Version 2.2.0 RC-1

This commit is contained in:
Neo committed 2025-12-19 00:22:37 -08:00
1 parent f73f8bff6d
commit 22f1b963ee
1034 files changed
+178610 -70897

No files matched your search

+206 -110
View File
@@ -1,28 +1,18 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.1.7
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2005 Invision Power Services, Inc.
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Tuesday 18th of July 2006 05:56:00 PM
| Release: 52f408a29988b02f45b5e6f4ba5af0ae
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-02-06 23:08:03 +0000 (Mon, 06 Feb 2006) $
| > $Revision: 140 $
| > $Author: bfarber $
| > $Date: 2006-10-11 13:55:47 +0100 (Wed, 11 Oct 2006) $
| > $Revision: 624 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
| > SESSION CLASS
@@ -34,6 +24,12 @@
+--------------------------------------------------------------------------
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class session
{
# Global
@@ -74,46 +70,44 @@ class session
$this->time_now = time();
$cookie = array();
# TMP:
$this->ipsclass->vars['match_ipaddress'] = 1;
//-----------------------------------------
// Before we go any lets check the load settings..
//-----------------------------------------
if ($this->ipsclass->vars['load_limit'] > 0)
{
# @ supressor fixes warning in >4.3.2 with open_basedir restrictions
if ( @file_exists('/proc/loadavg') )
{
if ( $fh = @fopen( '/proc/loadavg', 'r' ) )
{
$data = @fread( $fh, 6 );
@fclose( $fh );
$load_avg = explode( " ", $data );
$this->ipsclass->server_load = trim($load_avg[0]);
//-----------------------------------------
// Check cache
//-----------------------------------------
if( $this->ipsclass->cache['systemvars']['loadlimit'] )
{
$loadinfo = explode( "-", $this->ipsclass->cache['systemvars']['loadlimit'] );
if ( count($loadinfo) )
{
//-----------------------------------------
// We have cache! $$
//-----------------------------------------
$this->ipsclass->server_load = $loadinfo[0];
if ($this->ipsclass->server_load > $this->ipsclass->vars['load_limit'])
{
$this->ipsclass->Error( array( 'LEVEL' => 1, 'MSG' => 'server_too_busy', 'INIT' => 1 ) );
//---------------------------------------
// Visiting Lo-fi page?
//---------------------------------------
if( defined( 'LOFI_NAME' ) AND constant( 'LOFI_NAME' ) == 'lofiversion' )
{
$this->ipsclass->boink_it( $this->ipsclass->vars['board_url'] );
}
else
{
$this->ipsclass->Error( array( 'LEVEL' => 1, 'MSG' => 'server_too_busy', 'INIT' => 1 ) );
}
}
}
}
else
{
if ( $serverstats = @exec("uptime") )
{
preg_match( "/(?:averages)?\: ([0-9\.]+),[\s]+([0-9\.]+),[\s]+([0-9\.]+)/", $serverstats, $load );
$this->ipsclass->server_load = $load[1];
if ($this->ipsclass->server_load > $this->ipsclass->vars['load_limit'])
{
$this->ipsclass->Error( array( 'LEVEL' => 1, 'MSG' => 'server_too_busy', 'INIT' => 1 ) );
}
}
}
}
}
@@ -189,7 +183,7 @@ class session
}
}
if ( preg_match( '/('.implode( '|', $this->bot_safe ) .')/i', $_SERVER['HTTP_USER_AGENT'], $match ) )
if ( preg_match( '/('.implode( '|', $this->bot_safe ) .')/i', $this->ipsclass->my_getenv('HTTP_USER_AGENT'), $match ) )
{
$this->ipsclass->DB->simple_construct( array( 'select' => '*',
'from' => 'groups',
@@ -228,21 +222,23 @@ class session
// Using lofi?
