Version 5.0.13
This commit is contained in:
1 parent
b89858b2ff
commit
5efe744c5f
1407 files changed
+69690
-30177
No files matched your search
+26
-21
@@ -79,13 +79,15 @@ if ( isset( Request::i()->state ) and $explodedData = explode( '-', Request::i()
|
||||
/* If it's a POST request and the URL is quite long, we need to redirect via POST */
|
||||
if ( Request::i()->requestMethod() === 'POST')
|
||||
{
|
||||
@header( 'Cross-Origin-Opener-Policy: same-origin' );
|
||||
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
|
||||
@header( "Expires: 0" );
|
||||
|
||||
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
|
||||
@header( "Expires: 0" );
|
||||
|
||||
$queryStringComponents = $destination->queryString;
|
||||
$destination = \IPS\Http\Url::createFromString( @base64_decode( $explodedData[1] ) );
|
||||
$output = <<<HTML
|
||||
$queryStringComponents = $destination->queryString;
|
||||
$destination = \IPS\Http\Url::createFromString( @base64_decode( $explodedData[1] ) );
|
||||
$loading = \IPS\Member::loggedIn()->language()->get('loading');
|
||||
$message = \IPS\Member::loggedIn()->language()->get('sign_in_short');
|
||||
$output = <<<HTML
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
@@ -95,21 +97,23 @@ if ( isset( Request::i()->state ) and $explodedData = explode( '-', Request::i()
|
||||
<noscript>{$message}</noscript>
|
||||
<form style="display: none" action="{$destination}" method="POST">
|
||||
HTML;
|
||||
foreach ( $queryStringComponents as $k => $v )
|
||||
{
|
||||
if ( $k === 'ref' )
|
||||
{
|
||||
if ( !$v )
|
||||
{
|
||||
$v = base64_encode( (string) \IPS\Http\Url::baseUrl() );
|
||||
}
|
||||
}
|
||||
$output .= <<<HTML
|
||||
<input name="{$k}" value="{$v}" >
|
||||
foreach ( $queryStringComponents as $k => $v )
|
||||
{
|
||||
$cleanV = htmlspecialchars( $v, ENT_QUOTES, 'UTF-8');
|
||||
if ( $k === 'ref' )
|
||||
{
|
||||
if ( !$v OR rtrim( base64_decode( $v ), '/' ) === rtrim( \IPS\Http\Url::baseUrl(), '/' ) )
|
||||
{
|
||||
$cleanV = base64_encode( (string) \IPS\Http\Url::baseUrl() );
|
||||
}
|
||||
}
|
||||
$k = htmlspecialchars( $k, ENT_QUOTES, 'UTF-8');
|
||||
$output .= <<<HTML
|
||||
<input name="{$k}" value="{$cleanV}" >
|
||||
HTML;
|
||||
|
||||
}
|
||||
$output .= <<<HTML
|
||||
}
|
||||
$output .= <<<HTML
|
||||
<input type="submit" value="{$message}" />
|
||||
</form>
|
||||
<script>
|
||||
@@ -119,8 +123,8 @@ HTML;
|
||||
</body>
|
||||
</html>
|
||||
HTML;
|
||||
echo $output;
|
||||
exit;
|
||||
echo $output;
|
||||
exit;
|
||||
}
|
||||
|
||||
Output::i()->redirect( $destination );
|
||||
@@ -132,6 +136,7 @@ HTML;
|
||||
$url = (string) Url::internal( 'oauth/callback/', 'none' );
|
||||
|
||||
/* Force no caching */
|
||||
@header( 'Cross-Origin-Opener-Policy: same-origin' );
|
||||
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
|
||||
@header( "Expires: 0" );
|
||||
?><!DOCTYPE html>
|
||||
|
||||
Reference in new issue
Block a user