
||||
{
|
||||
\IPS\Output::i()->output = $activeTabContents;
|
||||
Output::i()->output = $activeTabContents;
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global' )->tabs( $tabs, $activeTab, $activeTabContents, \IPS\Http\Url::internal( "app=core&module=settings&controller=mfa" ) );
|
||||
Output::i()->output = Theme::i()->getTemplate( 'forms' )->blurb( 'mfa_blurb' ) . Theme::i()->getTemplate( 'global' )->tabs( $tabs, $activeTab, $activeTabContents, Url::internal( "app=core&module=settings&controller=mfa" ) );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -77,22 +101,22 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
protected function _manageHandlers()
|
||||
protected function _manageHandlers() : string
|
||||
{
|
||||
/* Create the tree */
|
||||
$url = \IPS\Http\Url::internal( "app=core&module=settings&controller=mfa&tab=handlers" );
|
||||
$tree = new \IPS\Helpers\Tree\Tree(
|
||||
$url = Url::internal( "app=core&module=settings&controller=mfa&tab=handlers" );
|
||||
$tree = new Tree(
|
||||
$url,
|
||||
NULL,
|
||||
function() use( $url ) {
|
||||
$return = array();
|
||||
|
||||
foreach ( \IPS\MFA\MFAHandler::handlers() as $key => $handler )
|
||||
foreach ( MFAHandler::handlers() as $key => $handler )
|
||||
{
|
||||
$return[] = \IPS\Theme::i()->getTemplate( 'trees', 'core' )->row(
|
||||
$return[] = Theme::i()->getTemplate( 'trees', 'core' )->row(
|
||||
$url,
|
||||
$key,
|
||||
\IPS\Member::loggedIn()->language()->addToStack("mfa_{$key}_title"),
|
||||
Member::loggedIn()->language()->addToStack("mfa_{$key}_title"),
|
||||
FALSE,
|
||||
array(
|
||||
'settings' => array(
|
||||
@@ -101,7 +125,7 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
'link' => $url->setQueryString( array( 'do' => 'settings', 'key' => $key ) ),
|
||||
)
|
||||
),
|
||||
\IPS\Member::loggedIn()->language()->addToStack("mfa_{$key}_desc"),
|
||||
Member::loggedIn()->language()->addToStack("mfa_{$key}_desc"),
|
||||
NULL,
|
||||
NULL,
|
||||
FALSE,
|
||||
@@ -117,7 +141,7 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
);
|
||||
|
||||
/* Return */
|
||||
return \IPS\Theme::i()->getTemplate( 'forms' )->blurb( 'mfa_blurb', TRUE, TRUE ) . $tree;
|
||||
return $tree;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -125,42 +149,42 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function enableToggle()
|
||||
protected function enableToggle() : void
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
Session::i()->csrfCheck();
|
||||
|
||||
$key = \IPS\Request::i()->id;
|
||||
$handlers = \IPS\MFA\MFAHandler::handlers();
|
||||
$key = Request::i()->id;
|
||||
$handlers = MFAHandler::handlers();
|
||||
if ( !isset( $handlers[ $key ] ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'node_error', '2C345/1', 404, '' );
|
||||
Output::i()->error( 'node_error', '2C345/1', 404, '' );
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
$handlers[ $key ]->toggle( \IPS\Request::i()->status );
|
||||
$handlers[ $key ]->toggle( Request::i()->status );
|
||||
|
||||
if ( \IPS\Request::i()->status )
|
||||
if ( Request::i()->status )
|
||||
{
|
||||
\IPS\Session::i()->log( 'acplogs__mfa_handler_enabled', array( "mfa_{$key}_title" => TRUE ) );
|
||||
Session::i()->log( 'acplogs__mfa_handler_enabled', array( "mfa_{$key}_title" => TRUE ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Session::i()->log( 'acplogs__mfa_handler_disabled', array( "mfa_{$key}_title" => TRUE ) );
|
||||
Session::i()->log( 'acplogs__mfa_handler_disabled', array( "mfa_{$key}_title" => TRUE ) );
|
||||
}
|
||||
|
||||
if ( \IPS\Request::i()->isAjax() )
|
||||
if ( Request::i()->isAjax() )
|
||||
{
|
||||
\IPS\Output::i()->json('OK');
|
||||
Output::i()->json('OK');
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=settings&controller=mfa" ) );
|
||||
Output::i()->redirect( Url::internal( "app=core&module=settings&controller=mfa" ) );
|
||||
}
|
||||
}
|
||||
catch ( \Exception $e )
|
||||
catch ( Exception $e )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=settings&controller=mfa&tab=handlers&do=settings&key=" . $key ) );
|
||||
Output::i()->redirect( Url::internal( "app=core&module=settings&controller=mfa&tab=handlers&do=settings&key=" . $key ) );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -169,21 +193,21 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function settings()
|
||||
protected function settings() : void
|
||||
{
|
||||
$key = \IPS\Request::i()->key;
|
||||
$handlers = \IPS\MFA\MFAHandler::handlers();
