Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
+114
-120
@@ -11,26 +11,42 @@
|
||||
namespace IPS;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use DateInterval;
|
||||
use IPS\Data\Store;
|
||||
use IPS\Helpers\Form;
|
||||
use IPS\Http\Url;
|
||||
use IPS\Http\Url\Exception;
|
||||
use IPS\Http\Url\Internal;
|
||||
use IPS\Patterns\Singleton;
|
||||
use function defined;
|
||||
use function function_exists;
|
||||
use function in_array;
|
||||
use function intval;
|
||||
use function is_array;
|
||||
use function mb_strtolower;
|
||||
use function substr;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* HTTP Request Class
|
||||
*/
|
||||
class _Request extends \IPS\Patterns\Singleton
|
||||
class Request extends Singleton
|
||||
{
|
||||
/**
|
||||
* @brief Singleton Instance
|
||||
*/
|
||||
protected static $instance = NULL;
|
||||
protected static ?Singleton $instance = NULL;
|
||||
|
||||
/**
|
||||
* @brief Cookie data
|
||||
*/
|
||||
public $cookie = array();
|
||||
public array $cookie = array();
|
||||
|
||||
/**
|
||||
* Constructor
|
||||
@@ -54,20 +70,13 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
array_walk_recursive( $_COOKIE, array( $this, 'clean' ) );
|
||||
|
||||
/* If we have a cookie prefix, we have to strip it first */
|
||||
if( \IPS\COOKIE_PREFIX !== NULL )
|
||||
if( COOKIE_PREFIX !== NULL )
|
||||
{
|
||||
foreach( $_COOKIE as $key => $value )
|
||||
{
|
||||
if( \IPS\COOKIE_PREFIX !== null )
|
||||
if( mb_strpos( $key, COOKIE_PREFIX) === 0 )
|
||||
{
|
||||
if( mb_strpos( $key, \IPS\COOKIE_PREFIX ) === 0 )
|
||||
{
|
||||
$this->cookie[ preg_replace( "/^" . \IPS\COOKIE_PREFIX . "(.+?)/", "$1", $key ) ] = $value;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->cookie[ $key ] = $value;
|
||||
$this->cookie[ preg_replace( "/^" . COOKIE_PREFIX . "(.+?)/", "$1", $key ) ] = $value;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -80,14 +89,14 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
/**
|
||||
* Parse Incoming Data
|
||||
*
|
||||
* @param array $data Data
|
||||
* @param array $data Data
|
||||
* @return void
|
||||
*/
|
||||
protected function parseIncomingRecursively( $data )
|
||||
protected function parseIncomingRecursively( array $data ) : void
|
||||
{
|
||||
foreach( $data as $k => $v )
|
||||
{
|
||||
if ( \is_array( $v ) )
|
||||
if ( is_array( $v ) )
|
||||
{
|
||||
array_walk_recursive( $v, array( $this, 'clean' ) );
|
||||
}
|
||||
@@ -108,7 +117,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
* @param mixed $k Key
|
||||
* @return void
|
||||
*/
|
||||
protected function clean( &$v, $k )
|
||||
protected function clean( mixed &$v, mixed $k ) : void
|
||||
{
|
||||
/* Remove NULL bytes and the RTL control byte */
|
||||
$v = str_replace( array( "\0", "\u202E" ), '', $v );
|
||||
@@ -117,10 +126,10 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
/**
|
||||
* Get value from array
|
||||
*
|
||||
* @param string $key Key with square brackets (e.g. "foo[bar]")
|
||||
* @param string $key Key with square brackets (e.g. "foo[bar]")
|
||||
* @return mixed Value
|
||||
*/
|
||||
public function valueFromArray( $key )
|
||||
public function valueFromArray( string $key ): mixed
|
||||
{
|
||||
$array = $this->data;
|
||||
|
||||
@@ -151,9 +160,10 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
* This can be used in place of passing strings as arguments to functions where it is
|
||||
* desirable to avoid the value being included in a backtrace if an error occurs.
