Version 4.1.19

This commit is contained in:
Neo committed 2025-12-19 05:38:56 -08:00
1 parent 28bd025b35
commit 2bd5025018
2674 files changed
+233518 -77766

No files matched your search

+68 -38
View File
@@ -2,9 +2,9 @@
/**
* @brief Admin CP Dispatcher
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @package IPS Community Suite
* @since 18 Feb 2013
* @version SVN_VERSION_NUMBER
*/
@@ -116,7 +116,45 @@ class _Admin extends \IPS\Dispatcher\Standard
}
}
/* Check we're logged in and we have ACP access */
if( ( !\IPS\Member::loggedIn()->member_id or !\IPS\Member::loggedIn()->isAdmin() )
and ( \IPS\Request::i()->module !== 'system' or \IPS\Request::i()->controller !== 'login' )
and ( !\IPS\ENFORCE_ACCESS )
)
{
/* Make sure the right protocol is used. IIS, for example, does not like protocol relative URL's in redirects. (Ref: 970629) */
$protocol = \IPS\Http\Url::PROTOCOL_HTTP;
if ( \IPS\Settings::i()->logins_over_https OR \substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' )
{
$protocol = \IPS\Http\Url::PROTOCOL_HTTPS;
}
$url = \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'admin', NULL, array(), $protocol );
if ( \IPS\Session::i()->error )
{
$url = $url->setQueryString( 'error', \IPS\Session::i()->error->getMessage() );
}
if( !\IPS\Request::i()->isAjax() )
{
/* If someone calls this from command line, while it wouldn't work, the key won't be set */
if( isset( $_SERVER['QUERY_STRING'] ) )
{
$url = $url->setQueryString( 'ref', base64_encode( preg_replace( '!adsess=((\w){32}|&)!', "", $_SERVER['QUERY_STRING'] ) ) );
}
}
else if( isset( $_SERVER['HTTP_REFERER'] ) )
{
$previous = preg_replace( "/^(.+?)\/\?/", "", $_SERVER['HTTP_REFERER'] );
$url = $url->setQueryString( 'ref', base64_encode( preg_replace( '!adsess=.*?(&|$)!', "", $previous ) ) );
}
\IPS\Output::i()->redirect( $url );
}
/* Init */
try
{
parent::init();
@@ -126,30 +164,10 @@ class _Admin extends \IPS\Dispatcher\Standard
\IPS\Output::i()->error( $e->getMessage(), '2S100/' . $e->getCode(), $e->getCode() === 4 ? 403 : 404, '' );
}
/* Check we're logged in and we have ACP access */
if( ( !\IPS\Member::loggedIn()->member_id or !\IPS\Member::loggedIn()->isAdmin() )
and ( $this->module->key !== 'system' or $this->controller !== 'login' )
and ( !\IPS\ENFORCE_ACCESS )
)
/* If we are in recovery mode, but not actually doing the recovery process, or logging in, then we need them to remove the constant */
if ( \IPS\RECOVERY_MODE === TRUE AND !in_array( $this->controller, array( 'recovery', 'login' ) ) )
{
$url = \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'admin', NULL, array(), \IPS\Settings::i()->logins_over_https );
if ( \IPS\Session::i()->error )
{
$url = $url->setQueryString( 'error', \IPS\Session::i()->error->getMessage() );
}
if( !\IPS\Request::i()->isAjax() )
{
$url = $url->setQueryString( 'ref', base64_encode( preg_replace( '!adsess=((\w){32}|&)!', "", $_SERVER['QUERY_STRING'] ) ) );
}
else if( isset( $_SERVER['HTTP_REFERER'] ) )
{
$previous = preg_replace( "/^(.+?)\/\?/", "", $_SERVER['HTTP_REFERER'] );
$url = $url->setQueryString( 'ref', base64_encode( preg_replace( '!adsess=.*?(&|$)!', "", $previous ) ) );
