Version 4.1.19

This commit is contained in:
Neo committed 2025-12-19 05:38:56 -08:00
1 parent 28bd025b35
commit 2bd5025018
2674 files changed
+233518 -77766

No files matched your search

@@ -2,9 +2,9 @@
/**
* @brief Security Settings
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @package IPS Community Suite
* @since 11 Jun 2013
* @version SVN_VERSION_NUMBER
*/
@@ -146,7 +146,7 @@ class _security extends \IPS\Dispatcher\Controller
}
/* ACP Directory Name */
if ( \IPS\CP_DIRECTORY == 'admin' )
if ( \IPS\CP_DIRECTORY == 'admin' and !\IPS\CIC )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title'),
@@ -182,12 +182,38 @@ class _security extends \IPS\Dispatcher\Controller
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\YesNo( 'security_remove_acp_link', !\IPS\Settings::i()->security_remove_acp_link, FALSE ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) ); //
if ( !\IPS\CIC )
{
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
}
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) );
/* If we are overriding IP address checking for the ACP, show a warning */
if( \IPS\BYPASS_ACP_IP_CHECK === TRUE )
{
\IPS\Member::loggedIn()->language()->words['match_ipaddress_warning'] = \IPS\Member::loggedIn()->language()->addToStack('ip_override_warn');
}
/* Password Strength */
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter', \IPS\Settings::i()->password_strength_meter, FALSE, array( 'togglesOn' => array( 'password_strength_meter_enforce' ) ), NULL, NULL, NULL, 'password_strength_meter' ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter_enforce', \IPS\Settings::i()->password_strength_meter_enforce, FALSE, array( 'togglesOn' => array( 'password_strength_option' ) ), NULL, NULL, NULL, 'password_strength_meter_enforce' ) );
$strengthOptions = array(
'3' => 'strength_3',
'4' => 'strength_4',
'5' => 'strength_5',
);
$form->add( new \IPS\Helpers\Form\Radio( 'password_strength_option', \IPS\Settings::i()->password_strength_option, FALSE, array( 'options' => $strengthOptions ), NULL, NULL, NULL, 'password_strength_option' ) );
if ( $values = $form->values() )
{
$values['security_remove_acp_link'] = $values['security_remove_acp_link'] ? FALSE : TRUE;
/* Disabling the password strength meter should also disable enforcing a strength */
$values['password_strength_meter_enforce'] = $values['password_strength_meter'] ? $values['password_strength_meter_enforce'] : FALSE;
$form->saveAsSettings( $values );
\IPS\Session::i()->log( 'acplogs__security_settings' );
@@ -210,7 +236,7 @@ class _security extends \IPS\Dispatcher\Controller
$done = FALSE;
/* Try... */
if ( !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
if ( \IPS\NO_WRITES or !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
{
\IPS\Output::i()->error( 'conf_not_altered', '2C258/2', 500, '' );
}
@@ -227,11 +253,16 @@ class _security extends \IPS\Dispatcher\Controller
*/
protected function htaccess()
{
if ( \IPS\NO_WRITES )
{
\IPS\Output::i()->error( 'no_writes', '1C258/7', 403, '' );
}
/* INIT */
$errors = array();
$deny = <<<EOF
#<ipb-protection>
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml)">
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml|([a-z0-9]{32}))$">
Order allow,deny
Deny from all
</Files>
@@ -306,14 +337,19 @@ EOF;
*/
protected function acpHtaccess()
{
if ( \IPS\NO_WRITES )
{
\IPS\Output::i()->error( 'no_writes', '1C258/6', 403, '' );
}
if ( !is_writable( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'err_not_writable', FALSE, array( 'sprintf' => array( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) ) ), '1C258/5', 403, '' );
}
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Text( 'username', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Text( 'htaccess_username', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Password( 'htaccess_password', NULL, TRUE ) );
if ( $values = $form->values() )
{
@@ -325,8 +361,8 @@ EOF;
. 'AuthUserFile "' . \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . "/.htpasswd\"\n"
. "Require valid-user\n";
$htaccess_pw = $values['username'] . ":" .
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['password'] : crypt( $values['password'], base64_encode( $values['password'] ) ) );
$htaccess_pw = $values['htaccess_username'] . ":" .
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['htaccess_password'] : crypt( $values['htaccess_password'], base64_encode( $values['htaccess_password'] ) ) );
if ( $FH = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htpasswd', 'w' ) )
{
@@ -340,6 +376,7 @@ EOF;
$done = TRUE;
\IPS\Session::i()->log( 'acplogs__security_acp_password' );
\IPS\IPS::resyncIPSCloud();
}
/* All Done */