Version 5.0.0 beta 1
This commit is contained in:
1 parent
25ddeb65d6
commit
15c7beabc5
6736 files changed
+627902
-497943
No files matched your search
+114
-56
@@ -11,59 +11,76 @@
|
||||
namespace IPS;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
|
||||
use DateTimeZone;
|
||||
use IPS\Content\Item;
|
||||
use IPS\Dispatcher\Setup;
|
||||
use IPS\Http\Useragent;
|
||||
use IPS\Session\Admin;
|
||||
use IPS\Session\Front;
|
||||
use RuntimeException;
|
||||
use StdClass;
|
||||
use UnderflowException;
|
||||
use function defined;
|
||||
use function function_exists;
|
||||
use function get_called_class;
|
||||
use function get_class;
|
||||
use function in_array;
|
||||
use function substr;
|
||||
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
header( ( $_SERVER['SERVER_PROTOCOL'] ?? 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Session Handler
|
||||
*/
|
||||
abstract class _Session
|
||||
abstract class Session
|
||||
{
|
||||
/**
|
||||
* @brief Singleton Instance
|
||||
*/
|
||||
protected static $instance = NULL;
|
||||
protected static mixed $instance = NULL;
|
||||
|
||||
/**
|
||||
* @brief User agent information
|
||||
* @see \IPS\Http\Useragent::parse()
|
||||
* @see Useragent::parse
|
||||
*/
|
||||
public $userAgent = NULL;
|
||||
public ?Useragent $userAgent = NULL;
|
||||
|
||||
/**
|
||||
* @brief Session record - stored so plugins can access
|
||||
*/
|
||||
protected $sessionData = NULL;
|
||||
protected bool|null|array $sessionData = NULL;
|
||||
|
||||
/**
|
||||
* Get instance
|
||||
*
|
||||
* @return static
|
||||
* @return static|Front|Admin|StdClass
|
||||
*/
|
||||
public static function i()
|
||||
public static function i(): static|Front|Admin|StdClass
|
||||
{
|
||||
if( static::$instance === NULL )
|
||||
{
|
||||
$classname = \get_called_class();
|
||||
$classname = get_called_class();
|
||||
|
||||
if ( $classname === 'IPS\Session' )
|
||||
{
|
||||
if( class_exists( 'IPS\Dispatcher', FALSE ) )
|
||||
{
|
||||
$location = ( \IPS\Dispatcher::hasInstance() ) ? mb_ucfirst( \IPS\Dispatcher::i()->controllerLocation ) : 'Front';
|
||||
$location = ( Dispatcher::hasInstance() ) ? IPS::mb_ucfirst( Dispatcher::i()->controllerLocation ) : 'Front';
|
||||
$classname = 'IPS\Session\\' . $location;
|
||||
}
|
||||
else
|
||||
{
|
||||
throw new \RuntimeException('LOCATION_UNKNOWN');
|
||||
throw new RuntimeException('LOCATION_UNKNOWN');
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$location = \substr( $classname, 12 );
|
||||
$location = substr( $classname, 12 );
|
||||
}
|
||||
|
||||
if ( class_exists( $classname ) )
|
||||
@@ -75,7 +92,7 @@ abstract class _Session
|
||||
session_cache_limiter('');
|
||||
|
||||
/* Name the session */
|
||||
$name = session_name( ( \IPS\COOKIE_PREFIX !== NULL ) ? \IPS\COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
|
||||
$name = session_name( ( COOKIE_PREFIX !== NULL ) ? COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
|
||||
|
||||
/* Set the handler */
|
||||
session_write_close();
|
||||
@@ -84,9 +101,9 @@ abstract class _Session
|
||||
/* Make sure we use HTTP-Only cookies */
|
||||
session_set_cookie_params(
|
||||
'0',
|
||||
( \IPS\COOKIE_PATH !== NULL ) ? \IPS\COOKIE_PATH : '/',
|
||||
( \IPS\COOKIE_DOMAIN !== NULL ) ? \IPS\COOKIE_DOMAIN : '',
