Version 4.7.23

This commit is contained in:
Neo committed 2025-12-19 16:21:27 -08:00
1 parent 7124a02564
commit 25ddeb65d6
1791 files changed
+76990 -44452

No files matched your search

@@ -10,6 +10,8 @@
namespace IPS\core\modules\front\system;
use IPS\Text\Encrypt;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
@@ -61,7 +63,7 @@ class _register extends \IPS\Dispatcher\Controller
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimalNoHome';
}
\IPS\Output::i()->sidebar['enabled'] = FALSE;
\IPS\Output::i()->pageCaching = FALSE;
\IPS\Output::setCacheTime( false );
\IPS\Output::i()->linkTags['canonical'] = (string) \IPS\Http\Url::internal( 'app=core&module=system&controller=register', 'front', 'register' );
}
@@ -430,14 +432,20 @@ class _register extends \IPS\Dispatcher\Controller
/* Set the form label */
\IPS\Member::loggedIn()->language()->words['q_and_a'] = \IPS\Member::loggedIn()->language()->addToStack( 'core_question_and_answer_' . $question['qa_id'], FALSE );
}
$captcha = new \IPS\Helpers\Form\Captcha;
/* If PBR request is from the last 5 minutes, don't ask for a captcha again */
if( $postBeforeRegister !== NULL AND \IPS\DateTime::ts( $postBeforeRegister['timestamp'] )->add( new \DateInterval('PT5M' ) )->getTimestamp() > time() )
{
$captcha = '';
}
if ( (string) $captcha !== '' )
{
$form->add( $captcha );
}
if ( $question OR (string) $captcha !== '' )
{
$form->addSeparator();
@@ -600,7 +608,7 @@ class _register extends \IPS\Dispatcher\Controller
$answers[ $v ] = array(
'answer_question_id' => $v,
'answer_member_id' => $member->member_id,
'answer_answer' => \IPS\Text\Encrypt::fromPlaintext( $values[ 'security_question_a_' . $matches[1] ] )->tag()
'answer_answer' => Encrypt::fromPlaintext( $values[ 'security_question_a_' . $matches[1] ] )->tag()
);
}
}
@@ -683,6 +691,13 @@ class _register extends \IPS\Dispatcher\Controller
}
catch ( \UnderflowException $e )
{
/* Reset the validation flag and redirect the member to the index page if we have no row */
if( \IPS\Member::loggedIn()->members_bitoptions['validating'] )
{
\IPS\Member::loggedIn()->members_bitoptions['validating'] = FALSE;
\IPS\Member::loggedIn()->save();
$this->_performRedirect( NULL, FALSE, 'validate_no_record' );
}
\IPS\Output::i()->error( 'validate_no_record', '2S129/4', 404, '' );
}
@@ -727,10 +742,12 @@ class _register extends \IPS\Dispatcher\Controller
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack('validation_email_rate_limit', FALSE, array( 'sprintf' => array( \IPS\DateTime::ts( $reg['email_sent'] )->relative( \IPS\DateTime::RELATIVE_FORMAT_LOWER ) ) ) ), '1C223/4', 429, '', array( 'Retry-After' => \IPS\DateTime::ts( $reg['email_sent'] )->add( new \DateInterval( 'PT15M' ) )->format('r') ) );
}
/* Rotate security key */
$plainSecurityKey = \IPS\Login::generateRandomString();
\IPS\Db::i()->update( 'core_validating', [ 'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag(), 'email_sent' => time() ], [ 'vid=?', $reg['vid'] ] );
\IPS\Email::buildFromTemplate( 'core', $reg['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $reg['vid'] ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
\IPS\Db::i()->update( 'core_validating', array( 'email_sent' => time() ), array( 'vid=?', $reg['vid'] ) );
\IPS\Email::buildFromTemplate( 'core', $reg['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $reg['vid'], $plainSecurityKey ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=register&do=validating', 'front', 'register' ), 'reg_email_resent' );
@@ -758,6 +775,12 @@ class _register extends \IPS\Dispatcher\Controller
$this->_performRedirect( NULL, FALSE, 'validate_no_record' );
}
/* Check security key */