|
||||
*
|
||||
* @param string $k
|
||||
* @return object
|
||||
*/
|
||||
public function protect( $k )
|
||||
public function protect( string $k ): object
|
||||
{
|
||||
return eval('return new class
|
||||
{
|
||||
@@ -169,29 +179,18 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
public function isAjax()
|
||||
public function isAjax(): bool
|
||||
{
|
||||
return ( isset( $_SERVER['HTTP_X_REQUESTED_WITH'] ) and $_SERVER['HTTP_X_REQUESTED_WITH'] == 'XMLHttpRequest' );
|
||||
}
|
||||
|
||||
/**
|
||||
* Is this request from the mobile app?
|
||||
*
|
||||
* @deprecated 4.6.11 - Will be removed in future version
|
||||
* @return bool
|
||||
*/
|
||||
public function isApp()
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Is this an SSL/Secure request?
|
||||
*
|
||||
* @return bool
|
||||
* @note A common technique to check for SSL is to look for $_SERVER['SERVER_PORT'] == 443, however this is not a correct check. Nothing requires SSL to be on port 443, or http to be on port 80.
|
||||
*/
|
||||
public function isSecure()
|
||||
public function isSecure(): bool
|
||||
{
|
||||
if( !empty( $_SERVER['HTTPS'] ) AND ( mb_strtolower( $_SERVER['HTTPS'] ) == 'on' or $_SERVER['HTTPS'] === '1' ) )
|
||||
{
|
||||
@@ -224,14 +223,14 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
/**
|
||||
* @brief Cached URL
|
||||
*/
|
||||
protected $_url = NULL;
|
||||
protected mixed $_url = NULL;
|
||||
|
||||
/**
|
||||
* Get current URL
|
||||
*
|
||||
* @return \IPS\Http\Url
|
||||
* @return Url|string|null
|
||||
*/
|
||||
public function url()
|
||||
function url(): Url|string|null
|
||||
{
|
||||
if( $this->_url === NULL )
|
||||
{
|
||||
@@ -240,7 +239,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
$ruleMatched = FALSE;
|
||||
|
||||
/* Nginx uses HTTP_X_FORWARDED_SERVER. @see <a href='https://plone.lucidsolutions.co.nz/web/reverseproxyandcache/setting-nginx-http-x-forward-headers-for-reverse-proxy'>Nginx Reverse Proxy</a> */
|
||||
if ( !\IPS\CIC )
|
||||
if ( !CIC )
|
||||
{
|
||||
if ( !empty( $_SERVER['HTTP_X_FORWARDED_SERVER'] ) )
|
||||
{
|
||||
@@ -285,7 +284,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
}
|
||||
$url .= $_SERVER['QUERY_STRING'];
|
||||
|
||||
return $this->_url = \IPS\Http\Url::createFromString( $url, TRUE, TRUE );
|
||||
return $this->_url = Url::createFromString( $url, TRUE, TRUE );
|
||||
}
|
||||
|
||||
return $this->_url;
|
||||
@@ -297,11 +296,11 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public function ipAddress()
|
||||
public function ipAddress(): string
|
||||
{
|
||||
$addrs = array();
|
||||
|
||||
if ( \IPS\Settings::i()->xforward_matching )
|
||||
if ( Settings::i()->xforward_matching )
|
||||
{
|
||||
if( isset( $_SERVER['HTTP_X_FORWARDED_FOR'] ) )
|
||||
{
|
||||
@@ -353,16 +352,16 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
public function ipAddressIsBanned()
|
||||
public function ipAddressIsBanned(): bool
|
||||