|
||||
( \IPS\COOKIE_BYPASS_SSLONLY !== TRUE ) ? ( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
( COOKIE_PATH !== NULL ) ? COOKIE_PATH : '/',
|
||||
( COOKIE_DOMAIN !== NULL ) ? COOKIE_DOMAIN : '',
|
||||
( !COOKIE_BYPASS_SSLONLY ) ? ( mb_substr( Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
TRUE
|
||||
);
|
||||
|
||||
@@ -101,12 +118,12 @@ abstract class _Session
|
||||
}
|
||||
else
|
||||
{
|
||||
static::$instance = new \StdClass;
|
||||
static::$instance->member = new \IPS\Member;
|
||||
static::$instance = new StdClass;
|
||||
static::$instance->member = new Member;
|
||||
static::$instance->csrfKey = '';
|
||||
|
||||
/* Upgrader starts session already */
|
||||
if ( !\IPS\Dispatcher::hasInstance() or !\IPS\Dispatcher::i() instanceof \IPS\Dispatcher\Setup )
|
||||
if ( !Dispatcher::hasInstance() or !Dispatcher::i() instanceof Setup )
|
||||
{
|
||||
if( session_status() !== PHP_SESSION_ACTIVE )
|
||||
{
|
||||
@@ -122,30 +139,30 @@ abstract class _Session
|
||||
/**
|
||||
* @brief Session ID
|
||||
*/
|
||||
public $id = NULL;
|
||||
public ?string $id = NULL;
|
||||
|
||||
/**
|
||||
* @brief Currently logged in member
|
||||
*/
|
||||
public $member = NULL;
|
||||
public ?Member $member = NULL;
|
||||
|
||||
/**
|
||||
* @brief CSRF Key
|
||||
*/
|
||||
public $csrfKey = '';
|
||||
public string $csrfKey = '';
|
||||
|
||||
/**
|
||||
* @brief Validation Error
|
||||
*/
|
||||
public $error = NULL;
|
||||
public ?string $error = NULL;
|
||||
|
||||
/**
|
||||
* Set Session Member
|
||||
*
|
||||
* @param \IPS\Member $member Member object
|
||||
* @param Member $member Member object
|
||||
* @return void
|
||||
*/
|
||||
public function setMember( $member )
|
||||
public function setMember( Member $member ) : void
|
||||
{
|
||||
/* PHP 7.0.2 had a bug reported where session_regenerate_id() does not close opened sessions properly and in some situations can cause PHP to hang or crash.
|
||||
* This issue is fixed in PHP 7.1.0 - https://bugs.php.net/bug.php?id=71394 */
|
||||
@@ -166,7 +183,7 @@ abstract class _Session
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function init()
|
||||
public function init() : void
|
||||
{
|
||||
/* Set ID */
|
||||
$this->id = session_id();
|
||||
@@ -180,7 +197,7 @@ abstract class _Session
|
||||
$save = FALSE;
|
||||
|
||||
/* Set the last activity (but not if this is an ajax request or a partially registered member as we delete where last_visit=0) */
|
||||
if ( isset( $this->data ) and ! \IPS\Request::i()->isAjax() and ( $this->member->email and $this->member->name ) )
|
||||
if ( isset( $this->data ) and ! Request::i()->isAjax() and ( $this->member->email and $this->member->name ) )
|
||||
{
|
||||
if ( time() - $this->member->last_activity > 3600 or !$this->member->last_visit )
|
||||
{
|
||||
@@ -195,10 +212,10 @@ abstract class _Session
|
||||
}
|
||||
|
||||
/* Set timezone */
|
||||
if ( isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and \in_array( \IPS\DateTime::getFixedTimezone( \IPS\Request::i()->cookie['ipsTimezone'] ), \DateTimeZone::listIdentifiers() ) )
|
||||
if ( isset( Request::i()->cookie['ipsTimezone'] ) and Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and in_array( DateTime::getFixedTimezone( Request::i()->cookie['ipsTimezone'] ), DateTimeZone::listIdentifiers() ) )