if( !\IPS\Login::compareHashes( Encrypt::fromTag( $record['security_key'] )->decrypt(), \IPS\Request::i()->security_key ) )
{
\IPS\Output::i()->error( 'validate_invalid_security_key', '2C223/I', 403, '' );
}
if ( isset( $record['ref'] ) )
{
\IPS\Request::i()->ref = base64_encode( $record['ref'] );
@@ -878,17 +901,21 @@ class _register extends \IPS\Dispatcher\Controller
{
if( isset( $values['username'] ) )
{
\IPS\Member::loggedIn()->logHistory( 'core', 'display_name', array( 'new' => $values['username'], 'old' => \IPS\Member::loggedIn()->language()->get('none'), 'by' => 'manual' ) );
\IPS\Member::loggedIn()->name = $values['username'];
}
$spamCode = NULL;
$spamAction = NULL;
$disposable = FALSE;
$geoBlock = FALSE;
if( isset( $values['email_address'] ) )
{
\IPS\Member::loggedIn()->logHistory( 'core', 'email_change', array( 'new' => $values['new_email'], 'old' => \IPS\Member::loggedIn()->language()->get('none'), 'by' => 'manual' ) );
\IPS\Member::loggedIn()->email = $values['email_address'];
if( \IPS\Settings::i()->spam_service_enabled )
{
$spamAction = \IPS\Member::loggedIn()->spamService( 'register', NULL, $spamCode );
$spamAction = \IPS\Member::loggedIn()->spamService( 'register', NULL, $spamCode, $disposable, $geoBlock );
if( $spamAction == 4 )
{
$action = \IPS\Settings::i()->spam_service_action_4;
@@ -905,6 +932,12 @@ class _register extends \IPS\Dispatcher\Controller
}
\IPS\Member::loggedIn()->members_bitoptions['must_reaccept_terms'] = FALSE;
\IPS\Member::loggedIn()->allow_admin_mails = $values['reg_admin_mails'];
/* We should run geolocation again, this may have been an account created via login handler that has since changed details - check for admin validation */
if( !$spamAction )
{
\IPS\Member::loggedIn()->geoSpamCheck( $geoBlock );
}
/* Save */
\IPS\Member::loggedIn()->save();
@@ -967,10 +1000,8 @@ class _register extends \IPS\Dispatcher\Controller
$pending = null;
}
/* If we're pending *admin* validation, don't let them change their email - otherwise doing so would allow them to bypass validation
@todo - this is kind of an unsatisfcatory solution as ideally it would put them back into admin approval, but this would require
significant reengineering to address - see commit notes on this code block */
if ( $pending and $pending['new_reg'] and $pending['user_verified'] )
/* If we're a new registration, no longer allow email addresses to be changed. */
if ( $pending and $pending['new_reg'] )
{
\IPS\Output::i()->error( 'no_module_permission', '2C223/6', 403, '' );
}
@@ -1033,8 +1064,9 @@ class _register extends \IPS\Dispatcher\Controller
}
$vid = \IPS\Login::generateRandomString();
$plainSecurityKey = \IPS\Login::generateRandomString();
\IPS\Db::i()->insert( 'core_validating', array(
\IPS\Db::i()->insert( 'core_validating', [
'vid' => $vid,
'member_id' => \IPS\Member::loggedIn()->member_id,
'entry_date' => time(),
@@ -1043,9 +1075,10 @@ class _register extends \IPS\Dispatcher\Controller
'user_verified' => ( \IPS\Settings::i()->reg_auth_type == 'admin' ) ?: FALSE,
'ip_address' => \IPS\Request::i()->ipAddress(),
'email_sent' => time(),
) );
'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag()
] );
\IPS\Email::buildFromTemplate( 'core', $pending['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $vid ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
\IPS\Email::buildFromTemplate( 'core', $pending['email_chg'] ? 'email_change' : 'registration_validate', array( \IPS\Member::loggedIn(), $vid, $plainSecurityKey ), \IPS\Email::TYPE_TRANSACTIONAL )->send( \IPS\Member::loggedIn() );
}
else
{
@@ -1233,7 +1266,7 @@ class _register extends \IPS\Dispatcher\Controller
return $ref;
}
\IPS\Output::i()->redirect( $ref, $message );
\IPS\Output::i()->redirect( $ref, $message );
}
/**