Version 4.3.6
This commit is contained in:
1 parent
fe1acf984a
commit
1a0c7fd3c2
609 files changed
+14707
-5726
No files matched your search
@@ -141,6 +141,10 @@ class _directory extends \IPS\Dispatcher\Controller
|
||||
/* Get All Clubs */
|
||||
$perPage = 24;
|
||||
$page = isset( \IPS\Request::i()->page ) ? intval( \IPS\Request::i()->page ) : 1;
|
||||
if( $page < 1 )
|
||||
{
|
||||
$page = 1;
|
||||
}
|
||||
$allClubs = \IPS\Member\Club::clubs( \IPS\Member::loggedIn(), array( ( $page - 1 ) * $perPage, $perPage ), $sortOption, $mineOnly, $filters, $extraWhere );
|
||||
$pagination = \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->pagination( $baseUrl, ceil( ( is_object( $allClubs ) ? $allClubs->count( TRUE ) : 0 ) / $perPage ), $page, $perPage );
|
||||
|
||||
|
||||
@@ -1516,7 +1516,7 @@ class _view extends \IPS\Helpers\CoverPhoto\Controller
|
||||
|
||||
/* We need to reset the included CSS files because by this point the responsive files are already in the output CSS array */
|
||||
\IPS\Output::i()->cssFiles = array();
|
||||
\IPS\Theme::i()->settings = array_merge( \IPS\Theme::i()->settings, array( 'responsive' => FALSE ) );
|
||||
\IPS\Output::i()->responsive = FALSE;
|
||||
\IPS\Dispatcher\Front::baseCss();
|
||||
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, $embedCss );
|
||||
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'styles/embeds.css', 'core', 'front' ) );
|
||||
|
||||
@@ -400,10 +400,11 @@ class _popular extends \IPS\Dispatcher\Controller
|
||||
|
||||
foreach( $classes as $class => $ids )
|
||||
{
|
||||
$or[] = \IPS\Content\Search\ContentFilter::init( $class )->onlyInIds( $ids );
|
||||
$or[] = \IPS\Content\Search\ContentFilter::initWithSpecificClass( $class )->onlyInIds( $ids );
|
||||
}
|
||||
|
||||
/* Query and manually sort */
|
||||
$sorted = array();
|
||||
$array = \IPS\Content\Search\Query::init()->filterByContent( $or )->search()->getArrayCopy();
|
||||
foreach( $array as $index => $data )
|
||||
{
|
||||
|
||||
@@ -205,7 +205,7 @@ class _streams extends \IPS\Dispatcher\Controller
|
||||
if ( $field == 'custom_members' and isset( \IPS\Request::i()->stream_custom_members ) )
|
||||
{
|
||||
$members = NULL;
|
||||
foreach( explode( ',', \IPS\Request::i()->stream_custom_members ) as $name )
|
||||
foreach( str_replace( "\r", '', explode( "\n", \IPS\Request::i()->stream_custom_members ) ) as $name )
|
||||
{
|
||||
try
|
||||
{
|
||||
@@ -460,7 +460,6 @@ class _streams extends \IPS\Dispatcher\Controller
|
||||
|
||||
$stream = new \IPS\core\Stream;
|
||||
$stream->member = \IPS\Member::loggedIn()->member_id;
|
||||
$stream->default_view = 'expanded';
|
||||
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'create_new_stream' );
|
||||
\IPS\Output::i()->output = $this->_buildForm( $stream );
|
||||
@@ -687,8 +686,11 @@ class _streams extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$form->hiddenValues['__stream_owner'] = $stream->member;
|
||||
}
|
||||
|
||||
$form->hiddenValues['stream_default_view'] = $stream->default_view;
|
||||
|
||||
if ( $stream->default_view )
|
||||
{
|
||||
$form->hiddenValues['stream_default_view'] = $stream->default_view;
|
||||
}
|
||||
|
||||
/* Handle submissions */
|
||||
if ( $values = $form->values() )
|
||||
|
||||
@@ -345,25 +345,7 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
);
|
||||
|
||||
/* Get visitor data */
|
||||
$visitors = array();
|
||||
$visitorInfo = json_decode( $this->member->pp_last_visitors, TRUE );
|
||||
if ( is_array( $visitorInfo ) and $this->member->members_bitoptions['pp_setting_count_visitors'] )
|
||||
{
|
||||
$visitorData = array();
|
||||
foreach( new \IPS\Patterns\ActiveRecordIterator( \IPS\Db::i()->select( '*', 'core_members', array( \IPS\Db::i()->in( 'member_id', array_keys( array_reverse( $visitorInfo, TRUE ) ) ) ) ), 'IPS\Member' ) AS $row )
|
||||
{
|
||||
$visitorData[$row->member_id] = $row;
|
||||
}
|
||||
|
||||
foreach( array_reverse( $visitorInfo, TRUE ) as $id => $time )
|
||||
{
|
||||
if ( isset( $visitorData[$id] ) )
|
||||
{
|
||||
$visitors[$id]['member'] = $visitorData[$id];
|
||||
$visitors[$id]['visit_time'] = $time;
|
||||
}
|
||||
}
|
||||
}
|
||||
$visitors = $this->member->profileVisitors;
|
||||
|
||||
/* Get followers */
|
||||
$followers = $this->member->followers( ( \IPS\Member::loggedIn()->isAdmin() OR \IPS\Member::loggedIn()->member_id === $this->member->member_id ) ? \IPS\Member::FOLLOW_PUBLIC + \IPS\Member::FOLLOW_ANONYMOUS : \IPS\Member::FOLLOW_PUBLIC, array( 'immediate', 'daily', 'weekly' ), NULL, array( 0, 12 ) );
