Version 4.6.0

This commit is contained in:
Neo committed 2025-12-19 05:55:31 -08:00
1 parent f79dcf067a
commit 517a5e1f70
2036 files changed
+110041 -26162

No files matched your search

+3 -2
View File
@@ -331,7 +331,7 @@ class oAuthServerAuthorizationRequest
public function prompt( $requestedPromptType, $loggedIn )
{
/* If we're banned or validating, we'll show those screens instead */
if ( \IPS\Member::loggedIn()->isBanned() )
if ( \IPS\Member::loggedIn()->member_id and \IPS\Member::loggedIn()->isBanned() )
{
\IPS\Output::i()->showBanned();
exit;
@@ -443,9 +443,10 @@ class oAuthServerAuthorizationRequest
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimalNoHome';
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'oauth_authorize', FALSE, array( 'sprintf' => array( \IPS\Settings::i()->board_name ) ) );
\IPS\Output::i()->httpHeaders['X-Frame-Options'] = 'DENY';
\IPS\Output::i()->pageCaching = FALSE;
/* Check we are not banned */
if ( \IPS\Request::i()->ipAddressIsBanned() or \IPS\Member::loggedIn()->isBanned() )
if ( \IPS\Request::i()->ipAddressIsBanned() or ( \IPS\Member::loggedIn()->member_id and \IPS\Member::loggedIn()->isBanned() ) )
{
\IPS\Output::i()->showBanned();
}
+4
View File
@@ -76,6 +76,10 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
}
$url = (string) \IPS\Http\Url::internal( 'oauth/callback/', 'none' );
/* Force no caching */
@header( "Cache-control: no-cache, no-store, must-revalidate" );
@header( "Expires: 0" );
?><!DOCTYPE html>
<html>
<head>
+6 -5
View File
@@ -131,7 +131,7 @@ class oAuthServerTokenRequest
/* If it's already been used, this should be treated as an attack: revoke any access tokens already generated and do not validate */
if ( $authorizationCode['used'] )
{
\IPS\Db::i()->delete( 'core_oauth_server_access_tokens', array( 'client_id=? AND authorization_code=?', $this->client->client_id, $authorizationCode['code'] ) );
\IPS\Db::i()->update( 'core_oauth_server_access_tokens', array( 'status' => 'revoked' ), array( 'client_id=? AND authorization_code=?', $this->client->client_id, $authorizationCode['code'] ) );
return;
}
@@ -288,7 +288,7 @@ class oAuthServerTokenRequest
$device = NULL;
}
return $this->client->generateAccessToken( $member, $scope, 'refresh_token', TRUE, NULL, $accessToken['auth_user_agent'], isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : NULL, $device, $accessToken );
return $this->client->generateAccessToken( $member, $scope, 'refresh_token', FALSE, NULL, $accessToken['auth_user_agent'], isset( $_SERVER['HTTP_USER_AGENT'] ) ? $_SERVER['HTTP_USER_AGENT'] : NULL, $device, $accessToken );
}
}
}
@@ -382,7 +382,8 @@ try
$response['scope'] = implode( ' ', json_decode( $accessToken['scope'], TRUE ) );
}
\IPS\Output::i()->sendOutput( json_encode( $response ), 200, 'application/json', array( 'Cache-Control' => 'no-store', 'Pragma' => 'no-cache' ), FALSE, FALSE, FALSE );
\IPS\Output::i()->sendOutput( json_encode( $response ), 200, 'application/json', array( 'Cache-Control' => 'no-cache, no-store, must-revalidate', 'Pragma' => 'no-cache' ), FALSE, FALSE, FALSE );
}
else
{
@@ -396,9 +397,9 @@ catch ( \IPS\Login\Handler\OAuth2\Exception $e )
{
$response['error_description'] = $e->description;
}
\IPS\Output::i()->sendOutput( json_encode( $response ), $e->getMessage() === 'invalid_client' ? 401 : 400, 'application/json', array(), FALSE, FALSE, FALSE );
\IPS\Output::i()->sendOutput( json_encode( $response ), $e->getMessage() === 'invalid_client' ? 401 : 400, 'application/json', array( 'Cache-Control' => 'no-cache, no-store, must-revalidate' ), FALSE, FALSE, FALSE );
}
catch ( Exception $e )
{
\IPS\Output::i()->sendOutput( json_encode( array( 'error' => 'server_error', 'error_description' => $e->getMessage() ) ), 500, 'application/json', array(), FALSE, FALSE, FALSE );
\IPS\Output::i()->sendOutput( json_encode( array( 'error' => 'server_error', 'error_description' => $e->getMessage() ) ), 500, 'application/json', array( 'Cache-Control' => 'no-cache, no-store, must-revalidate' ), FALSE, FALSE, FALSE );
}