|
||||
$key = Request::i()->key;
|
||||
$handlers = MFAHandler::handlers();
|
||||
if ( !isset( $handlers[ $key ] ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'node_error', '2C345/2', 404, '' );
|
||||
Output::i()->error( 'node_error', '2C345/2', 404, '' );
|
||||
}
|
||||
|
||||
$output = $handlers[ $key ]->acpSettings();
|
||||
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack("mfa_{$key}_title");
|
||||
\IPS\Output::i()->output = $output;
|
||||
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal('app=core&module=settings&controller=mfa&tab=handlers'), \IPS\Member::loggedIn()->language()->addToStack('menu__core_settings_mfa') );
|
||||
\IPS\Output::i()->breadcrumb[] = array( NULL, \IPS\Member::loggedIn()->language()->addToStack("mfa_{$key}_title") );
|
||||
Output::i()->title = Member::loggedIn()->language()->addToStack("mfa_{$key}_title");
|
||||
Output::i()->output = $output;
|
||||
Output::i()->breadcrumb[] = array( Url::internal('app=core&module=settings&controller=mfa&tab=handlers'), Member::loggedIn()->language()->addToStack('menu__core_settings_mfa') );
|
||||
Output::i()->breadcrumb[] = array( NULL, Member::loggedIn()->language()->addToStack("mfa_{$key}_title") );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -191,26 +215,26 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
protected function _manageSettings()
|
||||
protected function _manageSettings() : string
|
||||
{
|
||||
$form = new \IPS\Helpers\Form;
|
||||
$form = new Form;
|
||||
|
||||
$form->addHeader('mfa_header_setup');
|
||||
$groups = array_combine( array_keys( \IPS\Member\Group::groups() ), array_map( function( $_group ) { return (string) $_group; }, \IPS\Member\Group::groups() ) );
|
||||
$form->add( new \IPS\Helpers\Form\CheckboxSet( 'mfa_required_groups', \IPS\Settings::i()->mfa_required_groups == '*' ? '*' : explode( ',', \IPS\Settings::i()->mfa_required_groups ), FALSE, array(
|
||||
$groups = array_combine( array_keys( Group::groups() ), array_map( function( $_group ) { return (string) $_group; }, Group::groups() ) );
|
||||
$form->add( new CheckboxSet( 'mfa_required_groups', Settings::i()->mfa_required_groups == '*' ? '*' : explode( ',', Settings::i()->mfa_required_groups ), FALSE, array(
|
||||
'multiple' => TRUE,
|
||||
'options' => $groups,
|
||||
'unlimited' => '*',
|
||||
'unlimitedLang' => 'everyone',
|
||||
'impliedUnlimited' => TRUE
|
||||
) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'mfa_required_prompt', \IPS\Settings::i()->mfa_required_prompt, FALSE, array(
|
||||
$form->add( new Radio( 'mfa_required_prompt', Settings::i()->mfa_required_prompt, FALSE, array(
|
||||
'options' => array(
|
||||
'immediate' => 'mfa_prompt_immediate',
|
||||
'access' => 'mfa_prompt_access',
|
||||
)
|
||||
), NULL, NULL, NULL, 'mfa_required_prompt' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'mfa_optional_prompt', \IPS\Settings::i()->mfa_optional_prompt, FALSE, array(
|
||||
$form->add( new Radio( 'mfa_optional_prompt', Settings::i()->mfa_optional_prompt, FALSE, array(
|
||||
'options' => array(
|
||||
'immediate' => 'mfa_prompt_immediate',
|
||||
'access' => 'mfa_prompt_access',
|
||||
@@ -221,15 +245,15 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
'access' => array( 'security_questions_opt_out_warning' ),
|
||||
)
|
||||
), NULL, NULL, NULL, 'mfa_optional_prompt' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Translatable( 'security_questions_opt_out_warning', NULL, FALSE, array( 'app' => 'core', 'key' => 'security_questions_opt_out_warning_value' ), NULL, NULL, NULL, 'security_questions_opt_out_warning' ) );
|
||||
$form->add( new Translatable( 'security_questions_opt_out_warning', NULL, FALSE, array( 'app' => 'core', 'key' => 'security_questions_opt_out_warning_value' ), NULL, NULL, NULL, 'security_questions_opt_out_warning' ) );
|
||||
|
||||
$form->addHeader('mfa_header_authentication');
|
||||
$form->add( new \IPS\Helpers\Form\CheckboxSet( 'security_questions_areas', \IPS\Settings::i()->security_questions_areas ? explode( ',', \IPS\Settings::i()->security_questions_areas ) : array_keys( \IPS\MFA\MFAHandler::areas() ), FALSE, array( 'options' => \IPS\MFA\MFAHandler::areas() ), NULL, NULL, NULL, 'security_questions_areas' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Interval( 'security_questions_timer', \IPS\Settings::i()->security_questions_timer, FALSE, array( 'valueAs' => \IPS\Helpers\Form\Interval::MINUTES, 'unlimited' => 0, 'unlimitedLang' => 'security_questions_timer_session' ) ) );
