Version 4.7.23

This commit is contained in:
Neo committed 2025-12-19 16:21:27 -08:00
1 parent 7124a02564
commit 25ddeb65d6
1791 files changed
+76990 -44452

No files matched your search

+2 -1
View File
@@ -455,7 +455,8 @@ class oAuthServerAuthorizationRequest
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimalNoHome';
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'oauth_authorize', FALSE, array( 'sprintf' => array( \IPS\Settings::i()->board_name ) ) );
\IPS\Output::i()->httpHeaders['X-Frame-Options'] = 'DENY';
\IPS\Output::i()->pageCaching = FALSE;
\IPS\Output::i()->httpHeaders['Cross-Origin-Opener-Policy'] = 'same-origin';
\IPS\Output::setCacheTime( false );
/* Check we are not banned */
if ( \IPS\Request::i()->ipAddressIsBanned() or ( \IPS\Member::loggedIn()->member_id and \IPS\Member::loggedIn()->isBanned() ) )
+7 -44
View File
@@ -69,53 +69,15 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
$destination = $destination->setQueryString( 'code', \IPS\Request::i()->code );
}
if ( \IPS\Request::i()->requestMethod() === 'POST' )
/* If it's a POST request and the URL is quite long, we need to redirect via POST */
if ( \IPS\Request::i()->requestMethod() === 'POST')
{
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
@header( "Expires: 0" );
$queryStringComponents = $destination->queryString;
$loading = \IPS\Member::loggedIn()->language()->get('loading');
$message = \IPS\Member::loggedIn()->language()->get('oauth_post_redirect_submit');
$destination = \IPS\Http\Url::createFromString( @base64_decode( $explodedData[1] ) );
$output = <<<HTML
<!DOCTYPE html>
<html>
<head>
<title>{$loading}</title>
</head>
<body>
<noscript>{$message}</noscript>
<form style="display: none" action="{$destination}" method="POST">
HTML;
foreach ( $queryStringComponents as $k => $v )
if( empty( $destination->queryString['ref'] ) )
{
if ( $k === 'ref' )
{
if ( !$v )
{
$v = base64_encode( (string) \IPS\Http\Url::baseUrl() );
}
}
$output .= <<<HTML
<input name="{$k}" value="{$v}" >
HTML;
$destination = $destination->setQueryString( 'ref', base64_encode( (string) \IPS\Http\Url::baseUrl() ) );
}
$output .= <<<HTML
<input type="submit" value="{$message}" />
</form>
<script>
const form = document.querySelector('form');
form.submit();
</script>
</body>
</html>
HTML;
echo $output;
exit;
\IPS\Output::i()->redirect( $destination, httpStatusCode: 307 );
}
\IPS\Output::i()->redirect( $destination );
@@ -127,6 +89,7 @@ HTML;
$url = (string) \IPS\Http\Url::internal( 'oauth/callback/', 'none' );
/* Force no caching */
@header( 'Cross-Origin-Opener-Policy: same-origin' );
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
@header( "Expires: 0" );
?><!DOCTYPE html>
+12 -11
View File
@@ -197,9 +197,9 @@ class oAuthServerTokenRequest
*/
public function validatePassword( $username, $password, $scope )
{
$member = NULL;
$accessToken = NULL;
$fails = array();
$fails = [];
$success = FALSE;
$login = new \IPS\Login();
@@ -207,7 +207,10 @@ class oAuthServerTokenRequest
{
try
{
$member = $method->authenticateUsernamePassword( $login, $username, $password );
if( $member = $method->authenticateUsernamePassword( $login, $username, $password ) )
{
$success = TRUE;
}
\IPS\Login::checkIfAccountIsLocked( $member, TRUE );
if ( !$member->isBanned() and !$member->members_bitoptions['validating'] )
@@ -225,18 +228,16 @@ class oAuthServerTokenRequest
}
catch ( \Exception $e ) { }
}
foreach ( $fails as $failedMember )
/* Record any fails if none of the sign-ins were successful */
if( $success === TRUE )
{
if ( !$member or $failedMember->member_id != $failedMember->member_id )
foreach ( $fails as $failedMember )
{
$failedLogins = \is_array( $failedMember->failed_logins ) ? $failedMember->failed_logins : array();
$failedLogins[ \IPS\Request::i()->ipAddress() ][] = time();
$failedMember->failed_logins = $failedLogins;
$failedMember->save();
$failedMember->failedLogin();
}
}
return $accessToken;
}