Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -10,6 +10,8 @@
|
||||
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
use IPS\Text\Encrypt;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
@@ -61,7 +63,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimalNoHome';
|
||||
}
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->pageCaching = FALSE;
|
||||
\IPS\Output::setCacheTime( false );
|
||||
\IPS\Output::i()->linkTags['canonical'] = (string) \IPS\Http\Url::internal( 'app=core&module=system&controller=register', 'front', 'register' );
|
||||
}
|
||||
|
||||
@@ -430,14 +432,20 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
/* Set the form label */
|
||||
\IPS\Member::loggedIn()->language()->words['q_and_a'] = \IPS\Member::loggedIn()->language()->addToStack( 'core_question_and_answer_' . $question['qa_id'], FALSE );
|
||||
}
|
||||
|
||||
|
||||
$captcha = new \IPS\Helpers\Form\Captcha;
|
||||
|
||||
|
||||
/* If PBR request is from the last 5 minutes, don't ask for a captcha again */
|
||||
if( $postBeforeRegister !== NULL AND \IPS\DateTime::ts( $postBeforeRegister['timestamp'] )->add( new \DateInterval('PT5M' ) )->getTimestamp() > time() )
|
||||
{
|
||||
$captcha = '';
|
||||
}
|
||||
|
||||
if ( (string) $captcha !== '' )
|
||||
{
|
||||
$form->add( $captcha );
|
||||
}
|
||||
|
||||
|
||||
if ( $question OR (string) $captcha !== '' )
|
||||
{
|
||||
$form->addSeparator();
|
||||
@@ -600,7 +608,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
$answers[ $v ] = array(
|
||||
'answer_question_id' => $v,
|
||||
'answer_member_id' => $member->member_id,
|
||||
'answer_answer' => \IPS\Text\Encrypt::fromPlaintext( $values[ 'security_question_a_' . $matches[1] ] )->tag()
|
||||
'answer_answer' => Encrypt::fromPlaintext( $values[ 'security_question_a_' . $matches[1] ] )->tag()
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -683,6 +691,13 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
{
|
||||
/* Reset the validation flag and redirect the member to the index page if we have no row */
|
||||
if( \IPS\Member::loggedIn()->members_bitoptions['validating'] )
|
||||
{
|
||||
\IPS\Member::loggedIn()->members_bitoptions['validating'] = FALSE;
|
||||
\IPS\Member::loggedIn()->save();
|
||||
$this->_performRedirect( NULL, FALSE, 'validate_no_record' );
|
||||
}
|
||||
\IPS\Output::i()->error( 'validate_no_record', '2S129/4', 404, '' );
|
||||
}
|
||||
|
||||
@@ -727,10 +742,12 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack('validation_email_rate_limit', FALSE, array( 'sprintf' => array( \IPS\DateTime::ts( $reg['email_sent'] )->relative( \IPS\DateTime::RELATIVE_FORMAT_LOWER ) ) ) ), '1C223/4', 429, '', array( 'Retry-After' => \IPS\DateTime::ts( $reg['email_sent'] )->add( new \DateInterval( 'PT15M' ) )->format('r') ) );
|
||||
}
|
||||
|
||||
/* Rotate security key */
|
||||
$plainSecurityKey = \IPS\Login::generateRandomString();
|
||||
\IPS\Db::i()->update( 'core_validating', [ 'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag(), 'email_sent' => time() ], [ 'vid=?', $reg['vid'] ] );
|
||||
|
||||
\IPS\Email::buildFromTemplate( 'core', $reg['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $reg['vid'] ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
|
||||
|
||||
\IPS\Db::i()->update( 'core_validating', array( 'email_sent' => time() ), array( 'vid=?', $reg['vid'] ) );
|
||||
\IPS\Email::buildFromTemplate( 'core', $reg['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $reg['vid'], $plainSecurityKey ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
|
||||
}
|
||||
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=register&do=validating', 'front', 'register' ), 'reg_email_resent' );
|
||||
@@ -758,6 +775,12 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
$this->_performRedirect( NULL, FALSE, 'validate_no_record' );
|
||||
}
|
||||
|
||||
/* Check security key */
|
||||
if( !\IPS\Login::compareHashes( Encrypt::fromTag( $record['security_key'] )->decrypt(), \IPS\Request::i()->security_key ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'validate_invalid_security_key', '2C223/I', 403, '' );
