Version 4.2.0
This commit is contained in:
1 parent
0dc2aee5ed
commit
96997ddd8e
2074 files changed
+125454
-55780
No files matched your search
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Login
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 7 Jun 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\core\modules\front\system;
|
||||
@@ -52,7 +51,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
$member = $login->authenticate();
|
||||
if ( $member !== NULL )
|
||||
{
|
||||
$this->_doLogin( $member, $login->flags['signin_anonymous'], $login->flags['remember_me'], \IPS\Login::getDestination() );
|
||||
$this->_doLogin( $member, $login->flags['signin_anonymous'], $login->flags['remember_me'], \IPS\Login::getDestination(), FALSE, $login->usedHandler );
|
||||
}
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
@@ -99,9 +98,10 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
* @param bool $rememberMe If the "remember me" checkbox was checked
|
||||
* @param \IPS\Http\Url $destination Where to redirect to
|
||||
* @param bool $bypass2FA If true, will not perform 2FA check
|
||||
* @param string $loginHandler Which login handler processed the login
|
||||
* @return void
|
||||
*/
|
||||
protected function _doLogin( $member, $anonymous=FALSE, $rememberMe=TRUE, $destination=NULL, $bypass2FA=FALSE )
|
||||
protected function _doLogin( $member, $anonymous=FALSE, $rememberMe=TRUE, $destination=NULL, $bypass2FA=FALSE, $loginHandler=NULL )
|
||||
{
|
||||
/* Get destination */
|
||||
if ( !$destination )
|
||||
@@ -109,36 +109,26 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
$destination = \IPS\Http\Url::internal( '' );
|
||||
}
|
||||
|
||||
/* Is this a known device? */
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member );
|
||||
|
||||
/* Do we need to do 2FA? */
|
||||
if ( !$bypass2FA and $output = \IPS\MFA\MFAHandler::accessToArea( 'core', 'AuthenticateFront', \IPS\Http\Url::internal( '' ), $member ) )
|
||||
if ( !$bypass2FA and $output = \IPS\MFA\MFAHandler::accessToArea( 'core', $device->known ? 'AuthenticateFrontKnown' : 'AuthenticateFront', \IPS\Http\Url::internal( '' ), $member ) )
|
||||
{
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $member->member_id, 'anonymous' => $anonymous, 'remember' => $rememberMe, 'destination' => (string) $destination );
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $member->member_id, 'anonymous' => $anonymous, 'remember' => $rememberMe, 'destination' => (string) $destination, 'handler' => $loginHandler );
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_mfaLogin', 1 ) );
|
||||
}
|
||||
|
||||
/* Set anonymous cookie */
|
||||
|
||||
/* Log in */
|
||||
\IPS\Session::i()->setMember( $member );
|
||||
if ( $anonymous and !\IPS\Settings::i()->disable_anonymous )
|
||||
{
|
||||
\IPS\Session::i()->setAnon();
|
||||
\IPS\Request::i()->setCookie( 'anon_login', 1 );
|
||||
}
|
||||
|
||||
/* Log in */
|
||||
\IPS\Session::i()->setMember( $member );
|
||||
|
||||
/* Set remember me cookie */
|
||||
if ( $rememberMe )
|
||||
{
|
||||
$expire = new \IPS\DateTime;
|
||||
$expire->add( new \DateInterval( 'P3M' ) );
|
||||
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', $member->member_login_key, $expire );
|
||||
|
||||
if ( $anonymous and !\IPS\Settings::i()->disable_anonymous )
|
||||
{
|
||||
\IPS\Request::i()->setCookie( 'anon_login', 1, $expire );
|
||||
}
|
||||
}
|
||||
/* Log device */
|
||||
$device->anonymous = $anonymous and !\IPS\Settings::i()->disable_anonymous;
|
||||
$device->updateAfterAuthentication( $rememberMe, $loginHandler );
|
||||
|
||||
/* Member sync */
|
||||
$member->memberSync( 'onLogin', array( \IPS\Login::getDestination() ) );
|
||||
@@ -174,10 +164,11 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
catch ( \Exception $e ) { }
|
||||
|
||||