|
||||
@@ -518,10 +500,14 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
/* If we requested a higher page than is allowed, redirect back to last page */
|
||||
$totalResults = $results->count( TRUE );
|
||||
|
||||
if( $totalResults AND ceil( $totalResults / $query->resultsToGet ) < $page )
|
||||
if( ceil( $totalResults / $query->resultsToGet ) < $page )
|
||||
{
|
||||
$highestPage = floor( $totalResults / $query->resultsToGet );
|
||||
\IPS\Output::i()->redirect( \IPS\Request::i()->url()->setQueryString( 'page', $highestPage ?: 1 ), NULL, 303 );
|
||||
|
||||
if ( $highestPage > 0 OR ( $highestPage == 0 AND $page > 1 ) )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Request::i()->url()->setQueryString( 'page', $highestPage ?: 1 ), NULL, 303 );
|
||||
}
|
||||
}
|
||||
|
||||
$pagination = trim( \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->pagination( $this->member->url()->setQueryString( array( 'do' => 'content', 'all_activity' => 1 ) ), ceil( $results->count( TRUE ) / $query->resultsToGet ), $page, $query->resultsToGet ) );
|
||||
@@ -692,6 +678,12 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
{
|
||||
$object = \IPS\Content\Reaction::load( $reaction['reaction'] );
|
||||
|
||||
/* Don't show disabled reactions */
|
||||
if( !$object->enabled )
|
||||
{
|
||||
throw new \UnderflowException;
|
||||
}
|
||||
|
||||
$reactions['given'][] = array( 'count' => $reaction['count'], 'reaction' => $object );
|
||||
}
|
||||
catch( \UnderflowException $e ){}
|
||||
@@ -703,6 +695,12 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
{
|
||||
$object = \IPS\Content\Reaction::load( $reaction['reaction'] );
|
||||
|
||||
/* Don't show disabled reactions */
|
||||
if( !$object->enabled )
|
||||
{
|
||||
throw new \UnderflowException;
|
||||
}
|
||||
|
||||
$reactions['received'][] = array( 'count' => $reaction['count'], 'reaction' => $object );
|
||||
}
|
||||
catch( \UnderflowException $e ){}
|
||||
@@ -738,21 +736,7 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
{
|
||||
$this->member->members_bitoptions['pp_setting_count_visitors'] = TRUE;
|
||||
|
||||
/* Get visitor data */
|
||||
$visitors = array();
|
||||
$visitorInfo = json_decode( $this->member->pp_last_visitors, TRUE );
|
||||
if ( is_array( $visitorInfo ) )
|
||||
{
|
||||
foreach( $visitorInfo as $id => $time )
|
||||
{
|
||||
$visitor = \IPS\Member::load( $id );
|
||||
if ( $visitor->member_id )
|
||||
{
|
||||
$visitors[$id]['member'] = $visitor;
|
||||
$visitors[$id]['visit_time'] = $time;
|
||||
}
|
||||
}
|
||||
}
|
||||
$visitors = $this->member->profileVisitors;
|
||||
}
|
||||
|
||||
$this->member->save();
|
||||
@@ -1218,7 +1202,15 @@ class _profile extends \IPS\Helpers\CoverPhoto\Controller
|
||||
$form->add( new \IPS\Helpers\Form\Url( 'member_photo_url', NULL, FALSE, array( 'file' => 'core_Profile', 'image' => TRUE, 'maxFileSize' => $photoVars[0] ? $photoVars[0] / 1024 : NULL, 'maxDimensions' => array( 'width' => $photoVars[1], 'height' => $photoVars[2] ) ), function( $val ) {
|
||||
if ( $val instanceof \IPS\Http\Url )
|
||||
{
|
||||
$image = \IPS\Image::create( (string) $val->request()->get() );
|
||||
try
|
||||
{
|
||||
$image = \IPS\Image::create( (string) $val->request()->get() );
|
||||
}
|
||||
catch ( \InvalidArgumentException $e )
|
||||
{
|
||||
throw new \DomainException('member_photo_bad_url');
|
||||
}
|
||||
|
||||
if( $image->isAnimatedGif and !$this->member->group['g_upload_animated_photos'] )
|
||||
{
|
||||
throw new \DomainException('member_photo_upload_no_animated');
|
||||
|
||||
@@ -154,7 +154,7 @@ class _messenger extends \IPS\Content\Controller
|
||||
$row['last_message'] = \IPS\core\Messenger\Conversation::load( $row['mt_id'] )->comments( 1, 0, 'date', 'desc' );
|
||||
$row['participants'] = \IPS\core\Messenger\Conversation::load( $row['mt_id'] )->participantBlurb();
|
||||
|
||||
\IPS\Output::i()->json( \IPS\Theme::i()->getTemplate( 'messaging' )->messageListRow( $row, FALSE, $folders ) );
|
||||
\IPS\Output::i()->json( \IPS\Theme::i()->getTemplate( 'messaging' )->messageListRow( $row, \IPS\Request::i()->_fromMenu ? FALSE : TRUE, $folders ) );
|
||||
}
|
||||
|
||||
\IPS\Output::i()->title = $conversation->title;
|
||||
@@ -743,7 +743,7 @@ class _messenger extends \IPS\Content\Controller
|
||||
/* Authorize each of the members */
|
||||
foreach ( $members as $member )
|
||||
{
|
||||
if ( array_key_exists( $member->member_id, $maps ) and !$maps[$member->member_id]['map_user_active'] and !\IPS\Request::i()->unblock )
