Version 4.2.0
This commit is contained in:
1 parent
0dc2aee5ed
commit
96997ddd8e
2074 files changed
+125454
-55780
No files matched your search
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Converter Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 14 Oct 2014
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
namespace IPS\Login;
|
||||
|
||||
@@ -76,12 +75,12 @@ class _Convert extends LoginAbstract
|
||||
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_no_account', FALSE, array( 'sprintf' => array( \IPS\Member::loggedIn()->language()->addToStack( $this->getLoginType( $this->authTypes ) ) ) ) ), \IPS\Login\Exception::NO_ACCOUNT );
|
||||
}
|
||||
|
||||
/* Table switcher for new IPS4 converters */
|
||||
/* Table switcher for new converters */
|
||||
try
|
||||
{
|
||||
try
|
||||
{
|
||||
$apps = \IPS\Db::i()->select( 'app_key', 'convert_apps', array( 'login=?', 1 ) );
|
||||
$apps = iterator_to_array( \IPS\Db::i()->select( 'app_key', 'convert_apps', array( 'login=?', 1 ) ) );
|
||||
}
|
||||
catch ( \IPS\Db\Exception $e )
|
||||
{
|
||||
@@ -97,6 +96,9 @@ class _Convert extends LoginAbstract
|
||||
|
||||
foreach( $apps as $sw )
|
||||
{
|
||||
/* Strip underscores from keys */
|
||||
$sw = str_replace( "_", "", $sw );
|
||||
|
||||
/* loop found members */
|
||||
foreach( $members as $member )
|
||||
{
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Login Exception Class
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 26 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief External Database Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
|
||||
+69
-19
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Facebook Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -28,6 +27,11 @@ class _Facebook extends LoginAbstract
|
||||
*/
|
||||
public static $icon = 'facebook-square';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = 'Facebook';
|
||||
|
||||
/**
|
||||
* @brief Share Service
|
||||
*/
|
||||
@@ -44,20 +48,38 @@ class _Facebook extends LoginAbstract
|
||||
public function loginForm( \IPS\Http\Url $url, $ucp = FALSE, \IPS\Http\Url $destination = NULL )
|
||||
{
|
||||
$scope = 'email';
|
||||
$facebookUrl = "https://www.facebook.com/dialog/oauth";
|
||||
|
||||
if ( \IPS\Settings::i()->profile_comments )
|
||||
{
|
||||
if ( isset( $this->settings['allow_status_import'] ) and $this->settings['allow_status_import'] )
|
||||
{
|
||||
$scope .= ',user_posts';
|
||||
}
|
||||
}
|
||||
|
||||
if ( isset( $this->settings['autoshare'] ) and $this->settings['autoshare'] )
|
||||
{
|
||||
$scope .= ',publish_actions';
|
||||
if ( isset( $this->settings['autoshare'] ) and $this->settings['autoshare'] )
|
||||
{
|
||||
$scope .= ',publish_actions';
|
||||
}
|
||||
|
||||
if ( isset( \IPS\Request::i()->permissionRequest_Facebook ) )
|
||||
{
|
||||
$allowedExtra = array( 'pages_show_list', 'manage_pages', 'publish_pages' );
|
||||
|
||||
/* We need at least version 2.5 for this to work, 2.8 is latest */
|
||||
$facebookUrl = "https://www.facebook.com/v2.8/dialog/oauth";
|
||||
|
||||
foreach( explode( ',', \IPS\Request::i()->permissionRequest_Facebook ) as $new )
|
||||
{
|
||||
if ( in_array( trim( $new ), $allowedExtra ) )
|
||||
{
|
||||
$scope .= "," . $new;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$url = \IPS\Http\Url::external( "https://www.facebook.com/dialog/oauth" )->setQueryString( array(
|
||||
$url = \IPS\Http\Url::external( $facebookUrl )->setQueryString( array(
|
||||
'client_id' => $this->settings['app_id'],
|
||||
'scope' => $scope,
|
||||
'redirect_uri' => (string) \IPS\Http\Url::internal( 'applications/core/interface/facebook/auth.php', 'none', NULL, array(), \IPS\Settings::i()->logins_over_https ? \IPS\Http\Url::PROTOCOL_HTTPS : 0 ),
|
||||
@@ -86,6 +108,13 @@ class _Facebook extends LoginAbstract
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Check user approved */
|
||||
if( !isset( \IPS\Request::i()->code ) OR !\IPS\Request::i()->code )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'denied_oauth', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Get a token */
|
||||
try
|
||||
{
|
||||
@@ -102,16 +131,9 @@ class _Facebook extends LoginAbstract
|
||||
}
|
||||
|
||||
/* Now exchange it for a one that will last a bit longer in case the user wants to use syncing */
|
||||
try
|
||||
{
|
||||
$response = \IPS\Http\Url::external( "https://graph.facebook.com/v2.8/oauth/access_token" )->request()->post( array(
|
||||
'grant_type' => 'fb_exchange_token',
|
||||
'client_id' => $this->settings['app_id'],
|
||||
'client_secret' => $this->settings['app_secret'],
|
||||
'fb_exchange_token' => $response['access_token']
|
||||
) )->decodeJson();
|
||||
}
|
||||
catch( \RuntimeException $e )
|
||||
$response['access_token'] = $this->exchangeToken( $response['access_token'] );
|
||||
|
||||
if ( ! $response['access_token'] )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'generic_error', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
