Version 4.1.19
This commit is contained in:
1 parent
28bd025b35
commit
2bd5025018
2674 files changed
+233518
-77766
No files matched your search
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Security Settings
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 11 Jun 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -146,7 +146,7 @@ class _security extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
/* ACP Directory Name */
|
||||
if ( \IPS\CP_DIRECTORY == 'admin' )
|
||||
if ( \IPS\CP_DIRECTORY == 'admin' and !\IPS\CIC )
|
||||
{
|
||||
$content[] = array(
|
||||
'title' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title'),
|
||||
@@ -182,12 +182,38 @@ class _security extends \IPS\Dispatcher\Controller
|
||||
$form = new \IPS\Helpers\Form;
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'security_remove_acp_link', !\IPS\Settings::i()->security_remove_acp_link, FALSE ) );
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) ); //
|
||||
|
||||
if ( !\IPS\CIC )
|
||||
{
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
|
||||
}
|
||||
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) );
|
||||
|
||||
/* If we are overriding IP address checking for the ACP, show a warning */
|
||||
if( \IPS\BYPASS_ACP_IP_CHECK === TRUE )
|
||||
{
|
||||
\IPS\Member::loggedIn()->language()->words['match_ipaddress_warning'] = \IPS\Member::loggedIn()->language()->addToStack('ip_override_warn');
|
||||
}
|
||||
|
||||
/* Password Strength */
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter', \IPS\Settings::i()->password_strength_meter, FALSE, array( 'togglesOn' => array( 'password_strength_meter_enforce' ) ), NULL, NULL, NULL, 'password_strength_meter' ) );
|
||||
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter_enforce', \IPS\Settings::i()->password_strength_meter_enforce, FALSE, array( 'togglesOn' => array( 'password_strength_option' ) ), NULL, NULL, NULL, 'password_strength_meter_enforce' ) );
|
||||
|
||||
$strengthOptions = array(
|
||||
'3' => 'strength_3',
|
||||
'4' => 'strength_4',
|
||||
'5' => 'strength_5',
|
||||
);
|
||||
$form->add( new \IPS\Helpers\Form\Radio( 'password_strength_option', \IPS\Settings::i()->password_strength_option, FALSE, array( 'options' => $strengthOptions ), NULL, NULL, NULL, 'password_strength_option' ) );
|
||||
|
||||
if ( $values = $form->values() )
|
||||
{
|
||||
$values['security_remove_acp_link'] = $values['security_remove_acp_link'] ? FALSE : TRUE;
|
||||
|
||||
/* Disabling the password strength meter should also disable enforcing a strength */
|
||||
$values['password_strength_meter_enforce'] = $values['password_strength_meter'] ? $values['password_strength_meter_enforce'] : FALSE;
|
||||
|
||||
$form->saveAsSettings( $values );
|
||||
|
||||
\IPS\Session::i()->log( 'acplogs__security_settings' );
|
||||
@@ -210,7 +236,7 @@ class _security extends \IPS\Dispatcher\Controller
|
||||
$done = FALSE;
|
||||
|
||||
/* Try... */
|
||||
if ( !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
|
||||
if ( \IPS\NO_WRITES or !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'conf_not_altered', '2C258/2', 500, '' );
|
||||
}
|
||||
@@ -227,11 +253,16 @@ class _security extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function htaccess()
|
||||
{
|
||||
if ( \IPS\NO_WRITES )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_writes', '1C258/7', 403, '' );
|
||||
}
|
||||
|
||||
/* INIT */
|
||||
$errors = array();
|
||||
$deny = <<<EOF
|
||||
#<ipb-protection>
|
||||
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml)">
|
||||
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml|([a-z0-9]{32}))$">
|
||||
Order allow,deny
|
||||
Deny from all
|
||||
</Files>
|
||||
@@ -306,14 +337,19 @@ EOF;
|
||||
*/
|
||||
protected function acpHtaccess()
|
||||
{
|
||||
if ( \IPS\NO_WRITES )
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_writes', '1C258/6', 403, '' );
|
||||
}
|
||||
|
||||
if ( !is_writable( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) )
|
||||
{
|
||||
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'err_not_writable', FALSE, array( 'sprintf' => array( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) ) ), '1C258/5', 403, '' );
|
||||
}
|
||||
|
||||
$form = new \IPS\Helpers\Form;
|
||||
$form->add( new \IPS\Helpers\Form\Text( 'username', NULL, TRUE ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE ) );
|
||||
$form->add( new \IPS\Helpers\Form\Text( 'htaccess_username', NULL, TRUE ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'htaccess_password', NULL, TRUE ) );
|
||||
|
||||
if ( $values = $form->values() )
|
||||
{
|
||||
@@ -325,8 +361,8 @@ EOF;
|
||||
. 'AuthUserFile "' . \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . "/.htpasswd\"\n"
|
||||
. "Require valid-user\n";
|
||||
|
||||
$htaccess_pw = $values['username'] . ":" .
|
||||
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['password'] : crypt( $values['password'], base64_encode( $values['password'] ) ) );
|
||||
$htaccess_pw = $values['htaccess_username'] . ":" .
|
||||
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['htaccess_password'] : crypt( $values['htaccess_password'], base64_encode( $values['htaccess_password'] ) ) );
|
||||
|
||||
if ( $FH = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htpasswd', 'w' ) )
|
||||
{
|
||||
@@ -340,6 +376,7 @@ EOF;
|
||||
$done = TRUE;
|
||||
|
||||
\IPS\Session::i()->log( 'acplogs__security_acp_password' );
|
||||
\IPS\IPS::resyncIPSCloud();
|
||||
}
|
||||
|
||||
/* All Done */
|
||||
|
||||
Reference in new issue
Block a user