{
|
||||
if ( isset( \IPS\Data\Store::i()->bannedIpAddresses ) )
|
||||
if ( isset( Store::i()->bannedIpAddresses ) )
|
||||
{
|
||||
$bannedIpAddresses = \IPS\Data\Store::i()->bannedIpAddresses;
|
||||
$bannedIpAddresses = Store::i()->bannedIpAddresses;
|
||||
}
|
||||
else
|
||||
{
|
||||
$bannedIpAddresses = iterator_to_array( \IPS\Db::i()->select( 'ban_content', 'core_banfilters', array( "ban_type=?", 'ip' ) ) );
|
||||
\IPS\Data\Store::i()->bannedIpAddresses = $bannedIpAddresses;
|
||||
$bannedIpAddresses = iterator_to_array( Db::i()->select( 'ban_content', 'core_banfilters', array( "ban_type=?", 'ip' ) ) );
|
||||
Store::i()->bannedIpAddresses = $bannedIpAddresses;
|
||||
}
|
||||
foreach ( $bannedIpAddresses as $ip )
|
||||
{
|
||||
@@ -380,14 +379,14 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return string
|
||||
*/
|
||||
public static function getCookiePath()
|
||||
public static function getCookiePath(): string
|
||||
{
|
||||
if( \IPS\COOKIE_PATH !== NULL )
|
||||
if( COOKIE_PATH !== NULL )
|
||||
{
|
||||
return \IPS\COOKIE_PATH;
|
||||
return COOKIE_PATH;
|
||||
}
|
||||
|
||||
$path = mb_substr( \IPS\Settings::i()->base_url, mb_strpos( \IPS\Settings::i()->base_url, ( !empty( $_SERVER['SERVER_NAME'] ) ) ? $_SERVER['SERVER_NAME'] : $_SERVER['HTTP_HOST'] ) + mb_strlen( ( !empty( $_SERVER['SERVER_NAME'] ) ) ? $_SERVER['SERVER_NAME'] : $_SERVER['HTTP_HOST'] ) );
|
||||
$path = mb_substr( Settings::i()->base_url, mb_strpos( Settings::i()->base_url, ( !empty( $_SERVER['SERVER_NAME'] ) ) ? $_SERVER['SERVER_NAME'] : $_SERVER['HTTP_HOST'] ) + mb_strlen( ( !empty( $_SERVER['SERVER_NAME'] ) ) ? $_SERVER['SERVER_NAME'] : $_SERVER['HTTP_HOST'] ) );
|
||||
$path = mb_substr( $path, mb_strpos( $path, '/' ) );
|
||||
|
||||
return $path;
|
||||
@@ -400,49 +399,49 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*/
|
||||
public static function getEssentialCookies(): array
|
||||
{
|
||||
return \IPS\Application::getEssentialCookieNames();
|
||||
return Application::getEssentialCookieNames();
|
||||
}
|
||||
|
||||
/**
|
||||
* Set a cookie
|
||||
*
|
||||
* @param string $name Name
|
||||
* @param string $name Name
|
||||
* @param mixed $value Value
|
||||
* @param \IPS\DateTime|null $expire Expiration date, or NULL for on session end
|
||||
* @param bool $httpOnly When TRUE the cookie will be made accessible only through the HTTP protocol
|
||||
* @param string|null $domain Domain to set to. If NULL, will be detected automatically.
|
||||
* @param string|null $path Path to set to. If NULL, will be detected automatically.
|
||||
* @param DateTime|null $expire Expiration date, or NULL for on session end
|
||||
* @param bool $httpOnly When TRUE the cookie will be made accessible only through the HTTP protocol
|
||||
* @param string|null $domain Domain to set to. If NULL, will be detected automatically.
|
||||
* @param string|null $path Path to set to. If NULL, will be detected automatically.
