Version 3.2.3
This commit is contained in:
1 parent
ae5c01cc78
commit
78706903a2
2641 files changed
+228363
-201264
No files matched your search
@@ -3,18 +3,18 @@
|
||||
/**
|
||||
* <pre>
|
||||
* Invision Power Services
|
||||
* IP.Board v3.1.4
|
||||
* IP.Board v3.2.3
|
||||
* Public session handler
|
||||
* Last Updated: $Date: 2010-10-06 06:09:32 -0400 (Wed, 06 Oct 2010) $
|
||||
* Last Updated: $Date: 2011-10-11 09:22:35 -0400 (Tue, 11 Oct 2011) $
|
||||
* </pre>
|
||||
*
|
||||
* @author $Author: mmecham $
|
||||
* @author $Author: ips_terabyte $
|
||||
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/community/board/license.html
|
||||
* @license This is NULLED!
|
||||
* @package IP.Board
|
||||
* @link http://www.invisionpower.com
|
||||
* @link http://hatynka.in
|
||||
* @since 26th January 2004
|
||||
* @version $Revision: 6946 $
|
||||
* @version $Revision: 9594 $
|
||||
*
|
||||
*/
|
||||
|
||||
@@ -37,10 +37,10 @@ class publicSessions extends ips_MemberRegistry
|
||||
/**
|
||||
* User agent trimmed
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var string
|
||||
*/
|
||||
private $_userAgent;
|
||||
protected $_userAgent;
|
||||
|
||||
/**
|
||||
* Session recorded flag
|
||||
@@ -197,34 +197,34 @@ class publicSessions extends ips_MemberRegistry
|
||||
/**
|
||||
* Sessions to be destroyed
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var array
|
||||
*/
|
||||
private $_sessionsToKill = array();
|
||||
protected $_sessionsToKill = array();
|
||||
|
||||
/**
|
||||
* Sessions to be updated
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var array
|
||||
*/
|
||||
private $_sessionsToSave = array();
|
||||
protected $_sessionsToSave = array();
|
||||
|
||||
/**
|
||||
* Session data of the session that didn't authorize
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var array
|
||||
*/
|
||||
private $_failedAuthorizationSessionData = array();
|
||||
protected $_failedAuthorizationSessionData = array();
|
||||
|
||||
/**
|
||||
* Delete sessions immediately?
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var boolean
|
||||
*/
|
||||
private $_deleteNow;
|
||||
protected $_deleteNow;
|
||||
|
||||
/**
|
||||
* Session Query Override Keys
|
||||
@@ -235,10 +235,10 @@ class publicSessions extends ips_MemberRegistry
|
||||
* You'd use:
|
||||
* ipsRegistry::member()->sessionClass()->addQueryKey( 'location_key_1', ipsRegistry::$request['f'] );
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @var array
|
||||
*/
|
||||
private $_queryOverride = array();
|
||||
protected $_queryOverride = array();
|
||||
|
||||
/**
|
||||
* Constructor :: Authorizes the session
|
||||
@@ -266,13 +266,13 @@ class publicSessions extends ips_MemberRegistry
|
||||
* This file can be used to easily integrate single-sign on in
|
||||
* situations where you need to check session data
|
||||
*/
|
||||
if( file_exists( IPS_ROOT_PATH . '/sources/classes/session/sso.php' ) )
|
||||
if( is_file( IPS_ROOT_PATH . '/sources/classes/session/sso.php' ) )
|
||||
{
|
||||
require_once( IPS_ROOT_PATH . '/sources/classes/session/sso.php' );
|
||||
|
||||
if( class_exists( "ssoSessionExtension" ) )
|
||||
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . '/sources/classes/session/sso.php', 'ssoSessionExtension' );
|
||||
|
||||
if( class_exists( $classToLoad ) )
|
||||
{
|
||||
$this->sso = new ssoSessionExtension( $this->registry );
|
||||
$this->sso = new $classToLoad( $this->registry );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -336,12 +336,12 @@ class publicSessions extends ips_MemberRegistry
|
||||
$cookie['member_id'] = IPSCookie::get('member_id');
|
||||
$cookie['pass_hash'] = IPSCookie::get('pass_hash');
|
||||
|
||||
if ( $cookie['session_id'] )
|
||||
if ( $cookie['session_id'] && empty( $this->request['_nsc'] ) )
|
||||
{
|
||||
$this->getSession($cookie['session_id']);
|
||||
$this->session_type = 'cookie';
|
||||
}
|
||||
elseif ( isset( $this->request['s'] ) AND $this->request['s'] )
|
||||
elseif ( !empty( $this->request['s'] ) )
|
||||
{
|
||||
$this->getSession($this->request['s']);
|
||||
$this->session_type = 'url';
|
||||
@@ -363,7 +363,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
// a valid session.