//-----------------------------------------
if ( strstr( $_SERVER['PHP_SELF'], 'lofiversion' ) )
if ( strstr( $this->ipsclass->my_getenv('PHP_SELF'), 'lofiversion' ) )
{
$qstring = "Lo-Fi: ".str_replace( "/", "", strrchr( $_SERVER['PHP_SELF'], "/" ) );
$qstring = "Lo-Fi: ".str_replace( "/", "", strrchr( $this->ipsclass->my_getenv('PHP_SELF'), "/" ) );
}
else
{
$qstring = str_replace( "'", "", $_SERVER['QUERY_STRING']);
$qstring = str_replace( "'", "", $this->ipsclass->my_getenv('QUERY_STRING'));
}
$qstring = htmlentities( strip_tags( str_replace( '\\', '', $qstring ) ) );
if ( $this->ipsclass->vars['spider_visit'] )
{
$this->ipsclass->DB->do_shutdown_insert( 'spider_logs', array (
'bot' => $agent,
'query_string' => $qstring,
'ip_address' => $_SERVER['REMOTE_ADDR'],
'ip_address' => $this->ipsclass->my_getenv('REMOTE_ADDR'),
'entry_date' => time(),
) );
}
@@ -268,13 +264,13 @@ class session
$cookie['session_id'] = $this->ipsclass->my_getcookie('session_id');
$cookie['member_id'] = $this->ipsclass->my_getcookie('member_id');
$cookie['pass_hash'] = $this->ipsclass->my_getcookie('pass_hash');
if ( $cookie['session_id'] )
{
$this->get_session($cookie['session_id']);
$this->ipsclass->session_type = 'cookie';
}
elseif ( $this->ipsclass->input['s'] )
elseif ( isset($this->ipsclass->input['s']) AND $this->ipsclass->input['s'] )
{
$this->get_session($this->ipsclass->input['s']);
$this->ipsclass->session_type = 'url';
@@ -329,9 +325,9 @@ class session
// Do we have cookies stored?
//-----------------------------------------
if ($cookie['member_id'] != "" and $cookie['pass_hash'] != "")
if ( $cookie['member_id'] != "" and $cookie['pass_hash'] != "" )
{
$this->load_member($cookie['member_id']);
$this->load_member( $cookie['member_id'] );
if ( (! $this->member['id']) or ($this->member['id'] == 0) )
{
@@ -340,9 +336,67 @@ class session
}
else
{
if ($this->member['member_login_key'] == $cookie['pass_hash'])
if ( $this->member['member_login_key'] == $cookie['pass_hash'] )
{
$this->create_member_session();
//-----------------------------------------
// STRONG HOLD
//-----------------------------------------
if ( $this->ipsclass->stronghold_check_cookie( $this->member['id'], $this->member['member_login_key'] ) !== TRUE )
{
$this->unload_member();
$this->create_guest_session();
}
else
{
$_ok = 1;
$_days = 0;
$_sticky = 1;
$_time = ( $this->ipsclass->vars['login_key_expire'] ) ? ( time() + ( intval($this->ipsclass->vars['login_key_expire']) * 86400 ) ) : 0;
//-----------------------------------------
// Key expired?
//-----------------------------------------
if ( $this->ipsclass->vars['login_key_expire'] )
{
$_sticky = 0;
$_days = $this->ipsclass->vars['login_key_expire'];
if ( time() > $this->member['member_login_key_expire'] )
{
$_ok = 0;
}
}
if ( $_ok == 1 )
{
$this->create_member_session();
//-----------------------------------------
// Change the log in key to make each authentication
// use a unique token. This means that if a cookie is
// stolen, the hacker can only use the auth once.
//-----------------------------------------
if ( $this->ipsclass->vars['login_change_key'] )
{
$this->member['member_login_key'] = $this->ipsclass->converge->generate_auto_log_in_key();
$this->ipsclass->DB->do_update( 'members', array( 'member_login_key' => $this->member['member_login_key'],
'member_login_key_expire' => $_time ), 'id='.$this->member['id'] );
$this->ipsclass->my_setcookie( "pass_hash", $this->member['member_login_key'], $_sticky, $_days );
$this->ipsclass->stronghold_set_cookie( $this->member['id'], $this->member['member_login_key'] );
}
}
else
{
$this->unload_member();
$this->create_guest_session();
}
}
}
else
{
@@ -361,7 +415,9 @@ class session
// Knock out Google Web Accelerator
//-----------------------------------------
if ( strstr( strtolower($_SERVER['HTTP_X_MOZ']), 'prefetch' ) AND $this->member['id'] )
$http_moz = $this->ipsclass->my_getenv('HTTP_X_MOZ');
if ( isset($http_moz) AND strstr( strtolower($http_moz), 'prefetch' ) AND $this->member['id'] )
{
if ( IPB_PHP_SAPI == 'cgi-fcgi' OR IPB_PHP_SAPI == 'cgi' )
{
@@ -438,13 +494,25 @@ class session
}
else if ( count($this->ipsclass->cache['moderators']) )
{
foreach( $this->ipsclass->cache['moderators'] as $i => $r )
$other_mgroups = array();
if( $this->member['mgroup_others'] )
