Version 4.2.0

This commit is contained in:
Neo committed 2025-12-19 05:44:59 -08:00
1 parent 0dc2aee5ed
commit 96997ddd8e
2074 files changed
+125454 -55780

No files matched your search

@@ -1,12 +1,11 @@
<?php
/**
* @brief User CP Controller
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Community Suite
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 10 Jun 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\core\modules\front\system;
@@ -144,8 +143,21 @@ class _settings extends \IPS\Dispatcher\Controller
{
$services[$key] = new $class( \IPS\Member::loggedIn() );
}
$nextStep = NULL;
if ( $completed = \IPS\Member::loggedIn()->profileCompletion() AND count( $completed['suggested'] ) )
{
foreach( $completed['suggested'] AS $id => $complete )
{
if ( !$complete )
{
$nextStep = \IPS\Member\ProfileStep::load( $id );
break;
}
}
}
return \IPS\Theme::i()->getTemplate( 'system' )->settingsOverview( $services );
return \IPS\Theme::i()->getTemplate( 'system' )->settingsOverview( $services, $nextStep );
}
/**
@@ -169,17 +181,7 @@ class _settings extends \IPS\Dispatcher\Controller
}
\IPS\Output::i()->output = $mfaOutput;
}
/* Do we have any pending validation emails? */
try
{
$pending = \IPS\Db::i()->select( '*', 'core_validating', array( 'member_id=? AND email_chg=1', \IPS\Member::loggedIn()->member_id ), 'entry_date DESC' )->first();
}
catch( \UnderflowException $e )
{
$pending = null;
}
/* Build the form */
$form = new \IPS\Helpers\Form;
$form->class = 'ipsForm_collapseTablet';
@@ -202,12 +204,16 @@ class _settings extends \IPS\Dispatcher\Controller
}
catch( \BadMethodCallException $e ){}
}
/* Invalidate sessions except this one */
\IPS\Member::loggedIn()->invalidateSessionsAndLogins( \IPS\Session::i()->id );
if( isset( \IPS\Request::i()->cookie['login_key'] ) )
{
\IPS\Member\Device::loadOrCreate( \IPS\Member::loggedIn() )->updateAfterAuthentication( TRUE );
}
/* Delete any pending validation emails */
if ( $pending['vid'] )
{
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND email_chg=1', \IPS\Member::loggedIn()->member_id ) );
}
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND email_chg=1', \IPS\Member::loggedIn()->member_id ) );
/* Send a validation email if we need to */
if ( \IPS\Settings::i()->reg_auth_type == 'user' or \IPS\Settings::i()->reg_auth_type == 'admin_user' )
@@ -285,12 +291,11 @@ class _settings extends \IPS\Dispatcher\Controller
catch( \BadMethodCallException $e ){}
}
/* If we have a pass_hash cookie, update it so we stay logged in on the next page load */
if( isset( \IPS\Request::i()->cookie['pass_hash'] ) )
/* Invalidate sessions except this one */
\IPS\Member::loggedIn()->invalidateSessionsAndLogins( \IPS\Session::i()->id );
if( isset( \IPS\Request::i()->cookie['login_key'] ) )
{
$expire = new \IPS\DateTime;
$expire->add( new \DateInterval( 'P3M' ) );
\IPS\Request::i()->setCookie( 'pass_hash', \IPS\Member::loggedIn()->member_login_key, $expire );
\IPS\Member\Device::loadOrCreate( \IPS\Member::loggedIn() )->updateAfterAuthentication( TRUE );
}
/* Send a confirmation email */
@@ -301,6 +306,128 @@ class _settings extends \IPS\Dispatcher\Controller
return \IPS\Theme::i()->getTemplate( 'system' )->settingsPassword( $form );
}
/**
* Devices
*
* @return string
*/
protected function _devices()
{
$mfaOutput = \IPS\MFA\MFAHandler::accessToArea( 'core', 'DeviceManagement', \IPS\Http\Url::internal( 'app=core&module=system&controller=settings&area=devices', 'front', 'settings_devices' ) );
