Version 4.6.0

This commit is contained in:
Neo committed 2025-12-19 05:55:31 -08:00
1 parent f79dcf067a
commit 517a5e1f70
2036 files changed
+110041 -26162

No files matched your search

+51 -79
View File
@@ -35,29 +35,39 @@ class _ajax extends \IPS\Dispatcher\Controller
$where = array( "name LIKE CONCAT(?, '%')" );
$binds = array( $input );
if ( \IPS\Dispatcher::i()->controllerLocation === 'admin' )
if ( \IPS\Dispatcher::i()->controllerLocation === 'admin' OR ( \IPS\Member::loggedIn()->modPermission('can_see_emails') AND \IPS\Request::i()->type == 'mod' ) )
{
$where[] = "email LIKE CONCAT(?, '%')";
$binds[] = $input;
}
if ( \IPS\Dispatcher::i()->controllerLocation === 'admin' )
{
if ( \is_numeric( \IPS\Request::i()->input ) )
{
$where[] = "member_id=?";
$binds[] = \intval( \IPS\Request::i()->input );
}
}
/* Build the array item for this member after constructing a record */
/* The value should be just the name so that it's inserted into the input properly, but for display, we wrap it in the group *fix */
foreach ( \IPS\Db::i()->select( '*', 'core_members', array_merge( array( implode( ' OR ', $where ) ), $binds ), 'LENGTH(name) ASC', array( 0, 20 ) ) as $row )
{
$member = \IPS\Member::constructFromData( $row );
$extra = \IPS\Dispatcher::i()->controllerLocation == 'admin' ? htmlspecialchars( $member->email, ENT_DISALLOWED | ENT_QUOTES, 'UTF-8', FALSE ) : $member->groupName;
if ( \IPS\Member::loggedIn()->modPermission('can_see_emails') AND \IPS\Request::i()->type == 'mod' )
{
$extra = htmlspecialchars( $member->email, ENT_DISALLOWED | ENT_QUOTES, 'UTF-8', FALSE ) . '<br>' . $member->groupName;
}
$results[] = array(
'id' => $member->member_id,
'value' => $member->name,
'name' => \IPS\Dispatcher::i()->controllerLocation == 'admin' ? $member->group['prefix'] . htmlspecialchars( $member->name, ENT_DISALLOWED | ENT_QUOTES, 'UTF-8', FALSE ) . $member->group['suffix'] : htmlspecialchars( $member->name, ENT_DISALLOWED | ENT_QUOTES, 'UTF-8', FALSE ),
'extra' => \IPS\Dispatcher::i()->controllerLocation == 'admin' ? htmlspecialchars( $member->email, ENT_DISALLOWED | ENT_QUOTES, 'UTF-8', FALSE ) : $member->groupName,
'extra' => $extra,
'photo' => (string) $member->photo,
);
}
@@ -256,77 +266,6 @@ class _ajax extends \IPS\Dispatcher\Controller
\IPS\Output::i()->json( $result );
}
/**
* Returns boolean in json indicating whether the supplied email already exists
*
* @return void
*/
public function emailExists()
{
$result = array( 'result' => 'ok' );
/* The value comes urlencoded so we need to decode so length is correct (and not using a percent-encoded value) */
$email = urldecode( \IPS\Request::i()->input );
/* Check is valid */
if ( !$email )
{
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('form_required') );
}
elseif ( filter_var( $email, FILTER_VALIDATE_EMAIL ) === FALSE )
{
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('form_bad_value') );
}
/* Check if it exists */
else if ( $error = \IPS\Login::emailIsInUse( $email ) )
{
if ( \IPS\Member::loggedIn()->isAdmin() )
{
$result = array( 'result' => 'fail', 'message' => $error );
}
else
{
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('member_email_exists') );
}
}
/* Check it's not banned */
if ( $result == array( 'result' => 'ok' ) )
{
foreach( \IPS\Db::i()->select( 'ban_content', 'core_banfilters', array("ban_type=?", 'email') ) as $bannedEmail )