|
||||
{
|
||||
$save = TRUE;
|
||||
$this->member->timezone = \IPS\DateTime::getFixedTimezone( \IPS\Request::i()->cookie['ipsTimezone'] );
|
||||
$this->member->timezone = DateTime::getFixedTimezone( Request::i()->cookie['ipsTimezone'] );
|
||||
}
|
||||
|
||||
/* Save */
|
||||
@@ -210,9 +227,9 @@ abstract class _Session
|
||||
else
|
||||
{
|
||||
/* Ensure any loggedIn cookies are removed */
|
||||
if( isset( \IPS\Request::i()->cookie['loggedIn'] ) )
|
||||
if( isset( Request::i()->cookie['loggedIn'] ) )
|
||||
{
|
||||
\IPS\Request::i()->setCookie( 'loggedIn', NULL );
|
||||
Request::i()->setCookie( 'loggedIn', NULL );
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -222,7 +239,7 @@ abstract class _Session
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function noUpdate()
|
||||
public function noUpdate() : void
|
||||
{
|
||||
/* Overridden methods do something (or not) */
|
||||
}
|
||||
@@ -232,52 +249,53 @@ abstract class _Session
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function csrfCheck()
|
||||
public function csrfCheck() : void
|
||||
{
|
||||
$token = (string) \IPS\Request::i()->csrfKey;
|
||||
$token = (string) Request::i()->csrfKey;
|
||||
|
||||
/* Guests may provide the csrf token via a header */
|
||||
if ( !\IPS\Member::loggedIn()->member_id && isset( $_SERVER['HTTP_X_CSRF_TOKEN'] ) )
|
||||
if ( !Member::loggedIn()->member_id && isset( $_SERVER['HTTP_X_CSRF_TOKEN'] ) )
|
||||
{
|
||||
$token = $_SERVER['HTTP_X_CSRF_TOKEN'];
|
||||
}
|
||||
|
||||
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, $token ) )
|
||||
if ( !Login::compareHashes( $this->csrfKey, $token ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
|
||||
Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Moderator Log
|
||||
* @code
|
||||
\IPS\Session::i()->modLog( 'modlog__spammer_flagged', array( $this->name => FALSE ) );
|
||||
* \IPS\Session::i()->modLog( 'modlog__spammer_flagged', array( $this->name => FALSE ) );
|
||||
* @endcode
|
||||
* @param string $langKey Language key for log
|
||||
* @param string $langKey Language key for log
|
||||
* @param array $params Key/Values - keys are variables to use in sprintf on $langKey, values are booleans indicating if they are language keys themselves (TRUE) or raw data (FALSE)
|
||||
* @param \IPS\Content\Item|NULL $item If moderation action is specific to an item
|
||||
* @param Item|null $item If moderation action is specific to an item
|
||||
* @return void
|
||||
*/
|
||||
public function modLog( $langKey, $params=array(), $item=null )
|
||||
public function modLog( string $langKey, array $params=array(), Item $item=null ) : void
|
||||
{
|
||||
$class = NULL;
|
||||
|
||||
if ( $item instanceof \IPS\Content\Item )
|
||||
if ( $item instanceof Item )
|
||||
{
|
||||
$class = \get_class( $item );
|
||||
/* @var Item $class */
|
||||
$class = get_class( $item );
|
||||
$idColumn = $class::$databaseColumnId;
|
||||
}
|
||||
|
||||
\IPS\Db::i()->insert( 'core_moderator_logs', array(
|
||||
'member_id' => \IPS\Member::loggedIn()->member_id,
|
||||
'member_name' => \IPS\Member::loggedIn()->name,
|
||||
Db::i()->insert( 'core_moderator_logs', array(
|
||||
'member_id' => Member::loggedIn()->member_id,