|
||||
* @return bool
|
||||
*/
|
||||
public function setCookie( $name, $value, $expire=NULL, $httpOnly=TRUE, $domain=NULL, $path=NULL )
|
||||
public function setCookie( string $name, mixed $value, DateTime $expire=NULL, bool $httpOnly=TRUE, string $domain=NULL, string $path=NULL ): bool
|
||||
{
|
||||
/* Let's see if this is an optional cookie and if it is one, if the user wants them */
|
||||
if( $this->skipCookie( $name ) )
|
||||
{
|
||||
\IPS\Log::debug('skipping ' . $name, 'cookie' );
|
||||
Log::debug('skipping ' . $name, 'cookie' );
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* Work out the path and if cookies should be SSL only */
|
||||
$sslOnly = FALSE;
|
||||
if( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' AND \IPS\COOKIE_BYPASS_SSLONLY !== TRUE )
|
||||
if( mb_substr( Settings::i()->base_url, 0, 5 ) == 'https' AND !COOKIE_BYPASS_SSLONLY )
|
||||
{
|
||||
$sslOnly = TRUE;
|
||||
}
|
||||
$path = $path ?: static::getCookiePath();
|
||||
|
||||
/* Are we forcing a cookie domain? */
|
||||
if( \IPS\COOKIE_DOMAIN !== NULL AND $domain === NULL )
|
||||
if( COOKIE_DOMAIN !== NULL AND $domain === NULL )
|
||||
{
|
||||
$domain = \IPS\COOKIE_DOMAIN;
|
||||
$domain = COOKIE_DOMAIN;
|
||||
}
|
||||
|
||||
$realName = $name;
|
||||
|
||||
/* What about a prefix? */
|
||||
if( \IPS\COOKIE_PREFIX !== NULL )
|
||||
if( COOKIE_PREFIX !== NULL )
|
||||
{
|
||||
$name = \IPS\COOKIE_PREFIX . $name;
|
||||
$name = COOKIE_PREFIX . $name;
|
||||
}
|
||||
|
||||
/* Set the cookie */
|
||||
@@ -463,7 +462,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*/
|
||||
protected function skipCookie( string $name ): bool
|
||||
{
|
||||
if( \IPS\Dispatcher::hasInstance() AND \IPS\Dispatcher::i()->controllerLocation === 'admin' )
|
||||
if( Dispatcher::hasInstance() AND Dispatcher::i()->controllerLocation === 'admin' )
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
@@ -480,36 +479,31 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
/* Check wildcard cookies */
|
||||
foreach( static::getEssentialCookies() as $c )
|
||||
{
|
||||
if (str_ends_with($c, '*'))
|
||||
if( mb_substr( $c, -1, 1 ) === '*' AND rtrim( $name, '*' ) === $name )
|
||||
{
|
||||
$prefix = mb_substr($c, 0, -1);
|
||||
|
||||
if( str_starts_with($name, $prefix ) )
|
||||
{
|
||||
return false;
|
||||
}
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
|
||||
return ( !\IPS\Member::loggedIn()->optionalCookiesAllowed );
|
||||
return ( !Member::loggedIn()->optionalCookiesAllowed );
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief Storage of cookie consent status
|
||||
*/
|
||||
protected $_cookieConsentEnabled = NULL;
|
||||
protected ?bool $_cookieConsentEnabled = NULL;
|
||||
|
||||
/**
|
||||
* Check whether cookie consent is required
|
||||
*
|
||||
* @return bool
|
||||
* @return bool|null
|
||||
*/
|
||||
public function cookieConsentEnabled():? bool
|
||||
public function cookieConsentEnabled(): ?bool
|
||||
{
|
||||
// See if cookie consent is enabled
|
||||
if( \IPS\Dispatcher::hasInstance() AND $this->_cookieConsentEnabled === NULL )
|
||||
if( Dispatcher::hasInstance() AND $this->_cookieConsentEnabled === NULL )
|
||||
{
|
||||
$this->_cookieConsentEnabled = ( \IPS\Settings::i()->guest_terms_bar AND mb_strstr( \IPS\Member::loggedIn()->language()->get('guest_terms_bar_text_value'), '%4$s' ) );
|
||||
$this->_cookieConsentEnabled = ( Settings::i()->guest_terms_bar AND mb_strstr( Member::loggedIn()->language()->get('guest_terms_bar_text_value'), '%4$s' ) );
|
||||
}
|
||||
|
||||
return $this->_cookieConsentEnabled;
|
||||
@@ -520,7 +514,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function clearLoginCookies()
|
||||
public function clearLoginCookies() : void
|
||||
{
|
||||
$this->setCookie( 'member_id', NULL );
|
||||
$this->setCookie( 'login_key', NULL );
|
||||
@@ -539,15 +533,15 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
/**
|
||||