|
||||
//-----------------------------------------
|
||||
|
||||
if ( ($this->session_user_id != 0) and ( ! empty($this->session_user_id) ) )
|
||||
if ( ! empty($this->session_user_id) )
|
||||
{
|
||||
//-----------------------------------------
|
||||
// It's a member session, so load the member.
|
||||
@@ -480,21 +480,6 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
$this->sso->checkSSOForMember( 'create' );
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Change the log in key to make each authentication
|
||||
// use a unique token. This means that if a cookie is
|
||||
// stolen, the hacker can only use the auth once.
|
||||
//-----------------------------------------
|
||||
|
||||
if ( $this->settings['login_change_key'] )
|
||||
{
|
||||
self::$data_store['member_login_key'] = IPSMember::generateAutoLoginKey();
|
||||
|
||||
IPSMember::save( self::$data_store['member_id'], array( 'core' => array( 'member_login_key' => self::$data_store['member_login_key'], 'member_login_key_expire' => $_time ) ) );
|
||||
|
||||
IPSCookie::set( "pass_hash", self::$data_store['member_login_key'], $_sticky, $_days );
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -547,20 +532,13 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
if ( my_getenv('HTTP_X_MOZ') AND strstr( strtolower(my_getenv('HTTP_X_MOZ')), 'prefetch' ) AND self::$data_store['member_id'] )
|
||||
{
|
||||
if ( IPB_PHP_SAPI == 'cgi-fcgi' OR IPB_PHP_SAPI == 'cgi' )
|
||||
if ( isset( $_SERVER['SERVER_PROTOCOL'] ) AND strstr( $_SERVER['SERVER_PROTOCOL'], '/1.0' ) )
|
||||
{
|
||||
@header('Status: 403 Forbidden');
|
||||
@header('HTTP/1.0 403 Forbidden');
|
||||
}
|
||||
else
|
||||
{
|
||||
if ( isset( $_SERVER['SERVER_PROTOCOL'] ) AND strstr( $_SERVER['SERVER_PROTOCOL'], '/1.0' ) )
|
||||
{
|
||||
@header('HTTP/1.0 403 Forbidden');
|
||||
}
|
||||
else
|
||||
{
|
||||
@header('HTTP/1.1 403 Forbidden');
|
||||
}
|
||||
@header('HTTP/1.1 403 Forbidden');
|
||||
}
|
||||
|
||||
@header("Cache-Control: no-cache, must-revalidate, max-age=0");
|
||||
@@ -601,7 +579,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
* @param string Key
|
||||
* @param string Value
|
||||
* @param string [Session ID, will default to current session if none found]
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
public function addQueryKey( $key, $value, $sessionID='' )
|
||||
{
|
||||
@@ -708,6 +686,18 @@ class publicSessions extends ips_MemberRegistry
|
||||
//$this->session_id = "";
|
||||
}
|
||||
|
||||
/* Did the user agent change? */
|
||||
if ( ! empty( $uAgent['_browser'] ) )
|
||||
{
|
||||
$sessionData['browser'] = $uAgent['_browser'];
|
||||
unset( $uAgent['_browser'] );
|
||||
|
||||
foreach( $uAgent as $key => $value )
|
||||
{
|
||||
$this->session_data[ $key ] = $value;
|
||||
}
|
||||
}
|
||||
|
||||
/* Set type */
|
||||
self::$data_store['_sessionType'] = 'update';
|
||||
|
||||
@@ -767,8 +757,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
$this->session_id = substr( $uAgent['uagent_key'] . '=' . str_replace( '.', '', $this->_member->ip_address ) . '_session', 0, 60 );