|
||||
}
|
||||
|
||||
if ( isset( $record['ref'] ) )
|
||||
{
|
||||
\IPS\Request::i()->ref = base64_encode( $record['ref'] );
|
||||
@@ -878,17 +901,21 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
if( isset( $values['username'] ) )
|
||||
{
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'display_name', array( 'new' => $values['username'], 'old' => \IPS\Member::loggedIn()->language()->get('none'), 'by' => 'manual' ) );
|
||||
\IPS\Member::loggedIn()->name = $values['username'];
|
||||
}
|
||||
$spamCode = NULL;
|
||||
$spamAction = NULL;
|
||||
$disposable = FALSE;
|
||||
$geoBlock = FALSE;
|
||||
if( isset( $values['email_address'] ) )
|
||||
{
|
||||
\IPS\Member::loggedIn()->logHistory( 'core', 'email_change', array( 'new' => $values['new_email'], 'old' => \IPS\Member::loggedIn()->language()->get('none'), 'by' => 'manual' ) );
|
||||
\IPS\Member::loggedIn()->email = $values['email_address'];
|
||||
|
||||
if( \IPS\Settings::i()->spam_service_enabled )
|
||||
{
|
||||
$spamAction = \IPS\Member::loggedIn()->spamService( 'register', NULL, $spamCode );
|
||||
$spamAction = \IPS\Member::loggedIn()->spamService( 'register', NULL, $spamCode, $disposable, $geoBlock );
|
||||
if( $spamAction == 4 )
|
||||
{
|
||||
$action = \IPS\Settings::i()->spam_service_action_4;
|
||||
@@ -905,6 +932,12 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
\IPS\Member::loggedIn()->members_bitoptions['must_reaccept_terms'] = FALSE;
|
||||
\IPS\Member::loggedIn()->allow_admin_mails = $values['reg_admin_mails'];
|
||||
|
||||
/* We should run geolocation again, this may have been an account created via login handler that has since changed details - check for admin validation */
|
||||
if( !$spamAction )
|
||||
{
|
||||
\IPS\Member::loggedIn()->geoSpamCheck( $geoBlock );
|
||||
}
|
||||
|
||||
/* Save */
|
||||
\IPS\Member::loggedIn()->save();
|
||||
@@ -967,10 +1000,8 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
$pending = null;
|
||||
}
|
||||
|
||||
/* If we're pending *admin* validation, don't let them change their email - otherwise doing so would allow them to bypass validation
|
||||
@todo - this is kind of an unsatisfcatory solution as ideally it would put them back into admin approval, but this would require
|
||||
significant reengineering to address - see commit notes on this code block */
|
||||
if ( $pending and $pending['new_reg'] and $pending['user_verified'] )
|
||||
/* If we're a new registration, no longer allow email addresses to be changed. */
|
||||
if ( $pending and $pending['new_reg'] )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2C223/6', 403, '' );
|
||||
}
|
||||
@@ -1033,8 +1064,9 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
$vid = \IPS\Login::generateRandomString();
|
||||
$plainSecurityKey = \IPS\Login::generateRandomString();
|
||||
|
||||
\IPS\Db::i()->insert( 'core_validating', array(
|
||||
\IPS\Db::i()->insert( 'core_validating', [
|
||||
'vid' => $vid,
|
||||
'member_id' => \IPS\Member::loggedIn()->member_id,
|
||||
'entry_date' => time(),
|
||||
@@ -1043,9 +1075,10 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
'user_verified' => ( \IPS\Settings::i()->reg_auth_type == 'admin' ) ?: FALSE,
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
'email_sent' => time(),
|
||||
) );
|
||||
'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag()
|
||||
] );
|
||||
|
||||
\IPS\Email::buildFromTemplate( 'core', $pending['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $vid ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
|
||||
\IPS\Email::buildFromTemplate( 'core', $pending['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $vid, $plainSecurityKey ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -1233,7 +1266,7 @@ class _register extends \IPS\Dispatcher\Controller
|
||||
return $ref;
|
||||
}
|
||||
|
||||
\IPS\Output::i()->redirect( $ref, $message );
|
||||
\IPS\Output::i()->redirect( $ref, $message );
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in new issue
Block a user