{
$other_mgroups = explode( ",", $this->ipsclass->clean_perm_string( $this->member['mgroup_others'] ) );
}
foreach( $this->ipsclass->cache['moderators'] as $r )
{
if ( $r['member_id'] == $this->member['id'] or $r['group_id'] == $this->member['mgroup'] )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
$this->member['is_mod'] = 1;
}
else if( count($other_mgroups) AND in_array( $r['group_id'], $other_mgroups ) )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
$this->member['is_mod'] = 1;
}
}
}
@@ -464,13 +532,13 @@ class session
if ( $this->member['id'] )
{
if ( ! $this->ipsclass->input['last_activity'] )
if ( !isset($this->ipsclass->input['last_activity']) OR !$this->ipsclass->input['last_activity'] )
{
$this->ipsclass->input['last_activity'] = $this->member['last_activity'] ? $this->member['last_activity'] : $this->time_now;
}
if ( ! $this->ipsclass->input['last_visit'] )
if ( !isset($this->ipsclass->input['last_visit']) OR !$this->ipsclass->input['last_visit'] )
{
$this->ipsclass->input['last_visit'] = $this->member['last_visit'] ? $this->member['last_visit'] : $this->time_now;
}
@@ -555,7 +623,7 @@ class session
function build_group_permissions()
{
if ( $this->member['mgroup_others'] )
if ( isset($this->member['mgroup_others']) AND $this->member['mgroup_others'] )
{
$groups_id = explode( ',', $this->member['mgroup_others'] );
$exclude = array( 'g_title', 'g_icon', 'prefix', 'suffix', 'g_promotion', 'g_photo_max_vars' );
@@ -566,7 +634,7 @@ class session
{
foreach( $groups_id as $pid )
{
if ( ! $this->ipsclass->cache['group_cache'][ $pid ]['g_id'] )
if ( ! isset($this->ipsclass->cache['group_cache'][ $pid ]['g_id']) OR !$this->ipsclass->cache['group_cache'][ $pid ]['g_id'] )
{
continue;
}
@@ -589,11 +657,11 @@ class session
}
else if ( in_array( $k, $zero_is_best ) )
{
if( $this->member[ $k ] == 0 )
if ( $this->member[ $k ] == 0 )
{
continue;
}
else if( $v > $this->member[ $k ] )
else if ( $v > $this->member[ $k ] )
{
$this->member[ $k ] = $v;
}
@@ -638,7 +706,7 @@ class session
}
}
$this->ipsclass->perm_id = ( $this->member['org_perm_id'] ) ? $this->member['org_perm_id'] : $this->member['g_perm_id'];
$this->ipsclass->perm_id = ( isset($this->member['org_perm_id']) AND $this->member['org_perm_id'] ) ? $this->member['org_perm_id'] : $this->member['g_perm_id'];
$this->ipsclass->perm_id_array = explode( ",", $this->ipsclass->perm_id );
}
@@ -653,10 +721,10 @@ class session
if ($member_id != 0)
{
$this->ipsclass->DB->build_query( array( 'select' => "id, name, mgroup, member_login_key, email, restrict_post, view_sigs, view_avs, view_pop, view_img, auto_track,
$this->ipsclass->DB->build_query( array( 'select' => "id, name, mgroup, member_login_key, member_login_key_expire, email, restrict_post, view_sigs, view_avs, view_pop, view_img, auto_track,
mod_posts, language, skin, new_msg, show_popup, msg_total, time_offset, posts, joined, last_post, subs_pkg_chosen,
ignored_users, login_anonymous, last_visit, last_activity, dst_in_use, view_prefs, org_perm_id, mgroup_others, temp_ban, sub_end,
has_blog, members_markers, members_editor_choice, members_auto_dst, members_display_name, members_created_remote,
has_blog, has_gallery, members_markers, members_editor_choice, members_auto_dst, members_display_name, members_created_remote,
members_cache, members_disable_pm",
'from' => 'members',
'where' => 'id='.$member_id ) );
@@ -682,7 +750,7 @@ class session
// Unpack cache
//-----------------------------------------
if ( $this->member['members_cache'] )
if ( isset($this->member['members_cache']) )
{
$this->member['_cache'] = $this->ipsclass->unpack_member_cache( $this->member['members_cache'] );
}
@@ -691,6 +759,11 @@ class session
$this->member['_cache'] = array();
}
if ( ! isset( $this->member['_cache']['friends'] ) or ! is_array( $this->member['_cache']['friends'] ) )
{
$this->member['_cache']['friends'] = array();
}
unset($member_id);
}
@@ -731,6 +804,14 @@ class session
return;
}
if ( time() - $this->member['last_activity'] > $this->ipsclass->vars['session_expiration'] )
{
// Session is expired - create new session
$this->create_member_session();
return;
}
//-----------------------------------------
// Get module settings
//-----------------------------------------
@@ -746,6 +827,8 @@ class session
