Version 4.1.19
This commit is contained in:
1 parent
28bd025b35
commit
2bd5025018
2674 files changed
+233518
-77766
No files matched your search
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Admin Session Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 11 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -74,14 +74,13 @@ class _Admin extends \IPS\Session
|
||||
}
|
||||
|
||||
/* Check IP address */
|
||||
if ( \IPS\Settings::i()->match_ipaddress and $session['session_ip_address'] !== \IPS\Request::i()->ipAddress() )
|
||||
if ( ( defined( '\IPS\BYPASS_ACP_IP_CHECK' ) and !\IPS\BYPASS_ACP_IP_CHECK ) and \IPS\Settings::i()->match_ipaddress and $session['session_ip_address'] !== \IPS\Request::i()->ipAddress() )
|
||||
{
|
||||
throw new \DomainException('BAD_IP');
|
||||
}
|
||||
|
||||
/* Return data */
|
||||
return $session['session_app_data'];
|
||||
|
||||
}
|
||||
catch ( \Exception $e )
|
||||
{
|
||||
@@ -179,6 +178,7 @@ class _Admin extends \IPS\Session
|
||||
|
||||
\IPS\Db::i()->insert( 'core_admin_logs', array(
|
||||
'member_id' => $this->member->member_id,
|
||||
'member_name' => \IPS\Member::loggedIn()->name,
|
||||
'ctime' => time(),
|
||||
'note' => json_encode( $params ),
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
|
||||
+81
-64
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Front Session Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 11 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -27,6 +27,7 @@ class _Front extends \IPS\Session
|
||||
const LOGIN_TYPE_ANONYMOUS = 1;
|
||||
const LOGIN_TYPE_GUEST = 2;
|
||||
const LOGIN_TYPE_SPIDER = 3;
|
||||
const LOGIN_TYPE_INCOMPLETE = 4;
|
||||
|
||||
/**
|
||||
* Guess if the user is logged in
|
||||
@@ -74,50 +75,41 @@ class _Front extends \IPS\Session
|
||||
*/
|
||||
public function read( $sessionId )
|
||||
{
|
||||
$session = NULL;
|
||||
$session = NULL;
|
||||
|
||||
/* Get user agent info */
|
||||
$this->userAgent = \IPS\Http\Useragent::parse();
|
||||
|
||||
/* Check the cache */
|
||||
$key = "session_{$sessionId}";
|
||||
if ( isset( \IPS\Data\Cache::i()->$key ) )
|
||||
/* Get from the database */
|
||||
try
|
||||
{
|
||||
$session = \IPS\Data\Cache::i()->$key;
|
||||
}
|
||||
/* Not in cache, check the database */
|
||||
else
|
||||
{
|
||||
try
|
||||
/* If it looks like we're logged in, join the member row to save a query later */
|
||||
if ( static::loggedIn() )
|
||||
{
|
||||
/* If it looks like we're logged in, join the member row to save a query later */
|
||||
if ( static::loggedIn() )
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ), NULL, NULL, NULL, NULL, \IPS\Db::SELECT_MULTIDIMENSIONAL_JOINS )->join( 'core_members', 'core_members.member_id=core_sessions.member_id' )->first();
|
||||
if ( $session['core_members']['member_id'] )
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ), NULL, NULL, NULL, NULL, \IPS\Db::SELECT_MULTIDIMENSIONAL_JOINS )->join( 'core_members', 'core_members.member_id=core_sessions.member_id' )->first();
|
||||
if ( $session['core_members']['member_id'] )
|
||||
{
|
||||
\IPS\Member::constructFromData( $session['core_members'], FALSE );
|
||||
}
|
||||
$session = $session['core_sessions'];
|
||||
\IPS\Member::constructFromData( $session['core_members'], FALSE );
|
||||
}
|
||||
/* If we're not logged in, just look at the session */
|
||||
$session = $session['core_sessions'];
|
||||
}
|
||||
/* If we're not logged in, just look at the session */
|
||||
else
|
||||
{
|
||||
/* Spiders match by IP and useragent */
|
||||
if ( $this->userAgent->spider )
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=? OR ( ip_address=? AND browser=? )', $sessionId, \IPS\Request::i()->ipAddress(), $_SERVER['HTTP_USER_AGENT'] ) )->first();
|
||||
$sessionId = $session['id'];
|
||||
}
|
||||
/* Normal users don't */
|
||||
else
|
||||
{
|
||||
/* Spiders match by IP and useragent */
|
||||
if ( $this->userAgent->spider )
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=? OR ( ip_address=? AND browser=? )', $sessionId, \IPS\Request::i()->ipAddress(), $_SERVER['HTTP_USER_AGENT'] ) )->first();
|
||||
$sessionId = $session['id'];
|
||||
}
|
||||
/* Normal users don't */
|
||||
else
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ) )->first();
