Version 4.3.6

This commit is contained in:
Neo committed 2025-12-19 05:49:12 -08:00
1 parent fe1acf984a
commit 1a0c7fd3c2
609 files changed
+14707 -5726

No files matched your search

+11 -7
View File
@@ -210,7 +210,7 @@ class oAuthServerAuthorizationRequest
if ( $this->responseType === 'token' )
{
return $this->redirectUri->setFragment( http_build_query( $response ) );
return $this->redirectUri->setFragment( http_build_query( $response, '', '&' ) );
}
else
{
@@ -280,9 +280,12 @@ class oAuthServerAuthorizationRequest
used on the community (tracking or advertisements, for example) will have access to it - this also makes the URI
a bit cleaner */
if ( isset( \IPS\Request::i()->client_id ) )
{
{
$key = md5( uniqid() );
\IPS\Request::i()->setCookie( 'oauth_authorize', $key );
\IPS\Db::i()->insert( 'core_oauth_authorize_prompts', array(
'session_id' => \IPS\Session::i()->id,
'session_id' => $key,
'client_id' => $this->client->client_id,
'response_type' => $this->responseType,
'redirect_uri' => $this->providedRedirectUri ?: NULL,
@@ -317,7 +320,7 @@ class oAuthServerAuthorizationRequest
{
if ( $success = $login->authenticate() )
{
\IPS\Db::i()->update( 'core_oauth_authorize_prompts', array( 'logged_in' => TRUE ), array( 'session_id=?', \IPS\Session::i()->id ) );
\IPS\Db::i()->update( 'core_oauth_authorize_prompts', array( 'logged_in' => TRUE ), array( 'session_id=?', \IPS\Request::i()->cookie['oauth_authorize'] ) );
if ( $success->mfa() )
{
@@ -380,7 +383,7 @@ try
{
try
{
$row = \IPS\Db::i()->select( '*', 'core_oauth_authorize_prompts', array( 'session_id=?', \IPS\Session::i()->id ) )->first();
$row = \IPS\Db::i()->select( '*', 'core_oauth_authorize_prompts', array( 'session_id=?', \IPS\Request::i()->cookie['oauth_authorize'] ) )->first();
$clientId = $row['client_id'];
$responseType = $row['response_type'];
$redirectUri = $row['redirect_uri'];
@@ -432,12 +435,13 @@ try
}
/* Still here? Go ahead */
\IPS\Db::i()->delete( 'core_oauth_authorize_prompts', array( 'session_id=?', \IPS\Session::i()->id ) );
\IPS\Db::i()->delete( 'core_oauth_authorize_prompts', array( 'session_id=?', \IPS\Request::i()->cookie['oauth_authorize'] ) );
\IPS\Request::i()->setCookie( 'oauth_authorize', NULL );
\IPS\Output::i()->redirect( $request->authorized( \IPS\Member::loggedIn(), isset( \IPS\Request::i()->grantedScope ) ? array_keys( \IPS\Request::i()->grantedScope ) : array() ), NULL, 302 );
}
catch ( \IPS\Login\Handler\OAuth2\InitException $e )
{
\IPS\Output::i()->error( $e->getMessage(), '3S361/1', 403 );
\IPS\Output::i()->error( $e->getMessage(), '2S361/2', 403 );
}
catch ( \IPS\Login\Handler\OAuth2\Exception $e )
{