|
||||
$memberName = $uAgent['uagent_name'];
|
||||
$memberGroup = $this->settings['spider_group'];
|
||||
$loginType = intval( $this->settings['spider_anon'] );
|
||||
$memberGroup = $this->settings['guest_group'];
|
||||
|
||||
IPSDebug::addMessage( "Updating SEARCH ENGINE session: " . $this->session_data['id'] );
|
||||
}
|
||||
@@ -777,13 +766,13 @@ class publicSessions extends ips_MemberRegistry
|
||||
IPSDebug::addMessage( "Updating GUEST session: " . $this->session_data['id'] );
|
||||
}
|
||||
|
||||
$this->DB->force_data_type = array( 'member_name' => 'string' );
|
||||
$this->DB->setDataType( 'member_name', 'string' );
|
||||
|
||||
$sessionData = array(
|
||||
'member_name' => $memberName,
|
||||
'member_id' => 0,
|
||||
'member_group' => $memberGroup,
|
||||
'login_type' => $loginType,
|
||||
'login_type' => 0,
|
||||
'running_time' => IPS_UNIX_TIME_NOW,
|
||||
'in_error' => 0,
|
||||
'current_appcomponent' => $this->current_appcomponent,
|
||||
@@ -811,6 +800,18 @@ class publicSessions extends ips_MemberRegistry
|
||||
$this->session_type = 'cookie';
|
||||
//$this->session_id = "";
|
||||
}
|
||||
|
||||
/* Did the user agent change? */
|
||||
if ( ! empty( $uAgent['_browser'] ) )
|
||||
{
|
||||
$sessionData['browser'] = $uAgent['_browser'];
|
||||
unset( $uAgent['_browser'] );
|
||||
|
||||
foreach( $uAgent as $key => $value )
|
||||
{
|
||||
$this->session_data[ $key ] = $value;
|
||||
}
|
||||
}
|
||||
|
||||
/* Set type */
|
||||
self::$data_store['_sessionType'] = 'update';
|
||||
@@ -890,7 +891,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
'uagent_type' => $uAgent['uagent_type'],
|
||||
'uagent_bypass' => intval( $uAgent['uagent_bypass'] ) );
|
||||
|
||||
$this->DB->force_data_type = array( 'member_name' => 'string' );
|
||||
$this->DB->setDataType( 'member_name', 'string' );
|
||||
|
||||
$this->DB->insert( 'sessions', $data, true );
|
||||
|
||||
@@ -1016,8 +1017,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
$this->session_id = substr( $uAgent['uagent_key'] . '=' . str_replace( '.', '', $this->_member->ip_address ) . '_session', 0, 60 );
|
||||
$memberName = $uAgent['uagent_name'];
|
||||
$memberGroup = $this->settings['spider_group'];
|
||||
$loginType = intval( $this->settings['spider_anon'] );
|
||||
$memberGroup = $this->settings['guest_group'];
|
||||
|
||||
IPSDebug::addMessage( "Creating SEARCH ENGINE session: " . $this->session_id );
|
||||
|
||||
@@ -1046,7 +1046,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
'member_name' => $memberName,
|
||||
'member_id' => 0,
|
||||
'member_group' => $memberGroup,
|
||||
'login_type' => $loginType,
|
||||
'login_type' => 0,
|
||||
'running_time' => IPS_UNIX_TIME_NOW,
|
||||
'ip_address' => $this->_member->ip_address,
|
||||
'browser' => substr( $this->_member->user_agent, 0, 200 ),
|
||||
@@ -1065,7 +1065,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
'uagent_type' => $uAgent['uagent_type'],
|
||||
'uagent_bypass' => intval( $uAgent['uagent_bypass'] ) );