|
||||
$form->add( new CheckboxSet( 'security_questions_areas', Settings::i()->security_questions_areas ? explode( ',', Settings::i()->security_questions_areas ) : array_keys( MFAHandler::areas() ), FALSE, array( 'options' => MFAHandler::areas() ), NULL, NULL, NULL, 'security_questions_areas' ) );
|
||||
$form->add( new Interval( 'security_questions_timer', Settings::i()->security_questions_timer, FALSE, array( 'valueAs' => Interval::MINUTES, 'unlimited' => 0, 'unlimitedLang' => 'security_questions_timer_session' ) ) );
|
||||
|
||||
$form->addHeader('mfa_header_recovery');
|
||||
$form->add( new \IPS\Helpers\Form\Number( 'security_questions_tries', \IPS\Settings::i()->security_questions_tries, FALSE, array( 'min' => 1 ) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'mfa_lockout_behaviour', \IPS\Settings::i()->mfa_lockout_behaviour, FALSE, array(
|
||||
$form->add( new Number( 'security_questions_tries', Settings::i()->security_questions_tries, FALSE, array( 'min' => 1 ) ) );
|
||||
$form->add( new Radio( 'mfa_lockout_behaviour', Settings::i()->mfa_lockout_behaviour, FALSE, array(
|
||||
'options' => array(
|
||||
'lock' => 'mfa_lockout_behaviour_lock',
|
||||
'email' => 'mfa_lockout_behaviour_email',
|
||||
@@ -239,8 +263,8 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
'lock' => array( 'mfa_lockout_time' )
|
||||
)
|
||||
) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Interval( 'mfa_lockout_time', \IPS\Settings::i()->mfa_lockout_time, FALSE, array( 'valueAs' => \IPS\Helpers\Form\Interval::MINUTES, 'min' => 1 ), NULL, NULL, NULL, 'mfa_lockout_time' ) );
|
||||
$form->add( new \IPS\Helpers\Form\CheckboxSet( 'mfa_forgot_behaviour', explode( ',', \IPS\Settings::i()->mfa_forgot_behaviour ), FALSE, array(
|
||||
$form->add( new Interval( 'mfa_lockout_time', Settings::i()->mfa_lockout_time, FALSE, array( 'valueAs' => Interval::MINUTES, 'min' => 1 ), NULL, NULL, NULL, 'mfa_lockout_time' ) );
|
||||
$form->add( new CheckboxSet( 'mfa_forgot_behaviour', explode( ',', Settings::i()->mfa_forgot_behaviour ), FALSE, array(
|
||||
'options' => array(
|
||||
'email' => 'mfa_forgot_behaviour_email',
|
||||
'contact' => 'mfa_forgot_behaviour_contact',
|
||||
@@ -250,7 +274,7 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
|
||||
if ( $values = $form->values() )
|
||||
{
|
||||
\IPS\Lang::saveCustom( 'core', 'security_questions_opt_out_warning_value', $values['security_questions_opt_out_warning'] );
|
||||
Lang::saveCustom( 'core', 'security_questions_opt_out_warning_value', $values['security_questions_opt_out_warning'] );
|
||||
unset( $values['security_questions_opt_out_warning'] );
|
||||
|
||||
$values['mfa_required_groups'] = ( $values['mfa_required_groups'] == '*' ) ? '*' : implode( ',', $values['mfa_required_groups'] );
|
||||
@@ -259,8 +283,8 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
|
||||
$form->saveAsSettings( $values );
|
||||
|
||||
\IPS\Session::i()->log( 'acplogs__mfa_settings_updated' );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=settings&controller=mfa&tab=settings' ), 'saved' );
|
||||
Session::i()->log( 'acplogs__mfa_settings_updated' );
|
||||
Output::i()->redirect( Url::internal( 'app=core&module=settings&controller=mfa&tab=settings' ), 'saved' );
|
||||
}
|
||||
|
||||
return (string) $form;
|
||||
@@ -271,16 +295,16 @@ class _mfa extends \IPS\Dispatcher\Controller
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function resetSecurityAnswers()
|
||||
public function resetSecurityAnswers() : void
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
Session::i()->csrfCheck();
|
||||
|
||||
\IPS\Db::i()->delete( 'core_security_answers' );
|
||||
\IPS\Db::i()->update( 'core_members', "members_bitoptions2=members_bitoptions2 &~ 512" );
|
||||
Db::i()->delete( 'core_security_answers' );
|
||||
Db::i()->update( 'core_members', "members_bitoptions2=members_bitoptions2 &~ 512" );
|
||||
|
||||
/* Log MFA reset */
|
||||
\IPS\Session::i()->log( 'acplogs__mfa_questions_reset' );
|
||||
Session::i()->log( 'acplogs__mfa_questions_reset' );
|
||||
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=settings&controller=mfa&tab=handlers&do=settings&key=questions" ), 'acplogs__mfa_questions_reset' );
|
||||
Output::i()->redirect( Url::internal( "app=core&module=settings&controller=mfa&tab=handlers&do=settings&key=questions" ), 'acplogs__mfa_questions_reset' );
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user