* @brief Editor autosave keys to be cleared
|
||||
*/
|
||||
public $clearAutoSaveCookie = array();
|
||||
public array $clearAutoSaveCookie = array();
|
||||
|
||||
/**
|
||||
* Set cookie to clear autosave content from editor
|
||||
*
|
||||
* @param $autoSaveKey string The editor's autosave key
|
||||
* @param $autoSaveKey string The editor's autosave key
|
||||
* @return void
|
||||
*/
|
||||
public function setClearAutosaveCookie( $autoSaveKey )
|
||||
public function setClearAutosaveCookie( string $autoSaveKey ) : void
|
||||
{
|
||||
$this->clearAutoSaveCookie[ $autoSaveKey ] = $autoSaveKey;
|
||||
}
|
||||
@@ -567,29 +561,29 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public static function floodCheck()
|
||||
public static function floodCheck() : void
|
||||
{
|
||||
$groupFloodSeconds = \IPS\Member::loggedIn()->group['g_search_flood'];
|
||||
$groupFloodSeconds = Member::loggedIn()->group['g_search_flood'];
|
||||
|
||||
if ( \IPS\Session::i()->userAgent->bot )
|
||||
if ( Session::i()->userAgent->spider )
|
||||
{
|
||||
/* Force a 30 second flood control so if guests have it switched off, or set very low, you do not get flooded by known bots */
|
||||
$groupFloodSeconds = \IPS\BOT_SEARCH_FLOOD_SECONDS;
|
||||
$groupFloodSeconds = BOT_SEARCH_FLOOD_SECONDS;
|
||||
}
|
||||
|
||||
/* Flood control */
|
||||
if( $groupFloodSeconds )
|
||||
{
|
||||
$time = ( isset( \IPS\Request::i()->cookie['lastSearch'] ) ) ? \IPS\Request::i()->cookie['lastSearch'] : 0;
|
||||
$time = ( isset( Request::i()->cookie['lastSearch'] ) ) ? Request::i()->cookie['lastSearch'] : 0;
|
||||
|
||||
if( $time and ( time() - $time ) < $groupFloodSeconds )
|
||||
{
|
||||
$secondsToWait = $groupFloodSeconds - ( time() - $time );
|
||||
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'search_flood_error', FALSE, array( 'pluralize' => array( $secondsToWait ) ) ), '1C205/3', 429, \IPS\Member::loggedIn()->language()->addToStack( 'search_flood_error_admin', FALSE, array( 'pluralize' => array( $secondsToWait ) ) ), array( 'Retry-After' => \IPS\DateTime::create()->add( new \DateInterval( 'PT' . $secondsToWait . 'S' ) )->format('r') ) );
|
||||
Output::i()->error( Member::loggedIn()->language()->addToStack( 'search_flood_error', FALSE, array( 'pluralize' => array( $secondsToWait ) ) ), '1C205/3', 429, Member::loggedIn()->language()->addToStack( 'search_flood_error_admin', FALSE, array( 'pluralize' => array( $secondsToWait ) ) ), array( 'Retry-After' => DateTime::create()->add( new DateInterval( 'PT' . $secondsToWait . 'S' ) )->format('r') ) );
|
||||
}
|
||||
|
||||
$expire = new \IPS\DateTime;
|
||||
\IPS\Request::i()->setCookie( 'lastSearch', time(), $expire->add( new \DateInterval( 'PT' . \intval( $groupFloodSeconds ) . 'S' ) ) );
|
||||
$expire = new DateTime;
|
||||
Request::i()->setCookie( 'lastSearch', time(), $expire->add( new DateInterval( 'PT' . intval( $groupFloodSeconds ) . 'S' ) ) );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -599,9 +593,9 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
* @note Possible values: cgi, cgi-fcgi, fpm-fcgi
|
||||
* @return boolean
|
||||
*/
|
||||
public function isCgi()
|
||||
public function isCgi(): bool
|
||||
{
|
||||
if ( \substr( PHP_SAPI, 0, 3 ) == 'cgi' OR \substr( PHP_SAPI, -3 ) == 'cgi' )
|
||||
if ( substr( PHP_SAPI, 0, 3 ) == 'cgi' OR substr( PHP_SAPI, -3 ) == 'cgi' )
|
||||
{
|
||||
return true;
|
||||
}
|
||||
@@ -626,63 +620,63 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*/
|
||||
public function isZapier() : bool
|
||||
{
|
||||
return str_starts_with( \IPS\Request::i()->userAgent(), 'IPS Zapier Integration' );
|
||||
return str_starts_with( Request::i()->userAgent(), 'IPS Zapier Integration' );
|
||||
}
|
||||
|
||||
/**
|
||||
* Confirmation check
|
||||
*
|
||||
* @param string $title Lang string key for title
|
||||
* @param string $message Lang string key for confirm message
|
||||