|
||||
if ( array_key_exists( $member->member_id, $maps ) and !$maps[ $member->member_id ]['map_user_active'] AND !$maps[ $member->member_id ]['map_user_banned'] )
|
||||
{
|
||||
throw new \InvalidArgumentException( \IPS\Member::loggedIn()->language()->addToStack('messenger_member_left', FALSE, array( 'sprintf' => array( $member->name ) ) ) );
|
||||
}
|
||||
|
||||
@@ -77,12 +77,6 @@ class _online extends \IPS\Dispatcher\Controller
|
||||
|
||||
foreach ( \IPS\Member\Group::groups( TRUE, TRUE, TRUE ) as $group )
|
||||
{
|
||||
/* Hiding from online list? */
|
||||
if( $group->g_hide_online_list )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* Alias the lang keys */
|
||||
$realLangKey = "core_group_{$group->g_id}";
|
||||
$fakeLangKey = "online_users_group_{$group->g_id}";
|
||||
|
||||
@@ -318,7 +318,7 @@ class _promote extends \IPS\Dispatcher\Controller
|
||||
|
||||
try
|
||||
{
|
||||
if( !$class OR !class_exists( $class ) )
|
||||
if( !$class OR !class_exists( $class ) OR !is_subclass_of( $class, 'IPS\Content' ) )
|
||||
{
|
||||
throw new \InvalidArgumentException;
|
||||
}
|
||||
|
||||
@@ -470,9 +470,18 @@ class _search extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$beforeKey = "{$k}_before";
|
||||
$afterKey = "{$k}_after";
|
||||
if ( isset( \IPS\Request::i()->$beforeKey ) or isset( \IPS\Request::i()->$afterKey ) )
|
||||
|
||||
if ( isset( \IPS\Request::i()->$beforeKey ) and \IPS\Request::i()->$beforeKey != 'any' and isset( \IPS\Request::i()->$afterKey ) and \IPS\Request::i()->$afterKey != 'any' )
|
||||
{
|
||||
foreach ( array( 'before', 'after' ) as $l )
|
||||
$after = \IPS\DateTime::ts( \IPS\Request::i()->$afterKey );
|
||||
$before = \IPS\DateTime::ts( \IPS\Request::i()->$beforeKey );
|
||||
$titleConditions[] = \IPS\Member::loggedIn()->language()->addToStack( "search_blurb_date_$k", FALSE, array( 'sprintf' => array( \IPS\Member::loggedIn()->language()->addToStack( "search_blurb_date_between", FALSE, array( 'sprintf' => array( $after->localeDate(), $before->localeDate() ) ) ) ) ) );
|
||||
|
||||
$query->$method( $after, $before );
|
||||
}
|
||||
elseif ( isset( \IPS\Request::i()->$beforeKey ) or isset( \IPS\Request::i()->$afterKey ) )
|
||||
{
|
||||
foreach ( array( 'after', 'before' ) as $l )
|
||||
{
|
||||
$$l = NULL;
|
||||
$key = "{$l}Key";
|
||||
@@ -660,7 +669,7 @@ class _search extends \IPS\Dispatcher\Controller
|
||||
|
||||
\IPS\Output::i()->httpHeaders += $httpHeaders;
|
||||
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('search_results_title');
|
||||
\IPS\Output::i()->title = $title;
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'search' )->search( $this->_splitTermsForDisplay(), $title, $results, $pagination, $baseUrl, $types, $this->_form()->customTemplate( array( \IPS\Theme::i()->getTemplate( 'search' ), 'filters' ), $baseUrl, $count ), $count );
|
||||
}
|
||||
}
|
||||
@@ -1104,12 +1113,13 @@ class _search extends \IPS\Dispatcher\Controller
|
||||
/**
|
||||
* Get the different content type extensions
|
||||
*
|
||||
* @param bool|\IPS\Member $member Check member access
|
||||
* @return array
|
||||
*/
|
||||
public static function contentTypes()
|
||||
public static function contentTypes( $member = TRUE )
|
||||
{
|
||||
$types = array();
|
||||
foreach ( \IPS\Content::routedClasses( TRUE, FALSE, TRUE ) as $class )
|
||||
foreach ( \IPS\Content::routedClasses( $member, FALSE, TRUE ) as $class )
|
||||
{
|
||||
if( is_subclass_of( $class, 'IPS\Content\Searchable' ) and $class::includeInSiteSearch() )
|
||||
{
|
||||
|
||||
@@ -96,23 +96,15 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
/* Check if it exists */
|
||||
else
|
||||
else if ( $error = \IPS\Login::usernameIsInUse( $name ) )
|
||||
{
|
||||
foreach ( \IPS\Login::handlers( TRUE ) as $k => $handler )
|
||||
if ( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
if ( $handler->usernameIsInUse( $name ) === TRUE )
|
||||
{
|
||||
if ( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_name_exists_admin', FALSE, array( 'sprintf' => array( $k ) ) ) );
|
||||
break;
|
||||
}
|
||||
else
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_name_exists') );
|
||||
break;
|
||||
}
|
||||
}
|
||||
$result = array( 'result' => 'fail', 'message' => $error );
|
||||
}
|
||||
else
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_name_exists') );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -155,21 +147,15 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
/* Check if it exists */