return;
}
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_update( 'sessions',
array(
'member_name' => $this->member['members_display_name'],
@@ -755,12 +838,12 @@ class session
'running_time' => $this->time_now,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
),
"id='{$this->session_id}'"
);
@@ -797,21 +880,23 @@ class session
return;
}
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_update( 'sessions',
array(
'member_name' => "",
'member_name' => '',
'member_id' => 0,
'member_group' => $this->ipsclass->vars['guest_group'],
'login_type' => substr($this->member['login_anonymous'],0, 1),
'login_type' => '',
'running_time' => $this->time_now,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
),
"id='{$this->session_id}'"
);
@@ -903,8 +988,7 @@ class session
$this->ipsclass->vars['session_expiration'] = $this->ipsclass->vars['session_expiration'] ? (time() - $this->ipsclass->vars['session_expiration']) : (time() - 3600);
$this->ipsclass->DB->simple_construct( array( 'delete' => 'sessions', 'where' => "member_id=".$this->member['id'] ) );
$this->ipsclass->DB->simple_exec();
$this->ipsclass->DB->do_delete( 'sessions', "member_id=".$this->member['id'] );
$this->session_id = md5( uniqid(microtime()) );
@@ -927,6 +1011,8 @@ class session
// Insert the new session
//-----------------------------------------
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_insert( 'sessions',
array(
'id' => $this->session_id,
@@ -939,12 +1025,12 @@ class session
'browser' => $this->ipsclass->user_agent,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
)
);
@@ -1007,7 +1093,8 @@ class session
{
$query[] = "id='".$this->session_dead_id."'";
}
else if ( $this->ipsclass->vars['match_ipaddress'] == 1 )
if ( $this->ipsclass->vars['match_ipaddress'] == 1 )
{
$query[] = "ip_address='".$this->ipsclass->ip_address."'";
}
@@ -1039,6 +1126,8 @@ class session
// Insert the new session
//-----------------------------------------
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_insert( 'sessions',
array(
'id' => $this->session_id,
@@ -1051,12 +1140,12 @@ class session
'browser' => $this->ipsclass->user_agent,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
)
);
}
@@ -1073,6 +1162,8 @@ class session
$vars = $this->_get_location_settings();
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_insert( 'sessions',
array(
'id' => $bot.'='.str_replace('.','',$this->ipsclass->ip_address ).'_session',
@@ -1085,12 +1176,12 @@ class session
'browser' => $this->ipsclass->user_agent,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
)
);
}
@@ -1107,6 +1198,8 @@ class session
$vars = $this->_get_location_settings();
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_shutdown_update( 'sessions',
array(
'member_name' => $name ? $name : $bot,
@@ -1116,12 +1209,12 @@ class session
'running_time' => $this->time_now,
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => $vars['1_type'],
'location_1_id' => $vars['1_id'],
'location_2_type' => $vars['2_type'],
'location_2_id' => $vars['2_id'],
'location_3_type' => $vars['3_type'],
'location_3_id' => $vars['3_id'],
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
'location_1_id' => isset($vars['1_id']) ? intval($vars['1_id']) : 0,
'location_2_type' => isset($vars['2_type']) ? $vars['2_type'] : '',
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
),
"id='".$bot.'='.str_replace('.','',$this->ipsclass->ip_address )."_session'"
);
@@ -1138,7 +1231,7 @@ class session
//-----------------------------------------
$return = array();
$module = $this->ipsclass->input['automodule'] ? $this->ipsclass->input['automodule'] : $this->ipsclass->input['module'];
$module = isset($this->ipsclass->input['automodule']) ? $this->ipsclass->input['automodule'] : ( isset($this->ipsclass->input['module']) ? $this->ipsclass->input['module'] : '' );
//-----------------------------------------
// MODULE?
@@ -1203,6 +1296,9 @@ class session
else
{
$this->ipsclass->input['p'] = isset($this->ipsclass->input['p']) ? $this->ipsclass->input['p'] : '';
$this->ipsclass->input['CODE'] = isset($this->ipsclass->input['CODE']) ? $this->ipsclass->input['CODE'] : '';
$return = array( 'location' => $this->ipsclass->input['act'].",".$this->ipsclass->input['p'].",".$this->ipsclass->input['CODE'] );
}