|
||||
}
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ) )->first();
|
||||
}
|
||||
}
|
||||
catch ( \UnderflowException $e ) { }
|
||||
}
|
||||
catch ( \UnderflowException $e ) { }
|
||||
|
||||
/* Only use sessions with matching IP address */
|
||||
if( \IPS\Settings::i()->match_ipaddress and $session['ip_address'] != \IPS\Request::i()->ipAddress() )
|
||||
@@ -127,7 +119,7 @@ class _Front extends \IPS\Session
|
||||
|
||||
/* Store this so plugins can access */
|
||||
$this->sessionData = $session;
|
||||
|
||||
|
||||
/* Got one? */
|
||||
if ( $session )
|
||||
{
|
||||
@@ -159,15 +151,20 @@ class _Front extends \IPS\Session
|
||||
try
|
||||
{
|
||||
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
|
||||
if ( $member->member_login_key === \IPS\Request::i()->cookie['pass_hash'] )
|
||||
if ( $member->member_login_key AND \IPS\Request::i()->cookie['pass_hash'] AND \IPS\Login::compareHashes( (string) $member->member_login_key, (string) \IPS\Request::i()->cookie['pass_hash'] ) )
|
||||
{
|
||||
$this->member = $member;
|
||||
|
||||
/* Renew those cookies */
|
||||
$expire = new \IPS\DateTime;
|
||||
$expire->add( new \DateInterval( 'P7D' ) );
|
||||
$expire->add( new \DateInterval( 'P3M' ) );
|
||||
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', $member->member_login_key, $expire );
|
||||
|
||||
if( isset( \IPS\Request::i()->cookie['anon_login'] ) and \IPS\Request::i()->cookie['anon_login'] )
|
||||
{
|
||||
\IPS\Request::i()->setCookie( 'anon_login', 1, $expire );
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -191,6 +188,10 @@ class _Front extends \IPS\Session
|
||||
{
|
||||
$type = static::LOGIN_TYPE_ANONYMOUS;
|
||||
}
|
||||
else if ( ! $this->member->name or ! $this->member->email )
|
||||
{
|
||||
$type = static::LOGIN_TYPE_INCOMPLETE;
|
||||
}
|
||||
else
|
||||
{
|
||||
$type = static::LOGIN_TYPE_MEMBER;
|
||||
@@ -200,7 +201,7 @@ class _Front extends \IPS\Session
|
||||
{
|
||||
$type = $this->userAgent->spider ? static::LOGIN_TYPE_SPIDER : static::LOGIN_TYPE_GUEST;
|
||||
}
|
||||
|
||||
|
||||
/* Set data */
|
||||
$this->data = array(
|
||||
'id' => $sessionId,
|
||||
@@ -209,19 +210,21 @@ class _Front extends \IPS\Session
|
||||
'member_id' => $this->member->member_id ?: 0,
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
'browser' => isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : '',
|
||||
'running_time' => time(),
|
||||
/* We do not want ajax calls to update running time as this affects appearance of being online. If no session exists, we do not want ajax polling to trigger an online list hit so we set running time for time - 31 minutes as
|
||||
online lists look for running times less than 30 minutes. */
|
||||
'running_time' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['running_time'] : time() - 1860 ) : time(),
|
||||
'login_type' => $type,
|
||||
'member_group' => ( $this->member->member_id ) ? $this->member->member_group_id : \IPS\Settings::i()->guest_group,
|
||||
'current_appcomponent' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_appcomponent'] : '' ) : '',
|
||||
'current_module' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_module'] : '' ) : '',
|
||||
'current_controller' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_controller'] : NULL ) : NULL,
|
||||
'current_id' => intval( \IPS\Request::i()->id ),
|
||||
'current_id' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_id'] : NULL ) : intval( \IPS\Request::i()->id ),
|
||||
'uagent_key' => $this->userAgent->useragentKey,
|
||||
'uagent_version' => $this->userAgent->useragentVersion ?: '',
|
||||
'uagent_type' => $this->userAgent->spider ? 'search' : 'browser',
|
||||
'search_thread_id' => $session ? $session['search_thread_id'] : 0,
|
||||
'search_thread_id' => $session ? intval( $session['search_thread_id'] ) : 0,
|
||||
'search_thread_time' => $session ? $session['search_thread_time'] : 0,
|
||||
'data' => $session ? $session['data'] : NULL,
|
||||
'data' => $session ? $session['data'] : '',
|
||||
'location_url' => $session ? $session['location_url'] : NULL,
|
||||
'location_lang' => $session ? $session['location_lang'] : NULL,
|
||||
'location_data' => $session ? $session['location_data'] : NULL,
