Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -10,6 +10,9 @@
|
||||
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
use IPS\Http\Url;
|
||||
use IPS\Output;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
@@ -103,58 +106,64 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
|
||||
/* As you can insert "other media" from other apps (such as Downloads), we need to route the attachIDs appropriately. */
|
||||
$attachmentIds = array();
|
||||
|
||||
foreach( array_keys( \IPS\Request::i()->attachIDs ) as $attachId )
|
||||
{
|
||||
if( (int) $attachId == $attachId AND mb_strlen( (int) $attachId ) == mb_strlen( $attachId ) )
|
||||
{
|
||||
$attachmentIds[] = $attachId;
|
||||
}
|
||||
else
|
||||
{
|
||||
try
|
||||
{
|
||||
$url = \IPS\Http\Url::createFromString( $attachId );
|
||||
|
||||
/* Get the "real" query string (whatever the query string is, plus what we can get from decoding the FURL) */
|
||||
$qs = array_merge( $url->queryString, $url->hiddenQueryString );
|
||||
|
||||
/* We need an app, and it needs to not be an RSS link */
|
||||
if ( !isset( $qs['app'] ) )
|
||||
{
|
||||
throw new \UnexpectedValueException;
|
||||
}
|
||||
|
||||
/* Load the application */
|
||||
$application = \IPS\Application::load( $qs['app'] );
|
||||
|
||||
/* Loop through our content classes and see if we can find one that matches */
|
||||
foreach ( $application->extensions( 'core', 'ContentRouter' ) as $key => $extension )
|
||||
{
|
||||
$classes = $extension->classes;
|
||||
|
||||
/* So for each of those... */
|
||||
foreach ( $classes as $class )
|
||||
if( \IPS\Request::i()->attachIDs )
|
||||
{
|
||||
foreach( array_keys( \IPS\Request::i()->attachIDs ) as $attachId )
|
||||
{
|
||||
if( (int) $attachId == $attachId and mb_strlen( (int) $attachId ) == mb_strlen( $attachId ) )
|
||||
{
|
||||
$attachmentIds[] = $attachId;
|
||||
}else
|
||||
{
|
||||
try
|
||||
{
|
||||
$url = \IPS\Http\Url::createFromString( $attachId );
|
||||
|
||||
/* Get the "real" query string (whatever the query string is, plus what we can get from decoding the FURL) */
|
||||
$qs = array_merge( $url->queryString, $url->hiddenQueryString );
|
||||
|
||||
/* We need an app, and it needs to not be an RSS link */
|
||||
if( !isset( $qs[ 'app' ] ) )
|
||||
{
|
||||
/* Try to load it */
|
||||
try
|
||||
throw new \UnexpectedValueException;
|
||||
}
|
||||
|
||||
/* Load the application */
|
||||
$application = \IPS\Application::load( $qs[ 'app' ] );
|
||||
|
||||
/* Loop through our content classes and see if we can find one that matches */
|
||||
foreach( $application->extensions( 'core', 'ContentRouter' ) as $key => $extension )
|
||||
{
|
||||
$classes = $extension->classes;
|
||||
|
||||
/* So for each of those... */
|
||||
foreach( $classes as $class )
|
||||
{
|
||||
$item = $class::loadFromURL( $url );
|
||||
|
||||
if( !$item->canView() )
|
||||
/* Try to load it */
|
||||
try
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
}
|
||||
$item = $class::loadFromURL( $url );
|
||||
|
||||
/* If we're still here, we should be good. Any exceptions will have been caught by our general try/catch. */
|
||||
$toReturn[ $attachId ] = $item->getAttachmentInfo();
|
||||
break;
|
||||
if( !$item->canView() )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
}
|
||||
|
||||
/* If we're still here, we should be good. Any exceptions will have been caught by our general try/catch. */
|
||||
$toReturn[ $attachId ] = $item->getAttachmentInfo();
|
||||
break;
|
||||
}
|
||||
catch( \OutOfRangeException $e )
|
||||
{
|
||||
}
|
||||
}
|
||||
catch( \OutOfRangeException $e ){}
|
||||
}
|
||||
}
|
||||
catch( \Exception $e )
|
||||
{
|
||||
}
|
||||
}
|
||||
catch( \Exception $e ){}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -197,7 +206,7 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
try
|
||||
{
|
||||
if ( $loadedExtensions[ $map['location_key'] ]->attachmentPermissionCheck( $member, $map['id1'], $map['id2'], $map['id3'], $attachment ) )
|
||||
if ( method_exists( $loadedExtensions[ $map['location_key'] ], 'attachmentPermissionCheck') AND $loadedExtensions[ $map['location_key'] ]->attachmentPermissionCheck( $member, $map['id1'], $map['id2'], $map['id3'], $attachment ) )
|
||||
{
|
||||
$permission = TRUE;
|
||||
break;
|
||||
@@ -685,7 +694,10 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
public function getCsrfKey()
|
||||
{
|
||||
/* Don't cache the CSRF key */
|
||||
\IPS\Output::i()->pageCaching = FALSE;
|
||||
\IPS\Output::setCacheTime( false );
|
||||
|
||||
/* Restrict endpoint to our origin JS */
|
||||
Output::i()->httpHeaders['Access-Control-Allow-Origin'] = Url::internal('')->data[ Url::COMPONENT_SCHEME ] . '://' . Url::internal('')->data[ Url::COMPONENT_HOST ];
|
||||
|
||||
if ( isset( \IPS\Request::i()->path ) )
|
||||
{
|
||||
@@ -717,7 +729,7 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
}
|
||||
|
||||
\IPS\Output::i()->json( [ 'key' => \IPS\Session::i()->csrfKey ] );
|
||||
\IPS\Output::i()->json( [ 'key' => \IPS\Session::i()->csrfKey, 'expiry' => time() + 500 ] );
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in new issue
Block a user