|
||||
'member_name' => Member::loggedIn()->name,
|
||||
'ctime' => time(),
|
||||
'note' => json_encode( $params ),
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
'appcomponent' => \IPS\Dispatcher::i()->application->directory,
|
||||
'module' => \IPS\Dispatcher::i()->module->key,
|
||||
'controller' => \IPS\Dispatcher::i()->controller,
|
||||
'do' => \IPS\Request::i()->do,
|
||||
'ip_address' => Request::i()->ipAddress(),
|
||||
'appcomponent' => Dispatcher::i()->application->directory,
|
||||
'module' => Dispatcher::i()->module->key,
|
||||
'controller' => Dispatcher::i()->controller,
|
||||
'do' => Request::i()->do,
|
||||
'lang_key' => $langKey,
|
||||
'class' => $class,
|
||||
'item_id' => $item ? $item->$idColumn : NULL,
|
||||
@@ -289,9 +307,9 @@ abstract class _Session
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function regenerateCsrfKey()
|
||||
public function regenerateCsrfKey() : void
|
||||
{
|
||||
$this->csrfKey = md5( \IPS\SUITE_UNIQUE_KEY . "&{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
|
||||
$this->csrfKey = md5( SUITE_UNIQUE_KEY . "&{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -299,11 +317,11 @@ abstract class _Session
|
||||
*
|
||||
* @return int
|
||||
*/
|
||||
public static function sessionLifetime()
|
||||
public static function sessionLifetime(): int
|
||||
{
|
||||
$timeout = 1440;
|
||||
|
||||
if( \function_exists('ini_get') )
|
||||
if( function_exists('ini_get') )
|
||||
{
|
||||
$phpTimeout = @ini_get('session.gc_maxlifetime');
|
||||
$timeout = $phpTimeout ?: $timeout;
|
||||
@@ -311,4 +329,44 @@ abstract class _Session
|
||||
|
||||
return $timeout;
|
||||
}
|
||||
|
||||
/**
|
||||
* Admin Log
|
||||
*
|
||||
* @code
|
||||
\IPS\Session::i()->log( 'acplog__enhancements_enable', array( 'enhancements__foo' => TRUE ) );
|
||||
* @endcode
|
||||
* @param string $langKey Language key for log
|
||||
* @param array $params Key/Values - keys are variables to use in sprintf on $langKey, values are booleans indicating if they are language keys themselves (TRUE) or raw data (FALSE)
|
||||
* @param bool $noDupes If TRUE, will check the last log and not log again if it's the same and less than an hour ago
|
||||
* @return void
|
||||
*/
|
||||
public function log( string $langKey, array $params=array(), bool $noDupes=FALSE ) : void
|
||||
{
|
||||
if ( $noDupes )
|
||||
{
|
||||
try
|
||||
{
|
||||
$lastLog = Db::i()->select( '*', 'core_admin_logs', array( 'member_id=?', $this->member->member_id ), 'ctime DESC', 1 )->first();
|
||||
if ( $lastLog['ctime'] > ( time() - 3600 ) and $lastLog['lang_key'] == $langKey )
|
||||
{
|
||||
return;
|
||||
}
|
||||
}
|
||||
catch ( UnderflowException $e ) { }
|
||||
}
|
||||
|
||||
Db::i()->insert( 'core_admin_logs', array(
|
||||
'member_id' => $this->member->member_id,
|
||||
'member_name' => Member::loggedIn()->name,
|
||||
'ctime' => time(),
|
||||
'note' => json_encode( $params ),
|
||||
'ip_address' => Request::i()->ipAddress(),
|
||||
'appcomponent' => Dispatcher::i()->application->directory,
|
||||
'module' => Dispatcher::i()->module->key,
|
||||
'controller' => Dispatcher::i()->controller,
|
||||
'do' => Request::i()->do,
|
||||
'lang_key' => $langKey
|
||||
) );
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user