|
||||
else
|
||||
else if ( $error = \IPS\Login::emailIsInUse( $email ) )
|
||||
{
|
||||
foreach ( \IPS\Login::handlers( TRUE ) as $k => $handler )
|
||||
if ( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
if ( $handler->emailIsInUse( $email ) === TRUE )
|
||||
{
|
||||
if ( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_email_exists_admin', FALSE, array( 'sprintf' => array( $k ) ) ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_email_exists') );
|
||||
}
|
||||
}
|
||||
$result = array( 'result' => 'fail', 'message' => $error );
|
||||
}
|
||||
else
|
||||
{
|
||||
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_email_exists') );
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -50,6 +50,14 @@ class _announcement extends \IPS\Content\Controller
|
||||
{
|
||||
\IPS\Output::i()->error( 'node_error_no_perm', '2C199/2', 403, '' );
|
||||
}
|
||||
|
||||
/* if the site is offline, use the minimal layout */
|
||||
if ( ( !\IPS\Settings::i()->site_online and !\IPS\Member::loggedIn()->group['g_access_offline'] ) OR ( !\IPS\Member::loggedIn()->member_id AND !\IPS\Member::loggedIn()->group['g_view_board'] ) )
|
||||
{
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->allowDefaultWidgets = FALSE;
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
}
|
||||
|
||||
/* Set Session Location */
|
||||
\IPS\Session::i()->setLocation( \IPS\Http\Url::internal( 'app=core&module=system&controller=announcement&id=' . $announcement->id, NULL, 'announcement', $announcement->seo_title ), array(), 'loc_viewing_announcement', array( $announcement->title => FALSE ) );
|
||||
|
||||
@@ -110,8 +110,22 @@ class _editor extends \IPS\Dispatcher\Controller
|
||||
$url = \IPS\Http\Url::createFromString( \IPS\Request::i()->url, TRUE, TRUE );
|
||||
$embed = NULL;
|
||||
$error = NULL;
|
||||
|
||||
if ( !\IPS\Request::i()->noEmbed )
|
||||
$noEmbed = \IPS\Request::i()->noEmbed;
|
||||
|
||||
if ( ! empty( \IPS\Request::i()->embedLocalOnly ) )
|
||||
{
|
||||
$srcDomain = parse_url( \IPS\Settings::i()->base_url, PHP_URL_HOST );
|
||||
$lclDomain = parse_url( $url, PHP_URL_HOST );
|
||||
|
||||
/* This is via the ACP, so we will only allow internal embeds */
|
||||
if ( $srcDomain != $lclDomain )
|
||||
{
|
||||
$noEmbed = FALSE;
|
||||
$error = \IPS\Member::loggedIn()->language()->addToStack( 'embed__fail_cant_acp' );
|
||||
}
|
||||
}
|
||||
|
||||
if ( ! $noEmbed )
|
||||
{
|
||||
try
|
||||
{
|
||||
@@ -145,7 +159,11 @@ class _editor extends \IPS\Dispatcher\Controller
|
||||
break;
|
||||
}
|
||||
}
|
||||
catch ( \Exception $e ){ }
|
||||
catch ( \Exception $e )
|
||||
{
|
||||
/* Log it if debug logging is enabled so we can see what happened. Maybe save another dev fifteen minutes of "why isn't this working" */
|
||||
\IPS\Log::debug( $e, 'embed_fail' );
|
||||
}
|
||||
}
|
||||
|
||||
if ( $embed OR $error )
|
||||
@@ -184,7 +202,7 @@ class _editor extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function emoji()
|
||||
{
|
||||
$emoji = ( \IPS\Settings::i()->emoji_style == 'disabled' or !\IPS\Settings::i()->getFromConfGlobal('sql_utf8mb4') ) ? array() : json_decode( file_get_contents( \IPS\ROOT_PATH . '/applications/core/data/emoji.json' ), TRUE );
|
||||
$emoji = ( \IPS\Settings::i()->emoji_style == 'disabled' or \IPS\Settings::i()->getFromConfGlobal('sql_utf8mb4') !== TRUE ) ? array() : json_decode( file_get_contents( \IPS\ROOT_PATH . '/applications/core/data/emoji.json' ), TRUE );
|
||||
|
||||
foreach ( \IPS\Db::i()->select( '*', 'core_emoticons', NULL, 'emo_set_position,emo_position' ) as $row )
|
||||
{
|
||||
|
||||
@@ -0,0 +1,100 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Facebook Authentication
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 09 August 2018
|
||||
*/
|
||||
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Facebook auth for ACP
|
||||
*/
|
||||
class _facebook extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* View Announcement
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function manage()
|
||||
{
|
||||
if ( ! \IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' )->setQueryString( 'ref', base64_encode( \IPS\Http\Url::internal( 'app=core&module=system&controller=facebook' ) ) ) );
|
||||
}
|
||||
|
||||
$promote = \IPS\core\Promote::getPromoter( 'Facebook' );
|
||||
$facebook = $promote::getLoginHandler();
|
||||
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=facebook' );
|
||||
|
||||
try
|
||||
{
|
||||
/* Get a request token */
|
||||
if ( !isset( \IPS\Request::i()->code ) )