{
if( preg_match( '/^' . str_replace( '\*', '.*', preg_quote( $bannedEmail, '/' ) ) . '$/i', $email ) )
{
$result = array( 'result' => 'fail', 'message' => \IPS\Member::loggedIn()->language()->addToStack('form_email_banned') );
break;
}
}
}
/* Check it's an allowed domain */
if ( \IPS\Settings::i()->allowed_reg_email !== '' AND $allowedEmailDomains = explode( ',', \IPS\Settings::i()->allowed_reg_email ) )
{
$matched = FALSE;
foreach ( $allowedEmailDomains AS $domain )
{
if( \mb_stripos( $email, "@" . $domain ) !== FALSE )
{
$matched = TRUE;
break;
}
}
if ( \count( $allowedEmailDomains ) AND !$matched )
{
$result = array( 'result' => 'fail', 'message' => $email );
}
}
\IPS\Output::i()->json( $result );
}
/**
* Get state/region list for country
*
@@ -396,6 +335,7 @@ class _ajax extends \IPS\Dispatcher\Controller
}
else
{
\IPS\Output::i()->metaTags['robots'] = 'noindex';
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'block_topContributors' );
\IPS\Output::i()->output = $output;
}
@@ -410,6 +350,11 @@ class _ajax extends \IPS\Dispatcher\Controller
{
/* How many? */
$limit = \intval( ( isset( \IPS\Request::i()->limit ) and \IPS\Request::i()->limit <= 25 ) ? \IPS\Request::i()->limit : 5 );
if( $limit < 0 )
{
$limit = 5;
}
/* What timeframe? */
$where = array( array( 'member_id > 0' ) );
@@ -454,6 +399,7 @@ class _ajax extends \IPS\Dispatcher\Controller
}
else
{
\IPS\Output::i()->metaTags['robots'] = 'noindex';
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'block_mostSolved' );
\IPS\Output::i()->output = $output;
}
@@ -472,6 +418,7 @@ class _ajax extends \IPS\Dispatcher\Controller
}
$preview = \IPS\Theme::i()->getTemplate( 'global', 'core', 'front' )->navBar( TRUE );
\IPS\Output::i()->metaTags['robots'] = 'noindex';
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'system/menumanager.css', 'core', 'admin' ) );
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'applications', 'core', 'admin' )->menuPreviewWrapper( $preview ) );
}
@@ -608,7 +555,8 @@ class _ajax extends \IPS\Dispatcher\Controller
{
$mysqlTimezone = "GMT" . ( ( $matches[2] == 0 ) ? '' : ( ( $matches[1] ?: '+' ) . \intval( $matches[2] ) ) );
}
\IPS\Output::i()->metaTags['robots'] = 'noindex';
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->chartTimezoneInfo( $mysqlTimezone );
}
@@ -626,7 +574,16 @@ class _ajax extends \IPS\Dispatcher\Controller
\IPS\core\AdminNotification::dismissNotification( \IPS\Request::i()->id );
}
\IPS\Output::i()->json( array( 'status' => 'OK' ) );
if( \IPS\Request::i()->isAjax() )
{
\IPS\Output::i()->json( array( 'status' => 'OK' ) );
}
else
{
$ref = \IPS\Request::i()->referrer();
\IPS\Output::i()->redirect( $ref ?? \IPS\Http\Url::internal( '' ) );
}
}
/**
@@ -650,7 +607,7 @@ class _ajax extends \IPS\Dispatcher\Controller
try
{
$container = $containerClass::load( \IPS\Request::i()->container );
$container = $containerClass::load( (int) \IPS\Request::i()->container );
}
catch( \OutOfRangeException $e )
{
@@ -695,4 +652,19 @@ class _ajax extends \IPS\Dispatcher\Controller
\IPS\Output::i()->json( $results );
}
/**
* Return current CSRF token
*
* @return string|null
*/
public function getCsrfKey(): ?string
{
if ( ! \IPS\Member::loggedIn()->member_id )
{
\IPS\Output::i()->json( [ 'key' => \IPS\Session::i()->csrfKey ] );
}
return NULL;
}
}