Version 4.1.19

This commit is contained in:
Neo committed 2025-12-19 05:38:56 -08:00
1 parent 28bd025b35
commit 2bd5025018
2674 files changed
+233518 -77766

No files matched your search

+102 -24
View File
@@ -2,9 +2,9 @@
/**
* @brief Admin CP Login
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @package IPS Community Suite
* @since 13 Mar 2013
* @version SVN_VERSION_NUMBER
*/
@@ -55,28 +55,7 @@ class _login extends \IPS\Dispatcher\Controller
/* Success */
if ( $member->isAdmin() )
{
/* Set the member */
\IPS\Session::i()->setMember( $member );
/* Log */
$this->log( 'ok' );
/* Clean out any existing session ID in the URL */
$queryString = array();
if( isset( \IPS\Request::i()->ref ) )
{
$_queryString = array();
parse_str( preg_replace( "/adsess=([a-zA-Z0-9]+)(?:&|$)/", '', base64_decode( \IPS\Request::i()->ref ) ), $_queryString );
foreach ( $_queryString as $k => $v )
{
if ( in_array( $k, array( 'app', 'module', 'controller' ) ) )
{
$queryString[ $k ] = $v;
}
}
}
/* Boink */
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( http_build_query( $queryString ) ) );
$this->_doLogin( $member );
}
/* Error */
else
@@ -134,6 +113,105 @@ class _login extends \IPS\Dispatcher\Controller
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'system' )->login( $forms, $this->activeTab, $error, $icons, $upgradeError ) );
}
/**
* MFA
*
* @return void
*/
protected function mfa()
{
/* Have we logged in? */
$member = NULL;
if ( isset( $_SESSION['processing2FA'] ) )
{
$member = \IPS\Member::load( $_SESSION['processing2FA']['memberId'] );
}
if ( !$member->member_id )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '', 'admin' ) );
}
/* Set the referer in the URL */
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'admin', 'login' );
if ( isset( \IPS\Request::i()->ref ) )
{
$url = $url->setQueryString( 'ref', \IPS\Request::i()->ref );
}
if ( isset( \IPS\Request::i()->auth ) )
{
$url = $url->setQueryString( 'auth', \IPS\Request::i()->auth );
}
/* Have we already done 2FA? */
$output = \IPS\MFA\MFAHandler::accessToArea( 'core', 'AuthenticateAdmin', $url, $member );
if ( !$output )
{
$this->_doLogin( $member, TRUE );
}
/* Nope, displau the 2FA form over the login page */
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'system/login.css', 'core', 'admin' ) );
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'system' )->mfaLogin( $output ) );
}
/**
* Process log in
*
* @param \IPS\Member $member The member
* @param bool $bypass2FA If true, will not perform 2FA check
* @return void
*/
protected function _doLogin( $member, $bypass2FA = FALSE )
{
/* Do we need to do 2FA? */
if ( !$bypass2FA and $output = \IPS\MFA\MFAHandler::accessToArea( 'core', 'AuthenticateAdmin', \IPS\Http\Url::internal( '' ), $member ) )
{
$_SESSION['processing2FA'] = array( 'memberId' => $member->member_id );
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'admin', 'login' );
if ( isset( \IPS\Request::i()->ref ) )
{
$url = $url->setQueryString( 'ref', \IPS\Request::i()->ref );
}
if ( isset( \IPS\Request::i()->auth ) )
{
$url = $url->setQueryString( 'auth', \IPS\Request::i()->auth );
}
\IPS\Output::i()->redirect( $url );
}
/* Set the member */
\IPS\Session::i()->setMember( $member );
/* Log */
$this->log( 'ok' );
/* Clean out any existing session ID in the URL */
$queryString = array();
if( isset( \IPS\Request::i()->ref ) )
{
$_queryString = array();
parse_str( preg_replace( "/adsess=([a-zA-Z0-9]+)(?:&|$)/", '', base64_decode( \IPS\Request::i()->ref ) ), $_queryString );
foreach ( $_queryString as $k => $v )
{
if ( in_array( $k, array( 'app', 'module', 'controller', 'id' ) ) )
{
$queryString[ $k ] = $v;
}
}
}
/* Boink - if we're in recovery mode, go there */
if ( \IPS\RECOVERY_MODE === TRUE )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=support&controller=recovery" ), '', 303 );
}
else
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( http_build_query( $queryString ) ), '', 303 );
}
}
/**
* Log Out
*