|
||||
@@ -245,7 +248,8 @@ class _Front extends \IPS\Session
|
||||
}
|
||||
}
|
||||
|
||||
return $this->data['data'];
|
||||
/* Session read() method MUST return a string, or this can result in PHP errors */
|
||||
return (string) $this->data['data'];
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -263,7 +267,7 @@ class _Front extends \IPS\Session
|
||||
|
||||
/* Set the cookie */
|
||||
$expire = new \IPS\DateTime;
|
||||
$expire->add( new \DateInterval( 'P7D' ) );
|
||||
$expire->add( new \DateInterval( 'P3M' ) );
|
||||
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
|
||||
|
||||
/* Make sure session handler saves during write() */
|
||||
@@ -284,14 +288,17 @@ class _Front extends \IPS\Session
|
||||
$this->save = TRUE;
|
||||
}
|
||||
|
||||
/* Don't update if instant notifications are checking to reduce overhead on the session table */
|
||||
if ( \IPS\Request::i()->isAjax() and isset( \IPS\Request::i()->app ) and \IPS\Request::i()->app === 'core' and isset( \IPS\Request::i()->controller ) and \IPS\Request::i()->controller === 'ajax' and isset( \IPS\Request::i()->do ) and \IPS\Request::i()->do === 'instantNotifications' )
|
||||
{
|
||||
$this->save = FALSE;
|
||||
}
|
||||
|
||||
$this->data['member_name'] = $this->member->member_id ? $this->member->name : '';
|
||||
$this->data['member_id'] = $this->member->member_id ?: NULL;
|
||||
$this->data['data'] = $data;
|
||||
$this->setLocationData();
|
||||
|
||||
$key = "session_{$sessionId}";
|
||||
\IPS\Data\Cache::i()->$key = $this->data;
|
||||
|
||||
if ( $this->save === TRUE and ( !empty( \IPS\Request::i()->cookie ) or $this->userAgent->spider or $this->member->member_id ) ) // If a guest and cookies are disabled we do not write to database to prevent duplicate sessions unless it's a search engine, which we deal with separately
|
||||
{
|
||||
\IPS\Db::i()->replace( 'core_sessions', $this->data, TRUE );
|
||||
@@ -459,6 +466,29 @@ class _Front extends \IPS\Session
|
||||
return $location;
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the session "login_type"
|
||||
*
|
||||
* @param int $type Type as defined by the class constants
|
||||
* @return void
|
||||
*/
|
||||
public function setType( $type )
|
||||
{
|
||||
switch ( $type )
|
||||
{
|
||||
case static::LOGIN_TYPE_MEMBER:
|
||||
case static::LOGIN_TYPE_ANONYMOUS:
|
||||
case static::LOGIN_TYPE_GUEST:
|
||||
case static::LOGIN_TYPE_SPIDER:
|
||||
case static::LOGIN_TYPE_INCOMPLETE:
|
||||
$this->data['login_type'] = $type;
|
||||
break;
|
||||
default:
|
||||
throw new \OutOfRangeException();
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the session as anonymous
|
||||
*
|
||||
@@ -466,7 +496,7 @@ class _Front extends \IPS\Session
|
||||
*/
|
||||
public function setAnon()
|
||||
{
|
||||
$this->data['login_type'] = static::LOGIN_TYPE_ANONYMOUS;
|
||||
$this->setType( static::LOGIN_TYPE_ANONYMOUS );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -496,10 +526,7 @@ class _Front extends \IPS\Session
|
||||
* @return bool
|
||||
*/
|
||||
public function destroy( $sessionId )
|
||||
{
|
||||
$key = "session_{$sessionId}";
|
||||
unset( \IPS\Data\Cache::i()->$key );
|
||||
|
||||
{
|
||||
if ( isset( $_SESSION['wizardKey'] ) )
|
||||
{
|
||||
$dataKey = $_SESSION['wizardKey'];
|
||||
@@ -525,21 +552,11 @@ class _Front extends \IPS\Session
|
||||
/**
|
||||
* Clear sessions - abstracted so it can be called externally without initiating a session
|
||||
*
|
||||
* @param int $lifetime Unix timestamp of the oldest session to keep
|
||||
* @param int $timeout Sessions older than the number of seconds provided will be deleted
|
||||
* @return void
|
||||
*/
|
||||
public static function clearSessions( $lifetime )
|
||||
public static function clearSessions( $timeout )
|
||||
{
|
||||
/* Only bother looping on sessions if we have a cache method set */
|
||||
if( \IPS\CACHE_METHOD !== 'None' )
|
||||
{
|
||||
foreach ( \IPS\Db::i()->select( '*', 'core_sessions', array( 'running_time<?', ( time() - $lifetime ) ) ) as $row )
|
||||
{
|
||||
$key = "session_{$row['id']}";
|
||||
unset( \IPS\Data\Cache::i()->$key );
|
||||
}
|
||||
}
|
||||
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'running_time<?', ( time() - $lifetime ) ) );