/* Have we already done 2FA? */
|
||||
$output = \IPS\MFA\MFAHandler::accessToArea( 'core', 'AuthenticateFront', \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'front', 'login' ), $member );
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member );
|
||||
$output = \IPS\MFA\MFAHandler::accessToArea( 'core', $device->known ? 'AuthenticateFrontKnown' : 'AuthenticateFront', \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'front', 'login' ), $member );
|
||||
if ( !$output )
|
||||
{
|
||||
$this->_doLogin( $member, $_SESSION['processing2FA']['anonymous'], $_SESSION['processing2FA']['remember'], $destination, TRUE );
|
||||
$this->_doLogin( $member, $_SESSION['processing2FA']['anonymous'], $_SESSION['processing2FA']['remember'], $destination, TRUE, $_SESSION['processing2FA']['handler'] );
|
||||
}
|
||||
|
||||
/* Nope, just send us where we want to go not logged in */
|
||||
@@ -249,7 +240,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
catch ( \Exception $e ) { }
|
||||
}
|
||||
$this->_doLogin( $member, FALSE, TRUE, $destination );
|
||||
$this->_doLogin( $member, FALSE, TRUE, $destination, FALSE, $details['handler'] );
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
{
|
||||
@@ -270,8 +261,12 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function logout()
|
||||
{
|
||||
$member = \IPS\Member::loggedIn();
|
||||
|
||||
/* CSRF Check */
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
/* Work out where we will be going after log out */
|
||||
if( !empty( $_SERVER['HTTP_REFERER'] ) )
|
||||
{
|
||||
$referrer = \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] );
|
||||
@@ -281,8 +276,6 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$redirectUrl = \IPS\Http\Url::internal( '' );
|
||||
}
|
||||
|
||||
$member = \IPS\Member::loggedIn();
|
||||
|
||||
/* Are we logging out back to an admin user? */
|
||||
if( isset( $_SESSION['logged_in_as_key'] ) )
|
||||
@@ -295,28 +288,25 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->redirect( $redirectUrl );
|
||||
}
|
||||
|
||||
\IPS\Request::i()->setCookie( 'member_id', NULL );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', NULL );
|
||||
\IPS\Request::i()->setCookie( 'anon_login', NULL );
|
||||
|
||||
foreach( \IPS\Request::i()->cookie as $name => $value )
|
||||
/* Do not allow the login_key to be re-used */
|
||||
if ( isset( \IPS\Request::i()->cookie['device_key'] ) )
|
||||
{
|
||||
if( mb_strpos( $name, "ipbforumpass_" ) !== FALSE )
|
||||
try
|
||||
{
|
||||
\IPS\Request::i()->setCookie( $name, NULL );
|
||||
$device = \IPS\Member\Device::loadAndAuthenticate( \IPS\Request::i()->cookie['device_key'], $member );
|
||||
$device->login_key = NULL;
|
||||
$device->save();
|
||||
}
|
||||
catch ( \OutOfRangeException $e ) { }
|
||||
}
|
||||
|
||||
/* Clear cookies */
|
||||
\IPS\Request::i()->clearLoginCookies();
|
||||
|
||||
/* Reset session global parameters */
|
||||
$_SESSION = array();
|
||||
|
||||
/* We have to explicitly reset the session cookie
|
||||
@link http://php.net/manual/en/function.session-destroy.php */
|
||||
/* Destroy the session (we have to explicitly reset the session cookie, see http://php.net/manual/en/function.session-destroy.php) */
|
||||
$_SESSION = array();
|
||||
$params = session_get_cookie_params();
|
||||
|
||||
setcookie( session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"] );
|
||||
|
||||
/* Then destroy the session itself */
|
||||
session_destroy();
|
||||
|
||||
/* Login handler callback */
|
||||
@@ -332,6 +322,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
/* Member sync callback */
|
||||
$member->memberSync( 'onLogout', array( $redirectUrl ) );
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( $redirectUrl->setQueryString( '_fromLogout', 1 ) );
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user