Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -169,7 +169,8 @@ abstract class _Handler extends \IPS\Node\Model
|
||||
if ( !isset( $this->_cachedLinks[ $member->member_id ] ) )
|
||||
{
|
||||
try
|
||||
{
|
||||
{
|
||||
/* @note SELECT_FROM_WRITE_SERVER Added in 2e3846f8e6e50b0fc89f18ada73539e7034c5290 "Read/Write Separation issue with OAuth logins" */
|
||||
$this->_cachedLinks[ $member->member_id ] = \IPS\Db::i()->select( '*', 'core_login_links', array( 'token_login_method=? AND token_member=? AND token_linked=1', $this->id, $member->member_id ), NULL, NULL, NULL, NULL, \IPS\Db::SELECT_FROM_WRITE_SERVER )->first();
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
@@ -458,7 +459,11 @@ abstract class _Handler extends \IPS\Node\Model
|
||||
* @return bool
|
||||
*/
|
||||
public function showInUcp( \IPS\Member $member = NULL )
|
||||
{
|
||||
{
|
||||
if( !$this->enabled )
|
||||
{
|
||||
return FALSE ;
|
||||
}
|
||||
if ( isset( $this->settings['show_in_ucp'] ) )
|
||||
{
|
||||
switch ( $this->settings['show_in_ucp'] )
|
||||
@@ -966,7 +971,7 @@ abstract class _Handler extends \IPS\Node\Model
|
||||
public function save()
|
||||
{
|
||||
parent::save();
|
||||
unset( \IPS\Data\Store::i()->loginMethods );
|
||||
unset( \IPS\Data\Store::i()->loginMethods, \IPS\Data\Store::i()->essentialCookieNames );
|
||||
\IPS\Data\Cache::i()->clearAll();
|
||||
}
|
||||
|
||||
|
||||
@@ -481,11 +481,13 @@ abstract class _OAuth1 extends \IPS\Login\Handler
|
||||
*/
|
||||
public function showInUcp( \IPS\Member $member = NULL )
|
||||
{
|
||||
if ( !isset( $this->settings['show_in_ucp'] ) )
|
||||
$return = parent::showInUcp( $member );
|
||||
|
||||
if ( $return AND !isset( $this->settings['show_in_ucp'] ) )
|
||||
{
|
||||
return TRUE; // Default to showing
|
||||
}
|
||||
return parent::showInUcp( $member );
|
||||
return $return;
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -21,12 +21,7 @@ if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
* Twitter Login Handler
|
||||
*/
|
||||
class _Twitter extends \IPS\Login\Handler\OAuth1
|
||||
{
|
||||
/**
|
||||
* @brief Share Service
|
||||
*/
|
||||
public static $shareService = 'Twitter';
|
||||
|
||||
{
|
||||
/**
|
||||
* Get title
|
||||
*
|
||||
@@ -78,7 +73,7 @@ class _Twitter extends \IPS\Login\Handler\OAuth1
|
||||
*/
|
||||
public function buttonColor()
|
||||
{
|
||||
return '#00abf0';
|
||||
return '#000000';
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -119,7 +114,7 @@ class _Twitter extends \IPS\Login\Handler\OAuth1
|
||||
*/
|
||||
public function logoForDeviceInformation()
|
||||
{
|
||||
return \IPS\Theme::i()->resource( 'logos/login/Twitter.png', 'core', 'interface' );
|
||||
return \IPS\Theme::i()->resource( 'logos/login/X.png', 'core', 'interface' );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -290,7 +285,7 @@ class _Twitter extends \IPS\Login\Handler\OAuth1
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Get user's statuses since a particular date
|
||||
*
|
||||
|
||||
@@ -188,8 +188,9 @@ abstract class _OAuth2 extends \IPS\Login\Handler
|
||||
|
||||
if ( $this->grantType() === 'authorization_code' AND $this->pkceSupported === TRUE )
|
||||
{
|
||||
$_SESSION['codeVerifier'] = \IPS\Login::generateRandomString( 128 );
|
||||
$data['code_challenge'] = rtrim( strtr( base64_encode( pack( 'H*', hash( 'sha256', $_SESSION['codeVerifier'] ) ) ), '+/', '-_' ), '=' );
|
||||
$codeChallenge = \IPS\Login::generateRandomString( 128 );
|
||||
\IPS\Request::i()->setCookie('codeVerifier', $codeChallenge, ( new \IPS\DateTime )->add( new \DateInterval( 'PT10M' ) ) );
|
||||
$data['code_challenge'] = rtrim( strtr( base64_encode( pack( 'H*', hash( 'sha256', $codeChallenge ) ) ), '+/', '-_' ), '=' );
|
||||
$data['code_challenge_method'] = 'S256';
|
||||
}
|
||||
|
||||
@@ -588,13 +589,13 @@ abstract class _OAuth2 extends \IPS\Login\Handler
|
||||
|
||||
if( $this->pkceSupported === TRUE )
|
||||
{
|
||||
$post['code_verifier'] = $_SESSION['codeVerifier'];
|
||||
$post['code_verifier'] = \IPS\Request::i()->cookie['codeVerifier'] ?: NULL;
|
||||
}
|
||||
|
||||