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'running_time<?', ( time() - $timeout ) ) );
|
||||
}
|
||||
}
|
||||
+15
-14
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Session Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 11 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -46,7 +46,7 @@ abstract class _Session
|
||||
*/
|
||||
public static function i()
|
||||
{
|
||||
if( self::$instance === NULL )
|
||||
if( static::$instance === NULL )
|
||||
{
|
||||
$classname = get_called_class();
|
||||
if ( get_called_class() === 'IPS\Session' )
|
||||
@@ -69,21 +69,21 @@ abstract class _Session
|
||||
if ( class_exists( $classname ) )
|
||||
{
|
||||
/* Create class */
|
||||
self::$instance = new $classname;
|
||||
static::$instance = new $classname;
|
||||
|
||||
/* Name the session */
|
||||
$name = session_name( ( \IPS\COOKIE_PREFIX !== NULL ) ? \IPS\COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
|
||||
|
||||
/* Set the handler */
|
||||
session_write_close();
|
||||
session_set_save_handler( array( self::$instance, 'open' ), array( self::$instance, 'close' ), array( self::$instance, 'read' ), array( self::$instance, 'write' ), array( self::$instance, 'destroy' ), array( self::$instance, 'gc' ) );
|
||||
session_set_save_handler( array( static::$instance, 'open' ), array( static::$instance, 'close' ), array( static::$instance, 'read' ), array( static::$instance, 'write' ), array( static::$instance, 'destroy' ), array( static::$instance, 'gc' ) );
|
||||
|
||||
/* Make sure we use HTTP-Only cookies */
|
||||
session_set_cookie_params(
|
||||
'0',
|
||||
( \IPS\COOKIE_PATH !== NULL ) ? \IPS\COOKIE_PATH : '/',
|
||||
( \IPS\COOKIE_DOMAIN !== NULL ) ? \IPS\COOKIE_DOMAIN : '',
|
||||
( \IPS\COOKIE_BYPASS_SSLONLY !== NULL ) ? ( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
( \IPS\COOKIE_BYPASS_SSLONLY !== TRUE ) ? ( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
TRUE
|
||||
);
|
||||
|
||||
@@ -91,16 +91,16 @@ abstract class _Session
|
||||
session_start();
|
||||
|
||||
/* Init */
|
||||
self::$instance->init();
|
||||
static::$instance->init();
|
||||
|
||||
/* Register shutdown */
|
||||
register_shutdown_function('session_write_close');
|
||||
}
|
||||
else
|
||||
{
|
||||
self::$instance = new \StdClass;
|
||||
self::$instance->member = new \IPS\Member;
|
||||
self::$instance->csrfKey = '';
|
||||
static::$instance = new \StdClass;
|
||||
static::$instance->member = new \IPS\Member;
|
||||
static::$instance->csrfKey = '';
|
||||
|
||||
/* Upgrader starts session already */
|
||||
if ( !\IPS\Dispatcher::hasInstance() or !\IPS\Dispatcher::i() instanceof \IPS\Dispatcher\Setup )
|
||||
@@ -123,7 +123,7 @@ abstract class _Session
|
||||
}
|
||||
}
|
||||
|
||||
return self::$instance;
|
||||
return static::$instance;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -177,7 +177,7 @@ abstract class _Session
|
||||
$save = FALSE;
|
||||
|
||||
/* Set the last activity */
|
||||
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS )
|
||||
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS and ! \IPS\Request::i()->isAjax() )
|
||||
{
|
||||
if ( time() - $this->member->last_activity > 3600 )
|
||||
{
|
||||
@@ -192,7 +192,7 @@ abstract class _Session
|
||||
}
|
||||
|
||||
/* Set timezone */
|
||||
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone )
|
||||
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
|
||||
{
|
||||
$save = TRUE;
|
||||
$this->member->timezone = \IPS\Request::i()->cookie['ipsTimezone'];
|
||||
@@ -213,7 +213,7 @@ abstract class _Session
|
||||
*/
|
||||
public function csrfCheck()
|
||||
{
|
||||
if ( \IPS\Request::i()->csrfKey !== $this->csrfKey )
|
||||
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, (string) \IPS\Request::i()->csrfKey ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
|
||||
}
|
||||
@@ -241,6 +241,7 @@ abstract class _Session
|
||||
|
||||
\IPS\Db::i()->insert( 'core_moderator_logs', array(
|
||||
'member_id' => \IPS\Member::loggedIn()->member_id,
|
||||
'member_name' => \IPS\Member::loggedIn()->name,
|
||||
'ctime' => time(),
|
||||
'note' => json_encode( $params ),
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
|
||||
Reference in new issue
Block a user