* @param string $submit Lang string key for submit button
|
||||
* @param string $title Lang string key for title
|
||||
* @param string $message Lang string key for confirm message
|
||||
* @param string $submit Lang string key for submit button
|
||||
* @param string $css CSS classes for the message
|
||||
* @return bool
|
||||
*/
|
||||
public function confirmedDelete( $title = 'delete_confirm', $message = 'delete_confirm_detail', $submit = 'delete', string $css = 'ipsMessage ipsMessage_warning' )
|
||||
public function confirmedDelete( string $title = 'delete_confirm', string $message = 'delete_confirm_detail', string $submit = 'delete', string $css = 'ipsMessage ipsMessage_warning' ): bool
|
||||
{
|
||||
/* The confirmation dialogs will send form_submitted=1, as will displaying a form, so we check for this.
|
||||
If the admin (or user) simply visited a delete URL directly, this would not be included in the request. */
|
||||
if ( !isset( \IPS\Request::i()->wasConfirmed ) )
|
||||
if ( !isset( Request::i()->wasConfirmed ) )
|
||||
{
|
||||
$form = new \IPS\Helpers\Form( 'form', $submit );
|
||||
$form = new Form( 'form', $submit );
|
||||
$form->hiddenValues['wasConfirmed'] = 1;
|
||||
$form->class = 'ipsForm_vertical';
|
||||
$form->class = 'ipsForm--vertical ipsForm--confirmation-check';
|
||||
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( $title );
|
||||
Output::i()->title = Member::loggedIn()->language()->addToStack( $title );
|
||||
|
||||
/* We call sendOutput() to show the form now */
|
||||
if( \IPS\Dispatcher::hasInstance() and \IPS\Dispatcher::i()->controllerLocation === 'front' )
|
||||
if( Dispatcher::hasInstance() and Dispatcher::i()->controllerLocation === 'front' )
|
||||
{
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global', 'core' )->confirmDelete( $message, $form, $title );
|
||||
Output::i()->output = Theme::i()->getTemplate( 'global', 'core' )->confirmDelete( $message, $form, $title );
|
||||
}
|
||||
else
|
||||
{
|
||||
$form->addMessage( $message, $css);
|
||||
\IPS\Output::i()->output = $form;
|
||||
Output::i()->output = $form;
|
||||
}
|
||||
|
||||
if ( \IPS\Request::i()->isAjax() )
|
||||
if ( Request::i()->isAjax() )
|
||||
{
|
||||
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core', 'front' )->genericBlock( $form, \IPS\Output::i()->title ), 200, 'text/html' );
|
||||
Output::i()->sendOutput( Theme::i()->getTemplate( 'global', 'core', 'front' )->genericBlock( $form, Output::i()->title ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core' )->globalTemplate( \IPS\Output::i()->title, \IPS\Output::i()->output, array( 'app' => \IPS\Dispatcher::i()->application->directory, 'module' => \IPS\Dispatcher::i()->module->key, 'controller' => \IPS\Dispatcher::i()->controller ) ), 200, 'text/html' );
|
||||
Output::i()->sendOutput( Theme::i()->getTemplate( 'global', 'core' )->globalTemplate( Output::i()->title, Output::i()->output, array( 'app' => Dispatcher::i()->application->directory, 'module' => Dispatcher::i()->module->key, 'controller' => Dispatcher::i()->controller ) ) );
|
||||
}
|
||||
}
|
||||
|
||||
/* If we are here, just check the csrf key */
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
Session::i()->csrfCheck();
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Old IPB escape-on-input routine
|
||||
*
|
||||
* @param string|object $val The unescaped text (can be a string or an object that can be cast to a string)
|
||||
* @param object|string $val The unescaped text (can be a string or an object that can be cast to a string)
|
||||
* @return string The IPB3-style escaped text
|
||||
*/
|
||||
public static function legacyEscape( $val )
|
||||
public static function legacyEscape( object|string $val ): string
|
||||
{
|
||||
$val = (string) $val;
|
||||
|
||||
@@ -708,9 +702,9 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
* @param bool $allowExternal If set to TRUE, external URL's will be allowed and returned.