$data = $this->_authenticatedRequest( $this->tokenEndpoint(), $post );
|
||||
|
||||
$response = $data->decodeJson();
|
||||
unset( $_SESSION['codeVerifier'] );
|
||||
\IPS\Request::i()->setCookie('codeVerifier', NULL );
|
||||
}
|
||||
catch( \RuntimeException $e )
|
||||
{
|
||||
@@ -845,11 +846,13 @@ abstract class _OAuth2 extends \IPS\Login\Handler
|
||||
*/
|
||||
public function showInUcp( \IPS\Member $member = NULL )
|
||||
{
|
||||
if ( !isset( $this->settings['show_in_ucp'] ) ) // Default to showing
|
||||
$return = parent::showInUcp( $member );
|
||||
|
||||
if ( $return and !isset( $this->settings['show_in_ucp'] ) ) // Default to showing
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
return parent::showInUcp( $member );
|
||||
return $return;
|
||||
}
|
||||
|
||||
|
||||
|
||||
+17
-20
@@ -293,10 +293,7 @@ class _Login
|
||||
{
|
||||
if ( !$success or $success->member->member_id != $failedMember->member_id )
|
||||
{
|
||||
$failedLogins = \is_array( $failedMember->failed_logins ) ? $failedMember->failed_logins : array();
|
||||
$failedLogins[ \IPS\Request::i()->ipAddress() ][] = time();
|
||||
$failedMember->failed_logins = $failedLogins;
|
||||
$failedMember->save();
|
||||
$failedMember->failedLogin();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -304,17 +301,7 @@ class _Login
|
||||
{
|
||||
if ( !$success or $success->member->email != $failedMember->email )
|
||||
{
|
||||
try
|
||||
{
|
||||
$failedLogins = \is_array( \IPS\Data\Store::i()->failedLogins ) ? \IPS\Data\Store::i()->failedLogins : array();
|
||||
}
|
||||
catch( \OutOfRangeException $e )
|
||||
{
|
||||
$failedLogins = array();
|
||||
}
|
||||
|
||||
$failedLogins[ $failedMember->email ][ \IPS\Request::i()->ipAddress() ][] = time();
|
||||
\IPS\Data\Store::i()->failedLogins = $failedLogins;
|
||||
$failedMember->failedLogin();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -396,6 +383,19 @@ class _Login
|
||||
*/
|
||||
public static function checkIfAccountIsLocked( $member, $success = FALSE )
|
||||
{
|
||||
/* Global attempts */
|
||||
if( \IPS\Settings::i()->bruteforce_global_attempts )
|
||||
{
|
||||
$fromTimestamp = ( new \IPS\DateTime )->sub( new \DateInterval( 'PT' . \IPS\Settings::i()->bruteforce_global_period .'M' ) )->getTimestamp();
|
||||
$globalFailures = \IPS\Db::i()->select( 'count(*) as total', 'core_login_failures', [ 'login_date>? AND login_ip_address=?', $fromTimestamp, \IPS\Request::i()->ipAddress() ] )->first();
|
||||
|
||||
/* Potential password-spraying activity */
|
||||
if( $globalFailures >= (int) \IPS\Settings::i()->bruteforce_global_attempts )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'login_err_locked_nounlock', \IPS\Login\Exception::ACCOUNT_LOCKED );
|
||||
}
|
||||
}
|
||||
|
||||
$unlockTime = $member->unlockTime();
|
||||
if ( $unlockTime !== FALSE )
|
||||
{
|
||||
@@ -415,7 +415,7 @@ class _Login
|
||||
if( $member->member_id )
|
||||
{
|
||||
\IPS\Email::buildFromTemplate( 'core', 'account_locked', array( $member, $location, isset( $unlockTime ) ? $unlockTime : NULL ), \IPS\Email::TYPE_TRANSACTIONAL )->send( $member );
|
||||
$member->logHistory( 'core', 'login', array( 'type' => 'lock', 'count' => \count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ), 'unlockTime' => isset( $unlockTime ) ? $unlockTime->getTimestamp() : NULL ) );
|
||||
$member->logHistory( 'core', 'login', array( 'type' => 'lock', 'count' => $member->failedLoginCount( \IPS\Request::i()->ipAddress() ), 'unlockTime' => isset( $unlockTime ) ? $unlockTime->getTimestamp() : NULL ) );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -432,10 +432,7 @@ class _Login
|
||||
}
|
||||
elseif ( $success )
|
||||
{
|
||||
$failedLogins = \is_array( $member->failed_logins ) ? $member->failed_logins : array();
|
||||
unset( $failedLogins[ \IPS\Request::i()->ipAddress() ] );
|
||||
$member->failed_logins = $failedLogins;
|
||||
$member->save();
|
||||
\IPS\Db::i()->delete( 'core_login_failures', [ 'login_member_id=? AND login_ip_address=?', $member->member_id, \IPS\Request::i()->ipAddress() ] );
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user