Version 4.3.6
This commit is contained in:
1 parent
fe1acf984a
commit
1a0c7fd3c2
609 files changed
+14707
-5726
No files matched your search
@@ -31,7 +31,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
public function execute()
|
||||
{
|
||||
/* Only logged in members */
|
||||
if ( !\IPS\Member::loggedIn()->member_id )
|
||||
if ( !\IPS\Member::loggedIn()->member_id and !in_array( \IPS\Request::i()->do, array( 'mfarecovery', 'mfarecoveryvalidate' ) ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission_guest', '2C122/1', 403, '' );
|
||||
}
|
||||
@@ -184,6 +184,11 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_email_changes_target ) );
|
||||
}
|
||||
|
||||
if( \IPS\Settings::i()->allow_email_changes != 'normal' )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C122/U', 403, '' );
|
||||
}
|
||||
|
||||
if( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
@@ -324,6 +329,11 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_password_changes_target ) );
|
||||
}
|
||||
|
||||
if( \IPS\Settings::i()->allow_password_changes != 'normal' )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C122/T', 403, '' );
|
||||
}
|
||||
|
||||
if( \IPS\Member::loggedIn()->isAdmin() )
|
||||
{
|
||||
@@ -761,7 +771,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( base64_decode( \IPS\Request::i()->ref ) );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->openRedirect() )
|
||||
{
|
||||
$ref = NULL;
|
||||
}
|
||||
@@ -889,7 +899,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->error( 'mfa_recovery_no_validation_key', '2C122/K', 410, '' );
|
||||
}
|
||||
|
||||
|
||||
/* Remove all MFA */
|
||||
$member = \IPS\Member::load( $record['member_id'] );
|
||||
foreach ( \IPS\MFA\MFAHandler::handlers() as $key => $handler )
|
||||
@@ -902,6 +912,12 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
/* Delete validating record */
|
||||
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND forgot_security=1', $member->member_id ) );
|
||||
|
||||
/* Log in if necessary */
|
||||
if ( !\IPS\Member::loggedIn()->member_id and isset( $_SESSION['processing2FA'] ) )
|
||||
{
|
||||
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'] ) )->process();
|
||||
}
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' ) );
|
||||
}
|
||||
@@ -1117,6 +1133,17 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->parseFileObjectUrls( $src );
|
||||
|
||||
$imageProperties = @getimagesize( $src );
|
||||
|
||||
/* getimagesize failed so let's try to use getimagesizefromstring */
|
||||
if( !$imageProperties )
|
||||
{
|
||||
try
|
||||
{
|
||||
$image = \IPS\Http\Url::external( $src )->request()->get();
|
||||
$imageProperties = getimagesizefromstring( $image->content );
|
||||
}
|
||||
catch ( \IPS\Http\Request\Exception $e ) {}
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -1600,7 +1627,7 @@ class _settings extends \IPS\Dispatcher\Controller
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user