Version 3.2.3

This commit is contained in:
Neo committed 2025-12-19 00:34:03 -08:00
1 parent ae5c01cc78
commit 78706903a2
2641 files changed
+228363 -201264

No files matched your search

@@ -3,18 +3,18 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.1.4
* IP.Board v3.2.3
* Public session handler
* Last Updated: $Date: 2010-10-06 06:09:32 -0400 (Wed, 06 Oct 2010) $
* Last Updated: $Date: 2011-10-11 09:22:35 -0400 (Tue, 11 Oct 2011) $
* </pre>
*
* @author $Author: mmecham $
* @author $Author: ips_terabyte $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/community/board/license.html
* @license This is NULLED!
* @package IP.Board
* @link http://www.invisionpower.com
* @link http://hatynka.in
* @since 26th January 2004
* @version $Revision: 6946 $
* @version $Revision: 9594 $
*
*/
@@ -37,10 +37,10 @@ class publicSessions extends ips_MemberRegistry
/**
* User agent trimmed
*
* @access private
* @access protected
* @var string
*/
private $_userAgent;
protected $_userAgent;
/**
* Session recorded flag
@@ -197,34 +197,34 @@ class publicSessions extends ips_MemberRegistry
/**
* Sessions to be destroyed
*
* @access private
* @access protected
* @var array
*/
private $_sessionsToKill = array();
protected $_sessionsToKill = array();
/**
* Sessions to be updated
*
* @access private
* @access protected
* @var array
*/
private $_sessionsToSave = array();
protected $_sessionsToSave = array();
/**
* Session data of the session that didn't authorize
*
* @access private
* @access protected
* @var array
*/
private $_failedAuthorizationSessionData = array();
protected $_failedAuthorizationSessionData = array();
/**
* Delete sessions immediately?
*
* @access private
* @access protected
* @var boolean
*/
private $_deleteNow;
protected $_deleteNow;
/**
* Session Query Override Keys
@@ -235,10 +235,10 @@ class publicSessions extends ips_MemberRegistry
* You'd use:
* ipsRegistry::member()->sessionClass()->addQueryKey( 'location_key_1', ipsRegistry::$request['f'] );
*
* @access private
* @access protected
* @var array
*/
private $_queryOverride = array();
protected $_queryOverride = array();
/**
* Constructor :: Authorizes the session
@@ -266,13 +266,13 @@ class publicSessions extends ips_MemberRegistry
* This file can be used to easily integrate single-sign on in
* situations where you need to check session data
*/
if( file_exists( IPS_ROOT_PATH . '/sources/classes/session/sso.php' ) )
if( is_file( IPS_ROOT_PATH . '/sources/classes/session/sso.php' ) )
{
require_once( IPS_ROOT_PATH . '/sources/classes/session/sso.php' );
if( class_exists( "ssoSessionExtension" ) )
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . '/sources/classes/session/sso.php', 'ssoSessionExtension' );
if( class_exists( $classToLoad ) )
{
$this->sso = new ssoSessionExtension( $this->registry );
$this->sso = new $classToLoad( $this->registry );
}
}
@@ -336,12 +336,12 @@ class publicSessions extends ips_MemberRegistry
$cookie['member_id'] = IPSCookie::get('member_id');
$cookie['pass_hash'] = IPSCookie::get('pass_hash');
if ( $cookie['session_id'] )
if ( $cookie['session_id'] && empty( $this->request['_nsc'] ) )
{
$this->getSession($cookie['session_id']);
$this->session_type = 'cookie';
}
elseif ( isset( $this->request['s'] ) AND $this->request['s'] )
elseif ( !empty( $this->request['s'] ) )
{
$this->getSession($this->request['s']);
$this->session_type = 'url';
@@ -363,7 +363,7 @@ class publicSessions extends ips_MemberRegistry
// a valid session.
//-----------------------------------------
if ( ($this->session_user_id != 0) and ( ! empty($this->session_user_id) ) )
if ( ! empty($this->session_user_id) )
{
//-----------------------------------------
// It's a member session, so load the member.