|
||||
* @param bool $onlyRequest If set to TRUE, will only look for the "ref" request parameter. Useful if you need to look for HTTP_REFERER at a specific point in time.
|
||||
* @param string|NULL $base If set, will only return URL's with this base.
|
||||
* @return \IPS\Http\Url|NULL
|
||||
* @return Url|NULL
|
||||
*/
|
||||
public function referrer( bool $allowExternal=FALSE, bool $onlyRequest=FALSE, ?string $base = NULL ): ?\IPS\Http\Url
|
||||
public function referrer( bool $allowExternal=FALSE, bool $onlyRequest=FALSE, ?string $base = NULL ): ?Url
|
||||
{
|
||||
/* Do we have a _ref request parameter? */
|
||||
$ref = NULL;
|
||||
@@ -730,9 +724,9 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
{
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
$ref = Url::createFromString( $ref );
|
||||
}
|
||||
catch( \IPS\Http\Url\Exception $e )
|
||||
catch( Exception $e )
|
||||
{
|
||||
/* Failed to create? Nope. */
|
||||
return NULL;
|
||||
@@ -745,9 +739,9 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
}
|
||||
|
||||
/* Return if URL is internal and not an open redirect, or if we're allowing external referrer references */
|
||||
if ( ( ( $ref instanceof \IPS\Http\Url\Internal ) AND !$ref->openRedirect() ) OR $allowExternal )
|
||||
if ( ( ( $ref instanceof Internal ) AND !$ref->openRedirect() ) OR $allowExternal )
|
||||
{
|
||||
if ( $base !== NULL AND ( $ref instanceof \IPS\Http\Url\Internal ) )
|
||||
if ( $base !== NULL AND ( $ref instanceof Internal ) )
|
||||
{
|
||||
if ( $ref->base === $base )
|
||||
{
|
||||
@@ -779,7 +773,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
*
|
||||
* @return string|null
|
||||
*/
|
||||
public function authorizationHeader()
|
||||
public function authorizationHeader(): ?string
|
||||
{
|
||||
/* Check if an API Key or Access Token has been passed as a parameter in the query string. Because of the
|
||||
obvious security issues with this, we do not recommend it, but sometimes it is the only choice */
|
||||
@@ -787,7 +781,7 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
{
|
||||
return 'Basic ' . base64_encode( $this->key . ':' );
|
||||
}
|
||||
if ( isset( $this->access_token ) and ( !\IPS\OAUTH_REQUIRES_HTTPS or $this->isSecure() ) )
|
||||
if ( isset( $this->access_token ) and ( !OAUTH_REQUIRES_HTTPS or $this->isSecure() ) )
|
||||
{
|
||||
return 'Bearer ' . $this->access_token;
|
||||
}
|
||||
@@ -810,13 +804,13 @@ class _Request extends \IPS\Patterns\Singleton
|
||||
}
|
||||
|
||||
/* ...if we didn't find anything there, try apache_request_headers() */
|
||||
if ( \function_exists('apache_request_headers') )
|
||||
if ( function_exists('apache_request_headers') )
|
||||
{
|
||||
$headers = @apache_request_headers();
|
||||
$headerKeys = ['authorization', 'x-authorization'];
|
||||
foreach ( $headers as $k => $v )
|
||||
{
|
||||
if ( \in_array( \mb_strtolower( $k ), $headerKeys ) )
|
||||
if ( in_array( mb_strtolower( $k ), $headerKeys ) )
|
||||
{
|
||||
return $v;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user