Version 5.0.13

This commit is contained in:
Neo committed 2025-12-19 19:04:57 -08:00
1 parent b89858b2ff
commit 5efe744c5f
1407 files changed
+69690 -30177

No files matched your search

@@ -12,10 +12,13 @@ namespace IPS\core\modules\front\system;
/* To prevent PHP errors (extending class does not exist) revealing path */
use DateInterval;
use IPS\Application;
use IPS\Data\Store;
use IPS\DateTime;
use IPS\Db;
use IPS\Dispatcher\Controller;
use IPS\Email;
use IPS\Extensions\SSOAbstract;
use IPS\Http\Url;
use IPS\Http\Url\Internal;
@@ -29,6 +32,7 @@ use IPS\MFA\MFAHandler;
use IPS\Output;
use IPS\Request;
use IPS\Session;
use IPS\Text\Encrypt;
use IPS\Theme;
use OutOfRangeException;
use UnderflowException;
@@ -157,7 +161,6 @@ class login extends Controller
}
/* Display Login Form */
Output::i()->allowDefaultWidgets = FALSE;
Output::i()->bodyClasses[] = 'ipsLayout_minimal';
Output::i()->sidebar['enabled'] = FALSE;
Output::i()->title = Member::loggedIn()->language()->addToStack('login');
@@ -254,8 +257,58 @@ class login extends Controller
$login->reauthenticateAs = $member;
$error = NULL;
/* Show error if linking cannot be completed */
if( !count( $login->usernamePasswordMethods() ) AND !count( $login->buttonMethods() ) )
{
/**
* Send validation email and show page explaining the next step.
*/
$vid = LoginClass::generateRandomString();
$plainSecurityKey = LoginClass::generateRandomString();
/* Invalidating any existing validating links */
try
{
/* Anything sent in the last 6 minutes? -- keep in mind the email link is only valid for 10 minutes */
Db::i()->select( '*', 'core_validating', [
'member_id=? AND login_link=1 AND email_sent>?',
$member->member_id,
( new DateTime )->sub( new DateInterval( 'PT6M' ) )->getTimestamp()
] )->first();
}
catch( \UnderflowException $e )
{
Db::i()->delete( 'core_validating', [ 'member_id=? AND login_link=1', $member->member_id ] );
Db::i()->insert( 'core_validating', [
'vid' => $vid,
'member_id' => $member->member_id,
'entry_date' => time(),
'email_chg' => false,
'ip_address' => Request::i()->ipAddress(),
'new_email' => '',
'email_sent' => time(),
'security_key' => Encrypt::fromPlaintext( $plainSecurityKey )->tag(),
'login_link' => true,
'extra' => $_SESSION['linkAccounts']
] );
/* send email */
Email::buildFromTemplate( 'core', 'loginLinkValidate', [ $member, $vid, $plainSecurityKey ], Email::TYPE_TRANSACTIONAL )->send( $member );
}
unset( $_SESSION['linkAccounts'] );
/* Otherwise show the reauthenticate form */
Output::i()->bodyClasses[] = 'ipsLayout_minimal';
Output::i()->sidebar['enabled'] = FALSE;
Output::setCacheTime();
Output::i()->title = Member::loggedIn()->language()->addToStack('login');
Output::i()->output = Theme::i()->getTemplate( 'system' )->mergeSocialAccountEmailValidation( $handler );
return;
}
/* Did we submit the merge form? */
if( isset( Request::i()->mergeAccount ) and Request::i()->mergeAccount )
else if( isset( Request::i()->mergeAccount ) and Request::i()->mergeAccount )
{
Session::i()->csrfCheck();