}
\IPS\Output::i()->redirect( $url );
\IPS\Output::i()->error( 'recovery_mode_remove_constant', '1S107/3', 403, '' );
}
/* Permission Check */
@@ -227,7 +245,7 @@ class _Admin extends \IPS\Dispatcher\Standard
{
$currentTab = $this->application->directory;
}
/* Display */
if( $this->controller !== 'login' )
{
@@ -250,6 +268,8 @@ class _Admin extends \IPS\Dispatcher\Standard
*/
public function buildMenu( $rebuild=FALSE )
{
$acpTabOrder = $this->_getAcpTabOrder();
if ( $this->menu === NULL or $rebuild === TRUE )
{
$this->menu = array( 'tabs' => array(), 'defaults' => array() );
@@ -258,13 +278,25 @@ class _Admin extends \IPS\Dispatcher\Standard
{
if ( \IPS\Application::appIsEnabled( $app->directory ) and \IPS\Application::load( $app->directory )->canAccess() )
{
foreach ( $app->acpMenu() as $moduleKey => $items )
$appMenu = $app->acpMenu();
if ( $acpTabOrder !== NULL and isset( $acpTabOrder[ $app->directory ] ) and $app->directory == 'nexus' )
{
if ( \IPS\Member::loggedIn()->hasAcpRestriction( $app, $moduleKey ) )
{
foreach ( $items as $itemKey => $item )
{
if ( !$item['restriction'] or \IPS\Member::loggedIn()->hasAcpRestriction( $app, $moduleKey, $item['restriction'] ) )
uksort( $appMenu, function( $a, $b ) use ( $acpTabOrder, $app )
{
return array_search( "{$app->directory}_{$a}", $acpTabOrder[ $app->directory ] ) - array_search( "{$app->directory}_{$b}", $acpTabOrder[ $app->directory ] );
} );
}
foreach ( $appMenu as $moduleKey => $items )
{
foreach ( $items as $itemKey => $item )
{
$moduleToCheck = ( isset( $item['restriction_module'] ) ) ? $item['restriction_module'] : $moduleKey;
if ( \IPS\Member::loggedIn()->hasAcpRestriction( $app, $moduleToCheck ) )
{
if ( !$item['restriction'] or \IPS\Member::loggedIn()->hasAcpRestriction( $app, $moduleToCheck, $item['restriction'] ) )
{
if ( !isset( $this->menu['defaults'][ $item['tab'] ] ) )
{
@@ -278,9 +310,7 @@ class _Admin extends \IPS\Dispatcher\Standard
}
}
}
}
$acpTabOrder = $this->_getAcpTabOrder();
}
if ( $acpTabOrder !== NULL )
{
@@ -344,8 +374,8 @@ class _Admin extends \IPS\Dispatcher\Standard
$this->acpTabOrder = json_decode( \IPS\Db::i()->select( 'data', 'core_acp_tab_order', array( 'id=?', \IPS\Member::loggedIn()->member_id ) )->first(), TRUE );
}
catch( \UnderflowException $ex )
{
$this->acpTabOrder = array( 'core' => array(), 'community' => array(), 'members' => array(), 'nexus' => array(), 'content' => array(), 'stats' => array(), 'customization' => array() );
{
$this->acpTabOrder = array( 'core' => array(), 'community' => array(), 'members' => array(), 'nexus' => array(), 'cms' => array(), 'stats' => array(), 'customization' => array() );
}
\IPS\Request::i()->setCookie( 'acpTabs', json_encode( $this->acpTabOrder ) );
@@ -378,7 +408,7 @@ class _Admin extends \IPS\Dispatcher\Standard
{
if ( !\IPS\Member::loggedIn()->hasAcpRestriction( ( $app ?: $this->application ), ( $module ?: $this->module ), $key ) )
{
\IPS\Output::i()->error( 'no_module_permission', '2S107/1', 403, '' );
\IPS\Output::i()->error( 'no_module_permission', '2S107/2', 403, '' );
}
}
}