if ( $mfaOutput )
{
if ( \IPS\Request::i()->isAjax() )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=settings&area=devices', 'front', 'settings_devices' ) );
}
\IPS\Output::i()->output = $mfaOutput;
return \IPS\Theme::i()->getTemplate( 'system' )->settingsDevices( array(), array() );
}
$devices = new \IPS\Patterns\ActiveRecordIterator( \IPS\Db::i()->select( '*', 'core_members_known_devices', array( 'member_id=? AND last_seen>?', \IPS\Member::loggedIn()->member_id, ( new \DateTime )->sub( new \DateInterval( \IPS\Member\Device::LOGIN_KEY_VALIDITY ) )->getTimestamp() ), 'last_seen DESC' ), 'IPS\Member\Device' );
$locations = array();
$ipAddresses = array();
foreach ( \IPS\Db::i()->select( '*', 'core_members_known_ip_addresses', array( 'member_id=?', \IPS\Member::loggedIn()->member_id ), 'last_seen DESC' ) as $log )
{
if ( \IPS\Settings::i()->ipsgeoip )
{
if ( !array_key_exists( $log['ip_address'], $locations ) )
{
try
{
$locations[ $log['ip_address'] ] = \IPS\GeoLocation::getByIp( $log['ip_address'] );
}
catch ( \Exception $e )
{
$locations[ $log['ip_address'] ] = \IPS\Member::loggedIn()->language()->addToStack('unknown');
}
}
$ipAddresses[ $log['device_key'] ][ $log['ip_address'] ] = array(
'location' => $locations[ $log['ip_address'] ],
'date' => $log['last_seen']
);
}
else
{
$ipAddresses[ $log['device_key'] ][ $log['ip_address'] ] = array(
'date' => $log['last_seen']
);
}
}
return \IPS\Theme::i()->getTemplate( 'system' )->settingsDevices( $devices, $ipAddresses );
}
/**
* Secure Account
*
* @return string
*/
protected function secureAccount()
{
/* Only logged in members */
if ( !\IPS\Member::loggedIn()->member_id )
{
\IPS\Output::i()->error( 'no_module_permission_guest', '2C122/Q', 403, '' );
}
$canChangePassword = FALSE;
foreach ( \IPS\Login::handlers( TRUE ) as $k => $handler )
{
if ( $handler->canChange( 'password', \IPS\Member::loggedIn() ) )
{
$canChangePassword = TRUE;
}
}
$canConfigureMfa = FALSE;
$hasConfiguredMfa = FALSE;
foreach ( \IPS\MFA\MFAHandler::handlers() as $handler )
{
if ( $handler->isEnabled() and $handler->memberCanUseHandler( \IPS\Member::loggedIn() ) )
{
$canConfigureMfa = TRUE;
if ( $handler->memberHasConfiguredHandler( \IPS\Member::loggedIn() ) )
{
$hasConfiguredMfa = TRUE;
break;
}
}
}
$services = \IPS\core\ProfileSync\ProfileSyncAbstract::services();
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'secure_account' );
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( 'app=core&module=system&controller=settings', 'front', 'settings' ), \IPS\Member::loggedIn()->language()->addToStack('settings') );
\IPS\Output::i()->breadcrumb[] = array( NULL, \IPS\Member::loggedIn()->language()->addToStack('secure_account') );
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->settingsSecureAccount( $canChangePassword, $canConfigureMfa, $hasConfiguredMfa, $services );
}
/**
* Disable Automatic Login
*
* @return string
*/
protected function disableAutomaticLogin()
{
\IPS\Session::i()->csrfCheck();
try
{
$device = \IPS\Member\Device::loadAndAuthenticate( \IPS\Request::i()->device, \IPS\Member::loggedIn() );
$device->login_key = NULL;
$device->save();
\IPS\Db::i()->delete( 'core_sessions', array( 'member_id=? AND browser=? AND id<>?', $device->member_id, $device->user_agent, \IPS\Session::i()->id ) );
}
catch ( \Exception $e ) { }
