Version 4.6.0

This commit is contained in:
Neo committed 2025-12-19 05:55:31 -08:00
1 parent f79dcf067a
commit 517a5e1f70
2036 files changed
+110041 -26162

No files matched your search

+20 -1
View File
@@ -70,6 +70,9 @@ abstract class _Session
{
/* Create class */
static::$instance = new $classname;
/* Remove PHPs own cache headers */
session_cache_limiter('');
/* Name the session */
$name = session_name( ( \IPS\COOKIE_PREFIX !== NULL ) ? \IPS\COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
@@ -204,6 +207,14 @@ abstract class _Session
$this->member->save();
}
}
else
{
/* Ensure any loggedIn cookies are removed */
if( isset( \IPS\Request::i()->cookie['loggedIn'] ) )
{
\IPS\Request::i()->setCookie( 'loggedIn', NULL );
}
}
}
/**
@@ -223,7 +234,15 @@ abstract class _Session
*/
public function csrfCheck()
{
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, (string) \IPS\Request::i()->csrfKey ) )
$token = (string) \IPS\Request::i()->csrfKey;
/* Guests may provide the csrf token via a header */
if ( !\IPS\Member::loggedIn()->member_id && isset( $_SERVER['HTTP_X_CSRF_TOKEN'] ) )
{
$token = $_SERVER['HTTP_X_CSRF_TOKEN'];
}
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, $token ) )
{
\IPS\Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
}