Version 4.7.13

This commit is contained in:
Neo committed 2025-12-19 16:14:56 -08:00
1 parent fd22d99e69
commit 7124a02564
954 files changed
+29277 -59308

No files matched your search

+12
View File
@@ -280,6 +280,12 @@ class oAuthServerAuthorizationRequest
{
return TRUE;
}
/* If our account is incomplete (e.g. no name or no email), show that screen instead */
if( \IPS\Member::loggedIn()->member_id and !( \IPS\Member::loggedIn()->real_name and \IPS\Member::loggedIn()->email ) )
{
return TRUE;
}
/* Have we gone through it already? */
if ( isset( \IPS\Request::i()->allow ) and \IPS\Login::compareHashes( (string) \IPS\Session::i()->csrfKey, (string) \IPS\Request::i()->csrfKey ) )
@@ -429,6 +435,12 @@ class oAuthServerAuthorizationRequest
\IPS\Dispatcher::i()->finish();
}
}
/* If we're logged in but the account is incomplete (e.g. social registration with hitherto unset name/email), redirect to complete registration first */
elseif ( \IPS\Member::loggedIn()->member_id and !( \IPS\Member::loggedIn()->real_name and \IPS\Member::loggedIn()->email ) )
{
$url = \IPS\Http\Url::internal( 'oauth/authorize/', 'interface' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=register&do=complete', 'front', 'register' )->addRef( $url )->setQueryString( 'oauth', 1 ) );
}
/* Still here? Show an authorization screen */
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'login', 'core', 'global' )->oauthAuthorize( $url, $this->client, $scopes );
+74 -25
View File
@@ -1,11 +1,11 @@
<?php
/**
* @brief OAuth Client Redirection Endpoint
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 31 May 2017
* @brief OAuth Client Redirection Endpoint
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 31 May 2017
*/
\define('REPORT_EXCEPTIONS', TRUE);
require '../../init.php';
@@ -16,15 +16,15 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
try
{
$destination = \IPS\Http\Url::createFromString( $destination )->setQueryString( array(
'_processLogin' => $explodedData[0],
'csrfKey' => $explodedData[2],
'ref' => $explodedData[3],
'_processLogin' => $explodedData[0],
'csrfKey' => $explodedData[2],
'ref' => $explodedData[3],
) );
if ( !( $destination instanceof \IPS\Http\Url\Internal ) )
{
throw new \Exception;
}
if ( isset( \IPS\Request::i()->error ) )
{
foreach ( array( 'error', 'error_description', 'error_uri' ) as $k )
@@ -48,7 +48,7 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
}
}
/* OAuth 1 */
elseif ( isset( \IPS\Request::i()->oauth_token ) )
elseif ( isset( \IPS\Request::i()->oauth_token ) )
{
foreach ( array( 'oauth_token', 'oauth_verifier', 'state' ) as $k )
{
@@ -65,10 +65,59 @@ if ( isset( \IPS\Request::i()->state ) and $explodedData = explode( '-', \IPS\Re
{
$_SESSION['oauth_user'] = \IPS\Request::i()->user;
}
$destination = $destination->setQueryString( 'code', \IPS\Request::i()->code );
}
if ( \IPS\Request::i()->requestMethod() === 'POST' )
{
@header( "Cache-control: no-cache, no-store, must-revalidate, max-age=0, s-maxage=0" );
@header( "Expires: 0" );
$queryStringComponents = $destination->queryString;
$loading = \IPS\Member::loggedIn()->language()->get('loading');
$message = \IPS\Member::loggedIn()->language()->get('oauth_post_redirect_submit');
$destination = \IPS\Http\Url::createFromString( @base64_decode( $explodedData[1] ) );
$output = <<<HTML
<!DOCTYPE html>
<html>
<head>
<title>{$loading}</title>
</head>
<body>
<noscript>{$message}</noscript>
<form style="display: none" action="{$destination}" method="POST">
HTML;
foreach ( $queryStringComponents as $k => $v )
{
if ( $k === 'ref' )
{
if ( !$v )
{
$v = base64_encode( (string) \IPS\Http\Url::baseUrl() );
}
}
$output .= <<<HTML
<input name="{$k}" value="{$v}" >
HTML;
}
$output .= <<<HTML
<input type="submit" value="{$message}" />
</form>
<script>
const form = document.querySelector('form');
form.submit();
</script>
</body>
</html>
HTML;
echo $output;
exit;
}
\IPS\Output::i()->redirect( $destination );
exit;
}
@@ -82,16 +131,16 @@ $url = (string) \IPS\Http\Url::internal( 'oauth/callback/', 'none' );
@header( "Expires: 0" );
?><!DOCTYPE html>
<html>
<head>
<title><?php echo \IPS\Member::loggedIn()->language()->get( 'loading' ); ?></title>
<script>
if ( window.location.hash ) {
var hash = window.location.hash.substr( 0, 1 ) == '#' ? window.location.hash.substr( 1 ) : window.location.hash;
window.location = "<?php echo $url; ?>?" + hash;
}
</script>
</head>
<body>
<noscript><?php echo \IPS\Member::loggedIn()->language()->get( 'oauth_implicit_no_js' ); ?></noscript>
</body>
<head>
<title><?php echo \IPS\Member::loggedIn()->language()->get( 'loading' ); ?></title>
<script>
if ( window.location.hash ) {
var hash = window.location.hash.substr( 0, 1 ) == '#' ? window.location.hash.substr( 1 ) : window.location.hash;
window.location = "<?php echo $url; ?>?" + hash;
}
</script>
</head>
<body>
<noscript><?php echo \IPS\Member::loggedIn()->language()->get( 'oauth_implicit_no_js' ); ?></noscript>
</body>
</html>