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=settings&area=devices', 'front', 'settings_devices' ) );
}
/**
* MFA
@@ -376,6 +503,8 @@ class _settings extends \IPS\Dispatcher\Controller
if ( isset( \IPS\Request::i()->mfa_setup ) )
{
\IPS\Session::i()->csrfCheck();
foreach ( $handlers as $key => $handler )
{
if ( ( count( $handlers ) == 1 ) or $key == \IPS\Request::i()->mfa_method )
@@ -399,6 +528,8 @@ class _settings extends \IPS\Dispatcher\Controller
if ( isset( \IPS\Request::i()->_mfa ) and \IPS\Request::i()->_mfa == 'optout' )
{
\IPS\Session::i()->csrfCheck();
\IPS\Member::loggedIn()->members_bitoptions['security_questions_opt_out'] = TRUE;
\IPS\Member::loggedIn()->save();
\IPS\Output::i()->redirect( $ref );
@@ -416,6 +547,8 @@ class _settings extends \IPS\Dispatcher\Controller
*/
protected function enableMfa()
{
\IPS\Session::i()->csrfCheck();
/* Get the handler */
$handlers = \IPS\MFA\MFAHandler::handlers();
$key = \IPS\Request::i()->type;
@@ -433,6 +566,8 @@ class _settings extends \IPS\Dispatcher\Controller
/* Did we just submit it? */
if ( isset( \IPS\Request::i()->mfa_setup ) and $handlers[ $key ]->configurationScreenSubmit( \IPS\Member::loggedIn() ) )
{
$_SESSION['MFAAuthenticated'] = time();
\IPS\Member::loggedIn()->members_bitoptions['security_questions_opt_out'] = FALSE;
\IPS\Member::loggedIn()->save();
@@ -451,6 +586,8 @@ class _settings extends \IPS\Dispatcher\Controller
*/
protected function disableMfa()
{
\IPS\Session::i()->csrfCheck();
/* Get the handler */
$handlers = \IPS\MFA\MFAHandler::handlers();
$key = \IPS\Request::i()->type;
@@ -572,13 +709,13 @@ class _settings extends \IPS\Dispatcher\Controller
{
$member = \IPS\Member::loggedIn();
}
/* Can we use this? */
if ( !$member->member_id or !( ( $member->failed_mfa_attempts >= \IPS\Settings::i()->security_questions_tries and \IPS\Settings::i()->mfa_lockout_behaviour == 'email' ) or in_array( 'email', explode( ',', \IPS\Settings::i()->mfa_forgot_behaviour ) ) ) )
{
\IPS\Output::i()->error( 'no_module_permission', '2C122/L', 403, '' );
}
/* If we have an existing validation record, we can just reuse it */
$sendEmail = TRUE;
try
@@ -703,9 +840,11 @@ class _settings extends \IPS\Dispatcher\Controller
}
/* How many changes */
$nameCount = \IPS\Db::i()->select( 'COUNT(*) as count, MIN(dname_date) as min_date', 'core_dnames_change', array(
'dname_member_id=? AND dname_date>?',
$nameCount = \IPS\Db::i()->select( 'COUNT(*) as count, MIN(log_date) as min_date', 'core_member_history', array(
'log_member=? AND log_app=? AND log_type=? AND log_date>?',
\IPS\Member::loggedIn()->member_id,
'core',
'display_name',
\IPS\DateTime::create()->sub( new \DateInterval( 'P' . \IPS\Member::loggedIn()->group['g_dname_date'] . 'D' ) )->getTimestamp()
) )->first();
@@ -854,8 +993,22 @@ class _settings extends \IPS\Dispatcher\Controller
{
$src = $image->getAttribute('src');
\IPS\Output::i()->parseFileObjectUrls( $src );
$imageProperties = @getimagesize( $src );
/* If we do not have any properties - remote fetch, and then check against the actual content as a fallback. We do this as a fallback as it can be slower. */
if ( !$imageProperties )
{
try
{
$imageContent = \IPS\Http\Url::external( $src )->request()->get();
$imageProperties = @getimagesizefromstring( (string) $imageContent );
}
catch( \IPS\Http\Request\Exception $e ) { }
}
}
else
{
$src = (string) \IPS\File::get( 'core_Attachment', $attachment['attach_location'] )->url;
}
