Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -455,7 +455,8 @@ class oAuthServerAuthorizationRequest
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimalNoHome';
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'oauth_authorize', FALSE, array( 'sprintf' => array( \IPS\Settings::i()->board_name ) ) );
|
||||
\IPS\Output::i()->httpHeaders['X-Frame-Options'] = 'DENY';
|
||||
\IPS\Output::i()->pageCaching = FALSE;
|
||||
\IPS\Output::i()->httpHeaders['Cross-Origin-Opener-Policy'] = 'same-origin';
|
||||
\IPS\Output::setCacheTime( false );
|
||||
|
||||
/* Check we are not banned */
|
||||
if ( \IPS\Request::i()->ipAddressIsBanned() or ( \IPS\Member::loggedIn()->member_id and \IPS\Member::loggedIn()->isBanned() ) )
|
||||
|
||||
@@ -69,53 +69,15 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
|
||||
$destination = $destination->setQueryString( 'code', \IPS\Request::i()->code );
|
||||
}
|
||||
|
||||
|
||||
|
||||
if ( \IPS\Request::i()->requestMethod() === 'POST' )
|
||||
/* If it's a POST request and the URL is quite long, we need to redirect via POST */
|
||||
if ( \IPS\Request::i()->requestMethod() === 'POST')
|
||||
{
|
||||
|
||||
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
|
||||
@header( "Expires: 0" );
|
||||
$queryStringComponents = $destination->queryString;
|
||||
$loading = \IPS\Member::loggedIn()->language()->get('loading');
|
||||
$message = \IPS\Member::loggedIn()->language()->get('oauth_post_redirect_submit');
|
||||
$destination = \IPS\Http\Url::createFromString( @base64_decode( $explodedData[1] ) );
|
||||
$output = <<<HTML
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>{$loading}</title>
|
||||
</head>
|
||||
<body>
|
||||
<noscript>{$message}</noscript>
|
||||
<form style="display: none" action="{$destination}" method="POST">
|
||||
HTML;
|
||||
foreach ( $queryStringComponents as $k => $v )
|
||||
if( empty( $destination->queryString['ref'] ) )
|
||||
{
|
||||
if ( $k === 'ref' )
|
||||
{
|
||||
if ( !$v )
|
||||
{
|
||||
$v = base64_encode( (string) \IPS\Http\Url::baseUrl() );
|
||||
}
|
||||
}
|
||||
$output .= <<<HTML
|
||||
<input name="{$k}" value="{$v}" >
|
||||
HTML;
|
||||
|
||||
$destination = $destination->setQueryString( 'ref', base64_encode( (string) \IPS\Http\Url::baseUrl() ) );
|
||||
}
|
||||
$output .= <<<HTML
|
||||
<input type="submit" value="{$message}" />
|
||||
</form>
|
||||
<script>
|
||||
const form = document.querySelector('form');
|
||||
form.submit();
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
HTML;
|
||||
echo $output;
|
||||
exit;
|
||||
|
||||
\IPS\Output::i()->redirect( $destination, httpStatusCode: 307 );
|
||||
}
|
||||
|
||||
\IPS\Output::i()->redirect( $destination );
|
||||
@@ -127,6 +89,7 @@ HTML;
|
||||
$url = (string) \IPS\Http\Url::internal( 'oauth/callback/', 'none' );
|
||||
|
||||
/* Force no caching */
|
||||
@header( 'Cross-Origin-Opener-Policy: same-origin' );
|
||||
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
|
||||
@header( "Expires: 0" );
|
||||
?><!DOCTYPE html>
|
||||
|
||||
+12
-11
@@ -197,9 +197,9 @@ class oAuthServerTokenRequest
|
||||
*/
|
||||
public function validatePassword( $username, $password, $scope )
|
||||
{
|
||||
$member = NULL;
|
||||
$accessToken = NULL;
|
||||
$fails = array();
|
||||
$fails = [];
|
||||
$success = FALSE;
|
||||
|
||||
$login = new \IPS\Login();
|
||||
|
||||
@@ -207,7 +207,10 @@ class oAuthServerTokenRequest
|
||||
{
|
||||
try
|
||||
{
|
||||
$member = $method->authenticateUsernamePassword( $login, $username, $password );
|
||||
if( $member = $method->authenticateUsernamePassword( $login, $username, $password ) )
|
||||
{
|
||||
$success = TRUE;
|
||||
}
|
||||
\IPS\Login::checkIfAccountIsLocked( $member, TRUE );
|
||||
|
||||
if ( !$member->isBanned() and !$member->members_bitoptions['validating'] )
|
||||
@@ -225,18 +228,16 @@ class oAuthServerTokenRequest
|
||||
}
|
||||
catch ( \Exception $e ) { }
|
||||
}
|
||||
|
||||
foreach ( $fails as $failedMember )
|
||||
|
||||
/* Record any fails if none of the sign-ins were successful */
|
||||
if( $success === TRUE )
|
||||
{
|
||||
if ( !$member or $failedMember->member_id != $failedMember->member_id )
|
||||
foreach ( $fails as $failedMember )
|
||||
{
|
||||
$failedLogins = \is_array( $failedMember->failed_logins ) ? $failedMember->failed_logins : array();
|
||||
$failedLogins[ \IPS\Request::i()->ipAddress() ][] = time();
|
||||
$failedMember->failed_logins = $failedLogins;
|
||||
$failedMember->save();
|
||||
$failedMember->failedLogin();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
return $accessToken;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user