|
||||
{
|
||||
$target = \IPS\Http\Url::external('https://www.facebook.com/dialog/oauth')->setQueryString( array(
|
||||
'client_id' => $facebook->settings['client_id'],
|
||||
'response_type' => 'code',
|
||||
'redirect_uri' => (string) \IPS\Http\Url::internal( 'oauth/callback/', 'none' ),
|
||||
'state' => $facebook->id . '-' . base64_encode( $url ) . '-' . \IPS\Session::i()->csrfKey . '-x',
|
||||
'scope' => 'manage_pages publish_pages publish_to_groups'
|
||||
) );
|
||||
|
||||
\IPS\Output::i()->redirect( $target );
|
||||
}
|
||||
|
||||
/* CSRF Check */
|
||||
if ( \IPS\Request::i()->csrfKey !== \IPS\Session::i()->csrfKey )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Did we get an error? */
|
||||
if ( isset( \IPS\Request::i()->error ) )
|
||||
{
|
||||
if ( \IPS\Request::i()->error === 'access_denied' )
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Log::log( print_r( $_GET, TRUE ), 'oauth' );
|
||||
throw new \IPS\Login\Exception( 'generic_error', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
}
|
||||
|
||||
/* If we have a code, swap it for an access token, otherwise, decode what we have */
|
||||
if ( isset( \IPS\Request::i()->code ) )
|
||||
{
|
||||
$accessToken = $facebook->exchangeMemberToken( \IPS\Request::i()->code );
|
||||
}
|
||||
|
||||
/* Store the settings */
|
||||
$promote->saveSettings( array(
|
||||
'member_token' => $accessToken
|
||||
) );
|
||||
|
||||
/* Show a done page */
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('promote_facebook_sorted');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'promote' )->promoteFacebookComplete();
|
||||
|
||||
}
|
||||
catch ( \Exception $e )
|
||||
{
|
||||
\IPS\Log::log( $e, 'facebook_promote' );
|
||||
|
||||
\IPS\Output::i()->error( 'generic_error', '4C375/1', 403, $e->getMessage() );
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -52,7 +52,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
@@ -200,7 +200,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( base64_decode( \IPS\Request::i()->ref ) );
|
||||
if ( $ref instanceof \IPS\Http\Url\Internal )
|
||||
if ( $ref instanceof \IPS\Http\Url\Internal and !$ref->openRedirect() )
|
||||
{
|
||||
$destination = $ref;
|
||||
}
|
||||
@@ -226,6 +226,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
/* Otherwise show the reauthenticate form */
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->pageCaching = FALSE;
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('login');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->mergeSocialAccount( $handler, $member, $login, $error );
|
||||
}
|
||||
|
||||
@@ -688,7 +688,7 @@ class _notifications extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$class = 'IPS\\Member';
|
||||
}
|
||||
if( \IPS\Request::i()->follow_app == 'core' and \IPS\Request::i()->follow_area == 'club' )
|
||||
elseif( \IPS\Request::i()->follow_app == 'core' and \IPS\Request::i()->follow_area == 'club' )
|
||||
{
|
||||
$class = 'IPS\\Member\Club';
|
||||
}
|
||||
|
||||
@@ -33,7 +33,17 @@ class _privacy extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->error( 'node_error', '2C381/1', 404, 'privacy_set_to_none_acp' );
|
||||
}
|
||||
|
||||
|
||||
$subprocessors = array();
|
||||
/* Work out the main subprocessors that the user has no direct choice over */
|
||||
if ( \IPS\Settings::i()->privacy_show_processors )
|
||||
{
|
||||
foreach( \IPS\Application::enabledApplications() as $app )
|
||||
{
|
||||
$subprocessors = array_merge( $subprocessors, $app->privacyPolicyThirdParties() );
|
||||
}
|
||||
}
|
||||
|
||||
/* Set Session Location */
|
||||
\IPS\Session::i()->setLocation( \IPS\Http\Url::internal( 'app=core&module=system&controller=privacy', NULL, 'privacy' ), array(), 'loc_viewing_privacy_policy' );
|
||||
|
||||
@@ -41,6 +51,6 @@ class _privacy extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('privacy');
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->privacy();
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->privacy( $subprocessors );
|
||||
}
|
||||
}
|
||||
@@ -34,7 +34,7 @@ class _redirect extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/* Construct the URL */
|
||||
$url = \IPS\Http\Url::external( \IPS\Request::i()->url );
|
||||
|
||||
|
||||
/* If it's a resource (image, etc.), we pull the actual contents to prevent the referrer being exposed (which is an issue in the ACP where the session ID is private) */
|
||||
if ( \IPS\Request::i()->resource )
|
||||
{
|
||||
|
||||