@@ -480,21 +480,6 @@ class publicSessions extends ips_MemberRegistry
{
$this->sso->checkSSOForMember( 'create' );
}
//-----------------------------------------
// Change the log in key to make each authentication
// use a unique token. This means that if a cookie is
// stolen, the hacker can only use the auth once.
//-----------------------------------------
if ( $this->settings['login_change_key'] )
{
self::$data_store['member_login_key'] = IPSMember::generateAutoLoginKey();
IPSMember::save( self::$data_store['member_id'], array( 'core' => array( 'member_login_key' => self::$data_store['member_login_key'], 'member_login_key_expire' => $_time ) ) );
IPSCookie::set( "pass_hash", self::$data_store['member_login_key'], $_sticky, $_days );
}
}
else
{
@@ -547,20 +532,13 @@ class publicSessions extends ips_MemberRegistry
{
if ( my_getenv('HTTP_X_MOZ') AND strstr( strtolower(my_getenv('HTTP_X_MOZ')), 'prefetch' ) AND self::$data_store['member_id'] )
{
if ( IPB_PHP_SAPI == 'cgi-fcgi' OR IPB_PHP_SAPI == 'cgi' )
if ( isset( $_SERVER['SERVER_PROTOCOL'] ) AND strstr( $_SERVER['SERVER_PROTOCOL'], '/1.0' ) )
{
@header('Status: 403 Forbidden');
@header('HTTP/1.0 403 Forbidden');
}
else
{
if ( isset( $_SERVER['SERVER_PROTOCOL'] ) AND strstr( $_SERVER['SERVER_PROTOCOL'], '/1.0' ) )
{
@header('HTTP/1.0 403 Forbidden');
}
else
{
@header('HTTP/1.1 403 Forbidden');
}
@header('HTTP/1.1 403 Forbidden');
}
@header("Cache-Control: no-cache, must-revalidate, max-age=0");
@@ -601,7 +579,7 @@ class publicSessions extends ips_MemberRegistry
* @param string Key
* @param string Value
* @param string [Session ID, will default to current session if none found]
* @return void
* @return @e void
*/
public function addQueryKey( $key, $value, $sessionID='' )
{
@@ -708,6 +686,18 @@ class publicSessions extends ips_MemberRegistry
//$this->session_id = "";
}
/* Did the user agent change? */
if ( ! empty( $uAgent['_browser'] ) )
{
$sessionData['browser'] = $uAgent['_browser'];
unset( $uAgent['_browser'] );
foreach( $uAgent as $key => $value )
{
$this->session_data[ $key ] = $value;
}
}
/* Set type */
self::$data_store['_sessionType'] = 'update';
@@ -767,8 +757,7 @@ class publicSessions extends ips_MemberRegistry
{
$this->session_id = substr( $uAgent['uagent_key'] . '=' . str_replace( '.', '', $this->_member->ip_address ) . '_session', 0, 60 );
$memberName = $uAgent['uagent_name'];
$memberGroup = $this->settings['spider_group'];
$loginType = intval( $this->settings['spider_anon'] );
$memberGroup = $this->settings['guest_group'];
IPSDebug::addMessage( "Updating SEARCH ENGINE session: " . $this->session_data['id'] );
}
@@ -777,13 +766,13 @@ class publicSessions extends ips_MemberRegistry
IPSDebug::addMessage( "Updating GUEST session: " . $this->session_data['id'] );
}
$this->DB->force_data_type = array( 'member_name' => 'string' );
$this->DB->setDataType( 'member_name', 'string' );
$sessionData = array(
'member_name' => $memberName,
'member_id' => 0,
'member_group' => $memberGroup,
'login_type' => $loginType,
'login_type' => 0,
'running_time' => IPS_UNIX_TIME_NOW,
'in_error' => 0,
'current_appcomponent' => $this->current_appcomponent,
@@ -811,6 +800,18 @@ class publicSessions extends ips_MemberRegistry
$this->session_type = 'cookie';
//$this->session_id = "";
}
/* Did the user agent change? */
if ( ! empty( $uAgent['_browser'] ) )
{
$sessionData['browser'] = $uAgent['_browser'];
unset( $uAgent['_browser'] );
foreach( $uAgent as $key => $value )
{
$this->session_data[ $key ] = $value;
}
}
/* Set type */
self::$data_store['_sessionType'] = 'update';
@@ -890,7 +891,7 @@ class publicSessions extends ips_MemberRegistry
'uagent_type' => $uAgent['uagent_type'],
