Version 4.3.6

This commit is contained in:
Neo committed 2025-12-19 05:49:12 -08:00
1 parent fe1acf984a
commit 1a0c7fd3c2
609 files changed
+14707 -5726

No files matched your search

@@ -31,7 +31,7 @@ class _settings extends \IPS\Dispatcher\Controller
public function execute()
{
/* Only logged in members */
if ( !\IPS\Member::loggedIn()->member_id )
if ( !\IPS\Member::loggedIn()->member_id and !in_array( \IPS\Request::i()->do, array( 'mfarecovery', 'mfarecoveryvalidate' ) ) )
{
\IPS\Output::i()->error( 'no_module_permission_guest', '2C122/1', 403, '' );
}
@@ -184,6 +184,11 @@ class _settings extends \IPS\Dispatcher\Controller
{
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_email_changes_target ) );
}
if( \IPS\Settings::i()->allow_email_changes != 'normal' )
{
\IPS\Output::i()->error( 'no_module_permission', '2C122/U', 403, '' );
}
if( \IPS\Member::loggedIn()->isAdmin() )
{
@@ -324,6 +329,11 @@ class _settings extends \IPS\Dispatcher\Controller
{
\IPS\Output::i()->redirect( \IPS\Http\Url::external( \IPS\Settings::i()->allow_password_changes_target ) );
}
if( \IPS\Settings::i()->allow_password_changes != 'normal' )
{
\IPS\Output::i()->error( 'no_module_permission', '2C122/T', 403, '' );
}
if( \IPS\Member::loggedIn()->isAdmin() )
{
@@ -761,7 +771,7 @@ class _settings extends \IPS\Dispatcher\Controller
try
{
$ref = \IPS\Http\Url::createFromString( base64_decode( \IPS\Request::i()->ref ) );
if ( !( $ref instanceof \IPS\Http\Url\Internal ) )
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->openRedirect() )
{
$ref = NULL;
}
@@ -889,7 +899,7 @@ class _settings extends \IPS\Dispatcher\Controller
{
\IPS\Output::i()->error( 'mfa_recovery_no_validation_key', '2C122/K', 410, '' );
}
/* Remove all MFA */
$member = \IPS\Member::load( $record['member_id'] );
foreach ( \IPS\MFA\MFAHandler::handlers() as $key => $handler )
@@ -902,6 +912,12 @@ class _settings extends \IPS\Dispatcher\Controller
/* Delete validating record */
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND forgot_security=1', $member->member_id ) );
/* Log in if necessary */
if ( !\IPS\Member::loggedIn()->member_id and isset( $_SESSION['processing2FA'] ) )
{
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'] ) )->process();
}
/* Redirect */
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' ) );
}
@@ -1117,6 +1133,17 @@ class _settings extends \IPS\Dispatcher\Controller
\IPS\Output::i()->parseFileObjectUrls( $src );
$imageProperties = @getimagesize( $src );
/* getimagesize failed so let's try to use getimagesizefromstring */
if( !$imageProperties )
{
try
{
$image = \IPS\Http\Url::external( $src )->request()->get();
$imageProperties = getimagesizefromstring( $image->content );
}
catch ( \IPS\Http\Request\Exception $e ) {}
}
}
else
{
@@ -1600,7 +1627,7 @@ class _settings extends \IPS\Dispatcher\Controller
try
{
$ref = \IPS\Http\Url::createFromString( $ref );
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
{
throw new \Exception;
}