@@ -37,7 +37,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
if( \IPS\Request::i()->do !== 'complete'
|
||||
and \IPS\Request::i()->do !== 'changeEmail' and \IPS\Request::i()->do !== 'validate'
|
||||
and \IPS\Request::i()->do !== 'validating' and \IPS\Request::i()->do !== 'reconfirm'
|
||||
and \IPS\Request::i()->do !== 'finish' )
|
||||
and \IPS\Request::i()->do !== 'finish' and \IPS\Request::i()->do !== 'cancel' )
|
||||
{
|
||||
if ( \IPS\Login::registrationType() == 'redirect' )
|
||||
{
|
||||
@@ -165,7 +165,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
/* Handle submissions */
|
||||
if ( $values = $form->values() )
|
||||
{
|
||||
if( !\IPS\Settings::i()->quick_register )
|
||||
if( \IPS\Login::registrationType() == 'full' )
|
||||
{
|
||||
foreach ( \IPS\core\ProfileFields\Field::fields( array(), \IPS\core\ProfileFields\Field::REG ) as $group => $fields )
|
||||
{
|
||||
@@ -224,7 +224,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
@@ -261,6 +261,12 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
public function finish()
|
||||
{
|
||||
/* You must be logged in for this action */
|
||||
if( !\IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C223/B', 403, '' );
|
||||
}
|
||||
|
||||
$steps = \IPS\Member\ProfileStep::loadAll();
|
||||
|
||||
/* Do we need to bother? We should only show this form if there are required items, but will show both required and suggested where possible to allow the user to complete as much of their profile as possible */
|
||||
@@ -416,18 +422,8 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Checkbox( 'reg_admin_mails', \IPS\Settings::i()->updates_consent_default == 'enabled' ? TRUE : FALSE, FALSE ) );
|
||||
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] = sprintf( \IPS\Member::loggedIn()->language()->get("reg_agreed_terms"), \IPS\Http\Url::internal( 'app=core&module=system&controller=terms', 'front', 'terms', array(), \IPS\Http\Url::PROTOCOL_RELATIVE ) );
|
||||
|
||||
/* Build the appropriate links for registration terms & privacy policy */
|
||||
if ( \IPS\Settings::i()->privacy_type == "internal" )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] .= sprintf( \IPS\Member::loggedIn()->language()->get("reg_privacy_link"), \IPS\Http\Url::internal( 'app=core&module=system&controller=privacy', 'front', 'privacy', array(), \IPS\Http\Url::PROTOCOL_RELATIVE ), 'data-ipsDialog data-ipsDialog-size="wide" data-ipsDialog-title="' . \IPS\Member::loggedIn()->language()->get("privacy") . '"' );
|
||||
}
|
||||
else if ( \IPS\Settings::i()->privacy_type == "external" )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] .= sprintf( \IPS\Member::loggedIn()->language()->get("reg_privacy_link"), \IPS\Http\Url::external( \IPS\Settings::i()->privacy_link ), 'target="_blank"' );
|
||||
}
|
||||
|
||||
\IPS\core\modules\front\system\register::buildRegistrationTerm();
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Checkbox( 'reg_agreed_terms', NULL, TRUE, array(), function( $val )
|
||||
{
|
||||
@@ -588,10 +584,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
/* Save custom field values */
|
||||
if ( ! \IPS\Settings::i()->quick_register )
|
||||
{
|
||||
\IPS\Db::i()->replace( 'core_pfields_content', array_merge( array( 'member_id' => $member->member_id ), $profileFields ) );
|
||||
}
|
||||
\IPS\Db::i()->replace( 'core_pfields_content', array_merge( array( 'member_id' => $member->member_id ), $profileFields ) );
|
||||
|
||||
/* Log that we gave consent for admin emails */
|
||||
$member->logHistory( 'core', 'admin_mails', array( 'enabled' => (boolean) $member->allow_admin_mails ) );
|
||||
@@ -770,17 +763,19 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$form->add( new \IPS\Helpers\Form\Email( 'email_address', NULL, TRUE, array( 'accountEmail' => TRUE ) ) );
|
||||
}
|
||||
if ( \IPS\Member::loggedIn()->members_bitoptions['must_reaccept_terms'] )
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Checkbox( 'reg_admin_mails', \IPS\Settings::i()->updates_consent_default == 'enabled' ? TRUE : FALSE, FALSE ) );
|
||||
|
||||
\IPS\core\modules\front\system\register::buildRegistrationTerm();
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\Checkbox( 'reg_agreed_terms', NULL, TRUE, array(), function( $val )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] = sprintf( \IPS\Member::loggedIn()->language()->get("reg_agreed_terms"), \IPS\Http\Url::internal( 'app=core&module=system&controller=terms', 'front', 'terms' ) );
|
||||