'uagent_bypass' => intval( $uAgent['uagent_bypass'] ) );
$this->DB->force_data_type = array( 'member_name' => 'string' );
$this->DB->setDataType( 'member_name', 'string' );
$this->DB->insert( 'sessions', $data, true );
@@ -1016,8 +1017,7 @@ class publicSessions extends ips_MemberRegistry
{
$this->session_id = substr( $uAgent['uagent_key'] . '=' . str_replace( '.', '', $this->_member->ip_address ) . '_session', 0, 60 );
$memberName = $uAgent['uagent_name'];
$memberGroup = $this->settings['spider_group'];
$loginType = intval( $this->settings['spider_anon'] );
$memberGroup = $this->settings['guest_group'];
IPSDebug::addMessage( "Creating SEARCH ENGINE session: " . $this->session_id );
@@ -1046,7 +1046,7 @@ class publicSessions extends ips_MemberRegistry
'member_name' => $memberName,
'member_id' => 0,
'member_group' => $memberGroup,
'login_type' => $loginType,
'login_type' => 0,
'running_time' => IPS_UNIX_TIME_NOW,
'ip_address' => $this->_member->ip_address,
'browser' => substr( $this->_member->user_agent, 0, 200 ),
@@ -1065,7 +1065,7 @@ class publicSessions extends ips_MemberRegistry
'uagent_type' => $uAgent['uagent_type'],
'uagent_bypass' => intval( $uAgent['uagent_bypass'] ) );
$this->DB->force_data_type = array( 'member_name' => 'string' );
$this->DB->setDataType( 'member_name', 'string' );
$this->DB->insert( 'sessions', $data, true );
@@ -1193,11 +1193,11 @@ class publicSessions extends ips_MemberRegistry
*
* @access protected
* @param string Any extra WHERE stuff
* @return void
* @return @e void
*/
protected function _destroySessions( $where='' )
{
$where .= ( $where ) ? ' OR ' : '';
$where = ( $where ) ? '(' . $where . ') OR ' : '';
$where .= 'running_time < ' . ( IPS_UNIX_TIME_NOW - $this->settings['session_expiration'] );
//-----------------------------------------
@@ -1297,11 +1297,11 @@ class publicSessions extends ips_MemberRegistry
/**
* Kill This Session
*
* @access private
* @access protected
* @param string Session ID
* @param bool
*/
private function _killAuthorizeAttempt( $session_id, $session_data )
protected function _killAuthorizeAttempt( $session_id, $session_data )
{
$this->_failedAuthorizationSessionData = $session_data;
$this->session_dead_id = $session_id;
@@ -1317,11 +1317,11 @@ class publicSessions extends ips_MemberRegistry
/**
* Allow This Session
*
* @access private
* @access protected
* @param string Session ID
* @param bool
*/
private function _allowAuthorizeAttempt( $session_id, $session_data )
protected function _allowAuthorizeAttempt( $session_id, $session_data )
{
$this->session_data = $session_data;
$this->session_id = $this->session_data['id'];
@@ -1367,8 +1367,8 @@ class publicSessions extends ips_MemberRegistry
if ( ! $this->registry->isClassLoaded( 'userAgentFunctions' ) )
{
require_once( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php' );
$this->registry->setClass( 'userAgentFunctions', new userAgentFunctions( $this->registry ) );
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php', 'userAgentFunctions' );
$this->registry->setClass( 'userAgentFunctions', new $classToLoad( $this->registry ) );
}
$uAgent = $this->registry->getClass( 'userAgentFunctions' )->findUserAgentID( $this->_member->user_agent );
@@ -1385,6 +1385,9 @@ class publicSessions extends ips_MemberRegistry
{
$uAgent['uagent_bypass'] = 0;
}
/* Update browser */
$uAgent['_browser'] = $this->_userAgent;
}
else
{
@@ -1408,29 +1411,21 @@ class publicSessions extends ips_MemberRegistry
*/
protected function _getLocationSettings()
{
//-----------------------------------------
// INIT
//-----------------------------------------
/* Init vars */
$return = array();
//-----------------------------------------
// MODULE?