|
||||
|
||||
$this->DB->force_data_type = array( 'member_name' => 'string' );
|
||||
$this->DB->setDataType( 'member_name', 'string' );
|
||||
|
||||
$this->DB->insert( 'sessions', $data, true );
|
||||
|
||||
@@ -1193,11 +1193,11 @@ class publicSessions extends ips_MemberRegistry
|
||||
*
|
||||
* @access protected
|
||||
* @param string Any extra WHERE stuff
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
protected function _destroySessions( $where='' )
|
||||
{
|
||||
$where .= ( $where ) ? ' OR ' : '';
|
||||
$where = ( $where ) ? '(' . $where . ') OR ' : '';
|
||||
$where .= 'running_time < ' . ( IPS_UNIX_TIME_NOW - $this->settings['session_expiration'] );
|
||||
|
||||
//-----------------------------------------
|
||||
@@ -1297,11 +1297,11 @@ class publicSessions extends ips_MemberRegistry
|
||||
/**
|
||||
* Kill This Session
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @param string Session ID
|
||||
* @param bool
|
||||
*/
|
||||
private function _killAuthorizeAttempt( $session_id, $session_data )
|
||||
protected function _killAuthorizeAttempt( $session_id, $session_data )
|
||||
{
|
||||
$this->_failedAuthorizationSessionData = $session_data;
|
||||
$this->session_dead_id = $session_id;
|
||||
@@ -1317,11 +1317,11 @@ class publicSessions extends ips_MemberRegistry
|
||||
/**
|
||||
* Allow This Session
|
||||
*
|
||||
* @access private
|
||||
* @access protected
|
||||
* @param string Session ID
|
||||
* @param bool
|
||||
*/
|
||||
private function _allowAuthorizeAttempt( $session_id, $session_data )
|
||||
protected function _allowAuthorizeAttempt( $session_id, $session_data )
|
||||
{
|
||||
$this->session_data = $session_data;
|
||||
$this->session_id = $this->session_data['id'];
|
||||
@@ -1367,8 +1367,8 @@ class publicSessions extends ips_MemberRegistry
|
||||
|
||||
if ( ! $this->registry->isClassLoaded( 'userAgentFunctions' ) )
|
||||
{
|
||||
require_once( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php' );
|
||||
$this->registry->setClass( 'userAgentFunctions', new userAgentFunctions( $this->registry ) );
|
||||
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php', 'userAgentFunctions' );
|
||||
$this->registry->setClass( 'userAgentFunctions', new $classToLoad( $this->registry ) );
|
||||
}
|
||||
|
||||
$uAgent = $this->registry->getClass( 'userAgentFunctions' )->findUserAgentID( $this->_member->user_agent );
|
||||
@@ -1385,6 +1385,9 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
$uAgent['uagent_bypass'] = 0;
|
||||
}
|
||||
|
||||
/* Update browser */
|
||||
$uAgent['_browser'] = $this->_userAgent;
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -1408,29 +1411,21 @@ class publicSessions extends ips_MemberRegistry
|
||||
*/
|
||||
protected function _getLocationSettings()
|
||||
{
|
||||
//-----------------------------------------
|
||||
// INIT
|
||||
//-----------------------------------------
|
||||
|
||||
/* Init vars */
|
||||
$return = array();
|
||||
|
||||
//-----------------------------------------
|
||||
// MODULE?