if( is_array( $imageProperties ) AND count( $imageProperties ) )
@@ -981,8 +1134,21 @@ class _settings extends \IPS\Dispatcher\Controller
$obj->save( $values );
}
$permissionRequest = 'permissionRequest_' . $service;
$extraPermissions = NULL;
$extraPermissionsButton = NULL;
if ( isset( \IPS\Request::i()->$permissionRequest ) )
{
$login = \IPS\Login\LoginAbstract::load( $class::$loginKey );
$url = \IPS\Http\Url::internal( "app=core&module=system&controller=settings&area=profilesync&service={$service}", 'front', "settings_{$service}" );
$extraPermissions = \IPS\Request::i()->$permissionRequest;
$extraPermissionsButton = $login->loginForm( $url, TRUE );
}
$photo = ( method_exists( $obj, 'photo' ) ) ? $obj->photo() : NULL;
return \IPS\Theme::i()->getTemplate( 'system' )->settingsProfileSync( $photo instanceof \IPS\File ? $photo->url : $photo, $headline, method_exists( $obj, 'status' ) ? $obj->status() : NULL, $form, $service, "profilesync__{$service}", ( $settings['photo'] or $settings['cover'] or $settings['status'] ) );
return \IPS\Theme::i()->getTemplate( 'system' )->settingsProfileSync( $photo instanceof \IPS\File ? $photo->url : $photo, $headline, method_exists( $obj, 'status' ) ? $obj->status() : NULL, $form, $service, "profilesync__{$service}", ( $settings['photo'] or $settings['cover'] or $settings['status'] ), $extraPermissions, $extraPermissionsButton );
}
else
{
@@ -1036,4 +1202,59 @@ class _settings extends \IPS\Dispatcher\Controller
$redirectUrl = ( !empty( $_SERVER['HTTP_REFERER'] ) ) ? \IPS\Http\Url::external( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal( "app=core&module=system&controller=settings", 'front', 'settings' );
\IPS\Output::i()->redirect( $redirectUrl, 'signature_pref_toggled' );
}
/**
* Dismiss Profile Completion
*
* @return void
*/
protected function dismissProfile()
{
\IPS\Session::i()->csrfCheck();
\IPS\Member::loggedIn()->members_bitoptions['profile_completion_dismissed'] = TRUE;
\IPS\Member::loggedIn()->save();
if ( \IPS\Request::i()->isAjax() )
{
\IPS\Output::i()->json( 'OK' );
}
else
{
$redirectUrl = ( !empty( $_SERVER['HTTP_REFERER'] ) ) ? \IPS\Http\Url::external( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal( "app=core&module=system&controller=settings", 'front', 'settings' );
\IPS\Output::i()->redirect( $redirectUrl );
}
}
/**
* Completion Wizard
*
* @return void
*/
protected function completion()
{
$steps = array();
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=settings&do=completion', 'front', 'settings' );
foreach( \IPS\Application::allExtensions( 'core', 'ProfileSteps' ) AS $extension )
{
if ( method_exists( $extension, 'wizard') AND count( $extension::wizard() ) )
{
$steps = array_merge( $steps, $extension::wizard() );
}
}
$steps = array_merge( $steps, array( 'profile_done' => function( $data ) {
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=settings", 'front', 'settings' ), 'saved' );
} ) );
$wizard = new \IPS\Helpers\Wizard( $steps, $url, TRUE, NULL, TRUE );
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( '2fa.css', 'core', 'global' ) );
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'styles/settings.css' ) );
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
\IPS\Output::i()->sidebar['enabled'] = FALSE;
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack( 'complete_your_profile' );
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->completeWizard( $wizard );
}
}