Version 4.7.0
This commit is contained in:
1 parent
517a5e1f70
commit
8ba7d43898
1933 files changed
+65613
-11332
No files matched your search
@@ -656,15 +656,58 @@ class _ajax extends \IPS\Dispatcher\Controller
|
||||
/**
|
||||
* Return current CSRF token
|
||||
*
|
||||
* @return string|null
|
||||
* @return void
|
||||
*/
|
||||
public function getCsrfKey(): ?string
|
||||
public function getCsrfKey()
|
||||
{
|
||||
if ( ! \IPS\Member::loggedIn()->member_id )
|
||||
if ( isset( \IPS\Request::i()->path ) )
|
||||
{
|
||||
\IPS\Output::i()->json( [ 'key' => \IPS\Session::i()->csrfKey ] );
|
||||
$baseUrlData = parse_url( \IPS\Http\Url::baseUrl() );
|
||||
|
||||
/* If the baseURL was site.com/forums/, JS returns pathname which is /forums/foo
|
||||
so we need to check for a path in the baseURL and make sure its removed from the
|
||||
incoming path. We want to look for 'admin', so 'forums/admin' would confuse it */
|
||||
$pathToUse = '';
|
||||
if ( isset( $baseUrlData['path'] ) and $baseUrlData['path'] )
|
||||
{
|
||||
$pathToUse .= trim( $baseUrlData['path'], '/' );
|
||||
}
|
||||
|
||||
$path = trim( \IPS\Request::i()->path, '/' );
|
||||
|
||||
if ( $pathToUse )
|
||||
{
|
||||
$path = trim( preg_replace( '#^' . $pathToUse . '#', '', $path ), '/' );
|
||||
}
|
||||
|
||||
$bits = explode( '/', $path );
|
||||
|
||||
/* This is an ACP URL, so we need the admin session */
|
||||
if ( $bits[0] == \IPS\CP_DIRECTORY )
|
||||
{
|
||||
/* Ask ajax to follow the redirect for the Admin session CSRF */
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=getCsrfKey', 'admin' ) );
|
||||
}
|
||||
}
|
||||
|
||||
return NULL;
|
||||
\IPS\Output::i()->json( [ 'key' => \IPS\Session::i()->csrfKey ] );
|
||||
}
|
||||
|
||||
/**
|
||||
* Get any events in the session cache and clear the cache
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function getDataLayerEvents()
|
||||
{
|
||||
$payload = '{}';
|
||||
if ( \IPS\Settings::i()->core_datalayer_enabled AND \IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
$payload = \IPS\core\DataLayer::i()->jsonEvents;
|
||||
\IPS\core\DataLayer::i()->clearCache();
|
||||
}
|
||||
|
||||
/* Using this instead of \IPS\Output::i()->json because it's already JSON encoded */
|
||||
\IPS\Output::i()->sendOutput( \IPS\Member::loggedIn()->language()->stripVLETags( $payload ), 200, 'application/json', \IPS\Output::i()->httpHeaders );
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user