$form->add( new \IPS\Helpers\Form\Checkbox( 'reg_agreed_terms', NULL, TRUE, array(), function( $val )
|
||||
if ( !$val )
|
||||
{
|
||||
if ( !$val )
|
||||
{
|
||||
throw new \InvalidArgumentException('reg_not_agreed_terms');
|
||||
}
|
||||
} ) );
|
||||
}
|
||||
throw new \InvalidArgumentException('reg_not_agreed_terms');
|
||||
}
|
||||
} ) );
|
||||
|
||||
$form->addButton( 'cancel', 'link', \IPS\Http\Url::internal( 'app=core&module=system&controller=register&do=cancel', 'front', 'register' )->csrf() );
|
||||
|
||||
/* Handle the submission */
|
||||
@@ -814,9 +809,21 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
}
|
||||
\IPS\Member::loggedIn()->members_bitoptions['must_reaccept_terms'] = FALSE;
|
||||
\IPS\Member::loggedIn()->allow_admin_mails = $values['reg_admin_mails'];
|
||||
|
||||
/* Save */
|
||||
\IPS\Member::loggedIn()->save();
|
||||
/* Log that we gave consent for admin emails */
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'admin_mails', array( 'enabled' => (boolean) \IPS\Member::loggedIn()->allow_admin_mails ) );
|
||||
|
||||
/* Log that we gave consent for terms and privacy */
|
||||
if ( \IPS\Settings::i()->privacy_type != 'none' )
|
||||
{
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'terms_acceptance', array( 'type' => 'privacy' ) );
|
||||
}
|
||||
|
||||
/* Log that the terms were accepted */
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'terms_acceptance', array( 'type' => 'terms' ) );
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'account', array( 'type' => 'complete' ), FALSE );
|
||||
|
||||
/* Handle validation */
|
||||
@@ -831,7 +838,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
@@ -1004,6 +1011,12 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function reconfirm()
|
||||
{
|
||||
/* You must be logged in for this action */
|
||||
if( !\IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C223/C', 403, '' );
|
||||
}
|
||||
|
||||
/* Generate form */
|
||||
$form = new \IPS\Helpers\Form( 'reconfirm_checkbox', 'reconfirm_checkbox' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
@@ -1035,7 +1048,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url\Friendly::createFromString( base64_decode( \IPS\Request::i()->ref ) );
|
||||
if ( $ref instanceof \IPS\Http\Url\Internal )
|
||||
if ( $ref instanceof \IPS\Http\Url\Internal and !$ref->openRedirect() )
|
||||
{
|
||||
\IPS\Output::i()->redirect( $ref );
|
||||
}
|
||||
@@ -1050,4 +1063,24 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('terms_of_use');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate('system')->reconfirmTerms( \IPS\Member::loggedIn()->members_bitoptions['must_reaccept_terms'], \IPS\Member::loggedIn()->members_bitoptions['must_reaccept_privacy'], $form );
|
||||
}
|
||||
|
||||
/**
|
||||
* Builds the reg_agreed_terms language string which takes the privacy type settings into account
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public static function buildRegistrationTerm()
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] = sprintf( \IPS\Member::loggedIn()->language()->get("reg_agreed_terms"), \IPS\Http\Url::internal( 'app=core&module=system&controller=terms', 'front', 'terms' ) );
|
||||
|
||||
/* Build the appropriate links for registration terms & privacy policy */
|
||||
if ( \IPS\Settings::i()->privacy_type == "internal" )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] .= sprintf( \IPS\Member::loggedIn()->language()->get("reg_privacy_link"), \IPS\Http\Url::internal( 'app=core&module=system&controller=privacy', 'front', 'privacy', array(), \IPS\Http\Url::PROTOCOL_RELATIVE ), 'data-ipsDialog data-ipsDialog-size="wide" data-ipsDialog-title="' . \IPS\Member::loggedIn()->language()->get("privacy") . '"' );
|
||||
}
|
||||
else if ( \IPS\Settings::i()->privacy_type == "external" )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words[ "reg_agreed_terms" ] .= sprintf( \IPS\Member::loggedIn()->language()->get("reg_privacy_link"), \IPS\Http\Url::external( \IPS\Settings::i()->privacy_link ), 'target="_blank" rel="noopener"' );
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -31,7 +31,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
public function execute()
|
||||
{
|
||||
/* Only logged in members */
|
||||
if ( !\IPS\Member::loggedIn()->member_id )
|
||||
if ( !\IPS\Member::loggedIn()->member_id and !in_array( \IPS\Request::i()->do, array( 'mfarecovery', 'mfarecoveryvalidate' ) ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission_guest', '2C122/1', 403, '' );
|
||||
}
|
||||