//-----------------------------------------
/* Got an app? */
if ( IPS_APP_COMPONENT )
{
$filename = IPSLib::getAppDir( IPS_APP_COMPONENT ) . '/extensions/coreExtensions.php';
$toload = 'publicSessions__' . IPS_APP_COMPONENT;
if ( file_exists( $filename ) )
$filename = IPSLib::getAppDir( IPS_APP_COMPONENT ) . '/extensions/coreExtensions.php';
if ( is_file( $filename ) )
{
require_once( $filename );
$toload = IPSLib::loadLibrary( $filename, 'publicSessions__' . IPS_APP_COMPONENT, IPS_APP_COMPONENT );
if ( class_exists( $toload ) )
{
$loader = new $toload;
$return = $loader->getSessionVariables();
}
}
@@ -1438,7 +1433,7 @@ class publicSessions extends ips_MemberRegistry
if( defined('NO_SESSION_UPDATE') AND NO_SESSION_UPDATE )
{
$this->do_update = 0;
$this->do_update = 0;
}
return $return;
@@ -1454,7 +1449,49 @@ class publicSessions extends ips_MemberRegistry
{
return $this->_sessionsToKill;
}
/**
* Store an inline message
* @param string $text
*/
public function setInlineMessage( $text )
{
$this->DB->insert( 'core_inline_messages', array( 'inline_msg_date' => IPS_UNIX_TIME_NOW,
'inline_msg_content' => $text ) );
$inline_msg_id = $this->DB->getInsertId();
$this->addQueryKey( 'session_msg_id', $inline_msg_id );
}
/**
* Get an inline message
* @return string The Message of course.
*/
public function getInlineMessage()
{
if ( ! empty( $this->session_data['session_msg_id'] ) )
{
if ( empty( $this->session_data['_inlineMsg'] ) )
{
$inlineMsg = $this->DB->buildAndFetch( array( 'select' => 'inline_msg_content',
'from' => 'core_inline_messages',
'where' => 'inline_msg_id=' . intval( $this->session_data['session_msg_id'] ) ) );
if ( ! empty( $inlineMsg['inline_msg_content'] ) )
{
$this->session_data['_inlineMsg'] = $inlineMsg['inline_msg_content'];
$this->addQueryKey( 'session_msg_id', 0 );
return $this->session_data['_inlineMsg'];
}
}
}
return false;
}
/**
* Updates a session
*
@@ -1462,7 +1499,7 @@ class publicSessions extends ips_MemberRegistry
* @param string Session id
* @param int Member ID
* @param array Array of information to update
* @return void Updates session_data array and member data array
* @return @e void Updates session_data array and member data array
*/
public function updateSession( $sessionID, $memberID, $data )
{
@@ -1535,7 +1572,7 @@ class publicSessions extends ips_MemberRegistry
* classes are culled
*
* @access public
* @return void
* @return @e void
*/
public function __myDestruct()
{
@@ -1551,7 +1588,7 @@ class publicSessions extends ips_MemberRegistry
{
if ( isset( $this->_queryOverride[ $sessionID ] ) AND is_array( $this->_queryOverride[ $sessionID ] ) AND count( $this->_queryOverride[ $sessionID ] ) )
{
foreach( $data as $field => $value )
foreach( $this->_queryOverride[ $sessionID ] as $field => $value )
{
if ( isset( $this->_queryOverride[ $sessionID ][ $field ] ) )
{
@@ -1560,7 +1597,7 @@ class publicSessions extends ips_MemberRegistry
}
}
$this->DB->force_data_type = array( 'member_name' => 'string' );
$this->DB->setDataType( 'member_name', 'string' );
$this->DB->update( 'sessions', $data, "id='" . $sessionID . "'", true );
}
}