|
||||
//-----------------------------------------
|
||||
|
||||
/* Got an app? */
|
||||
if ( IPS_APP_COMPONENT )
|
||||
{
|
||||
$filename = IPSLib::getAppDir( IPS_APP_COMPONENT ) . '/extensions/coreExtensions.php';
|
||||
$toload = 'publicSessions__' . IPS_APP_COMPONENT;
|
||||
|
||||
if ( file_exists( $filename ) )
|
||||
$filename = IPSLib::getAppDir( IPS_APP_COMPONENT ) . '/extensions/coreExtensions.php';
|
||||
|
||||
if ( is_file( $filename ) )
|
||||
{
|
||||
require_once( $filename );
|
||||
|
||||
$toload = IPSLib::loadLibrary( $filename, 'publicSessions__' . IPS_APP_COMPONENT, IPS_APP_COMPONENT );
|
||||
|
||||
if ( class_exists( $toload ) )
|
||||
{
|
||||
$loader = new $toload;
|
||||
|
||||
$return = $loader->getSessionVariables();
|
||||
}
|
||||
}
|
||||
@@ -1438,7 +1433,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
|
||||
if( defined('NO_SESSION_UPDATE') AND NO_SESSION_UPDATE )
|
||||
{
|
||||
$this->do_update = 0;
|
||||
$this->do_update = 0;
|
||||
}
|
||||
|
||||
return $return;
|
||||
@@ -1454,7 +1449,49 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
return $this->_sessionsToKill;
|
||||
}
|
||||
|
||||
/**
|
||||
* Store an inline message
|
||||
* @param string $text
|
||||
*/
|
||||
public function setInlineMessage( $text )
|
||||
{
|
||||
$this->DB->insert( 'core_inline_messages', array( 'inline_msg_date' => IPS_UNIX_TIME_NOW,
|
||||
'inline_msg_content' => $text ) );
|
||||
|
||||
$inline_msg_id = $this->DB->getInsertId();
|
||||
|
||||
$this->addQueryKey( 'session_msg_id', $inline_msg_id );
|
||||
}
|
||||
|
||||
/**
|
||||
* Get an inline message
|
||||
* @return string The Message of course.
|
||||
*/
|
||||
public function getInlineMessage()
|
||||
{
|
||||
if ( ! empty( $this->session_data['session_msg_id'] ) )
|
||||
{
|
||||
if ( empty( $this->session_data['_inlineMsg'] ) )
|
||||
{
|
||||
$inlineMsg = $this->DB->buildAndFetch( array( 'select' => 'inline_msg_content',
|
||||
'from' => 'core_inline_messages',
|
||||
'where' => 'inline_msg_id=' . intval( $this->session_data['session_msg_id'] ) ) );
|
||||
|
||||
if ( ! empty( $inlineMsg['inline_msg_content'] ) )
|
||||
{
|
||||
$this->session_data['_inlineMsg'] = $inlineMsg['inline_msg_content'];
|
||||
|
||||
$this->addQueryKey( 'session_msg_id', 0 );
|
||||
|
||||
return $this->session_data['_inlineMsg'];
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Updates a session
|
||||
*
|
||||
@@ -1462,7 +1499,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
* @param string Session id
|
||||
* @param int Member ID
|
||||
* @param array Array of information to update
|
||||
* @return void Updates session_data array and member data array
|
||||
* @return @e void Updates session_data array and member data array
|
||||
*/
|
||||
public function updateSession( $sessionID, $memberID, $data )
|
||||
{
|
||||
@@ -1535,7 +1572,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
* classes are culled
|
||||
*
|
||||
* @access public
|
||||
* @return void
|
||||
* @return @e void
|
||||
*/
|
||||
public function __myDestruct()
|
||||
{
|
||||
@@ -1551,7 +1588,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
{
|
||||
if ( isset( $this->_queryOverride[ $sessionID ] ) AND is_array( $this->_queryOverride[ $sessionID ] ) AND count( $this->_queryOverride[ $sessionID ] ) )
|
||||
{
|
||||
foreach( $data as $field => $value )
|
||||
foreach( $this->_queryOverride[ $sessionID ] as $field => $value )
|
||||
{
|
||||
if ( isset( $this->_queryOverride[ $sessionID ][ $field ] ) )
|
||||
{
|
||||
@@ -1560,7 +1597,7 @@ class publicSessions extends ips_MemberRegistry
|
||||
}
|
||||
}
|
||||
|
||||
$this->DB->force_data_type = array( 'member_name' => 'string' );
|
||||
$this->DB->setDataType( 'member_name', 'string' );
|
||||
$this->DB->update( 'sessions', $data, "id='" . $sessionID . "'", true );
|
||||
}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user