@@ -184,6 +184,11 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_email_changes_target ) );
|
||||
}
|
||||
|
||||
if( \IPS\Settings::i()->allow_email_changes != 'normal' )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C122/U', 403, '' );
|
||||
}
|
||||
|
||||
if( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
@@ -324,6 +329,11 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_password_changes_target ) );
|
||||
}
|
||||
|
||||
if( \IPS\Settings::i()->allow_password_changes != 'normal' )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C122/T', 403, '' );
|
||||
}
|
||||
|
||||
if( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
@@ -761,7 +771,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( base64_decode( \IPS\Request::i()->ref ) );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->openRedirect() )
|
||||
{
|
||||
$ref = NULL;
|
||||
}
|
||||
@@ -889,7 +899,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->error( 'mfa_recovery_no_validation_key', '2C122/K', 410, '' );
|
||||
}
|
||||
|
||||
|
||||
/* Remove all MFA */
|
||||
$member = \IPS\Member::load( $record['member_id'] );
|
||||
foreach ( \IPS\MFA\MFAHandler::handlers() as $key => $handler )
|
||||
@@ -902,6 +912,12 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
/* Delete validating record */
|
||||
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND forgot_security=1', $member->member_id ) );
|
||||
|
||||
/* Log in if necessary */
|
||||
if ( !\IPS\Member::loggedIn()->member_id and isset( $_SESSION['processing2FA'] ) )
|
||||
{
|
||||
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'] ) )->process();
|
||||
}
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' ) );
|
||||
}
|
||||
@@ -1117,6 +1133,17 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->parseFileObjectUrls( $src );
|
||||
|
||||
$imageProperties = @getimagesize( $src );
|
||||
|
||||
/* getimagesize failed so let's try to use getimagesizefromstring */
|
||||
if( !$imageProperties )
|
||||
{
|
||||
try
|
||||
{
|
||||
$image = \IPS\Http\Url::external( $src )->request()->get();
|
||||
$imageProperties = getimagesizefromstring( $image->content );
|
||||
}
|
||||
catch ( \IPS\Http\Request\Exception $e ) {}
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -1600,7 +1627,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
|
||||
@@ -44,6 +44,8 @@ class _terms extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function dismiss()
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
\IPS\Request::i()->setCookie( 'guestTermsDismissed', 1, NULL, FALSE );
|
||||
|
||||
if ( \IPS\Request::i()->isAjax() )
|
||||
@@ -63,7 +65,7 @@ class _terms extends \IPS\Dispatcher\Controller
|
||||
$url = NULL;
|
||||
}
|
||||
|
||||
if ( $url instanceof \IPS\Http\Url\Internal )
|
||||
if ( $url instanceof \IPS\Http\Url\Internal and !$url->openRedirect() )
|
||||
{
|
||||
\IPS\Output::i()->redirect( $url, 'terms_dismissed' );
|
||||
}
|
||||
|
||||
@@ -37,18 +37,19 @@ class _twitter extends \IPS\Dispatcher\Controller
|
||||
$twitter = \IPS\Login\Handler::findMethod('IPS\Login\Handler\Oauth1\Twitter');
|
||||
$promote = \IPS\core\Promote::getPromoter( 'Twitter' );
|
||||
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=twitter' );
|
||||
|
||||
$callback = $twitter->redirectionEndpoint()->setQueryString( 'state', $twitter->id . '-' . base64_encode( $url ) . '-' . \IPS\Session::i()->csrfKey . '-' );
|
||||
|
||||
try
|
||||
{
|
||||
/* Get a request token */
|
||||
if ( !isset( \IPS\Request::i()->oauth_token ) )
|
||||
{
|
||||
$response = $twitter->requestToken( $url->setQueryString( 'csrf', \IPS\Session::i()->csrfKey ) );
|
||||
$response = $twitter->requestToken( (string) $callback );
|
||||
\IPS\Output::i()->redirect( "https://api.twitter.com/oauth/authorize?force_login=1&oauth_token={$response['oauth_token']}" );
|
||||
}
|
||||
|
||||
/* CSRF Check */
|
||||
if ( \IPS\Request::i()->csrf !== \IPS\Session::i()->csrfKey )
|
||||
if ( \IPS\Request::i()->csrfKey !== \IPS\Session::i()->csrfKey )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
@@ -205,7 +205,7 @@ class _warnings extends \IPS\Content\Controller
|
||||
if ( isset( $_SERVER['HTTP_REFERER'] ) )
|
||||
{
|
||||
$url = \IPS\Http\Url\Friendly::createFromString( $_SERVER['HTTP_REFERER'] );
|
||||
if ( $url instanceof \IPS\Http\Url\Internal )
|
||||
if ( $url instanceof \IPS\Http\Url\Internal and !$url->openRedirect() )
|
||||
{
|
||||
\IPS\Output::i()->redirect( $url );
|
||||
return;
|
||||
|
||||
Reference in new issue
Block a user