@@ -137,6 +159,34 @@ class _Facebook extends LoginAbstract
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Exchange a short lived token for a longer lived token
|
||||
*
|
||||
* @param string $shortLivedToken The short lived token to exchange for a long lived token
|
||||
* @return string
|
||||
*/
|
||||
public function exchangeToken( $shortLivedToken )
|
||||
{
|
||||
try
|
||||
{
|
||||
$response = \IPS\Http\Url::external( "https://graph.facebook.com/v2.8/oauth/access_token" )->request()->post( array(
|
||||
'grant_type' => 'fb_exchange_token',
|
||||
'client_id' => $this->settings['app_id'],
|
||||
'client_secret' => $this->settings['app_secret'],
|
||||
'fb_exchange_token' => $shortLivedToken
|
||||
) )->decodeJson();
|
||||
|
||||
return $response['access_token'];
|
||||
}
|
||||
catch( \RuntimeException $e )
|
||||
{
|
||||
\IPS\Log::log( $e, 'facebook' );
|
||||
}
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/**
|
||||
* Link Account
|
||||
*
|
||||
|
||||
+14
-5
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Google Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 20 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -28,6 +27,11 @@ class _Google extends LoginAbstract
|
||||
*/
|
||||
public static $icon = 'google-plus';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = 'Google';
|
||||
|
||||
/**
|
||||
* Get Form
|
||||
*
|
||||
@@ -85,6 +89,11 @@ class _Google extends LoginAbstract
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
if( !isset( \IPS\Request::i()->code ) OR !\IPS\Request::i()->code )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'denied_oauth', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Get access token so we can get user data */
|
||||
$response = \IPS\Http\Url::external( "https://accounts.google.com/o/oauth2/token" )->request()->post( array(
|
||||
|
||||
+10
-17
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Internal Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 13 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -245,18 +244,12 @@ class _Internal extends LoginAbstract
|
||||
*/
|
||||
public function changePassword( \IPS\Member $member, $newPassword )
|
||||
{
|
||||
/* Clear any current sessions for this user. This resolves an issue where a user resets their password in one location, but a malicious
|
||||
user with access to their account can retain access in another location. */
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'member_id=?', $member->member_id ) );
|
||||
\IPS\Db::i()->delete( 'core_sys_cp_sessions', array( 'session_member_id=?', $member->member_id ) );
|
||||
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
|
||||
$member->member_login_key = '';
|
||||
/* When we reset the login key and call checkLoginKey(), it will save for us. Note that we are NOT sending an updated pass_hash cookie
|
||||
here, and that is instead the responsibility of any controllers that result in the password being updated. This is a central class
|
||||
and we may not be updating the current viewing user's password at this point. */
|
||||
$member->checkLoginKey();
|
||||
/* Change the password */
|
||||
$member->members_pass_salt = $member->generateSalt();
|
||||
$member->members_pass_hash = $member->encryptedPassword( $newPassword );
|
||||
$member->save();
|
||||
|
||||
/* Resync */
|
||||
$member->memberSync( 'onPassChange', array( $newPassword ) );
|
||||
}
|
||||
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief IPS Connect Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -161,7 +160,7 @@ class _Ipsconnect extends LoginAbstract
|
||||
$this->connectSuccessful( $member );
|
||||
|
||||
/* If we are still here and successful, redirect to master to log us in to each installation */
|
||||
\IPS\Request::i()->ref = (string) \IPS\Http\Url::external( $this->settings['url'] )->setQueryString(
|
||||
\IPS\Login::$forcedRedirectUrl = \IPS\Http\Url::external( $this->settings['url'] )->setQueryString(
|
||||
array(
|
||||
'do' => 'crossLogin',
|
||||
'key' => md5( $this->settings['key'] . $member->ipsconnect_id ),
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief LDAP Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief LinkedIn Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 20 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -28,6 +27,11 @@ class _Linkedin extends LoginAbstract
|
||||
*/
|
||||
public static $icon = 'linkedin';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = 'Linkedin';
|
||||
|
||||
/**
|
||||
* Get Form
|
||||
*
|
||||
@@ -64,6 +68,11 @@ class _Linkedin extends LoginAbstract
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
if( !isset( \IPS\Request::i()->code ) OR !\IPS\Request::i()->code )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'denied_oauth', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Get a token */
|
||||
$response = \IPS\Http\Url::external( "https://www.linkedin.com/uas/oauth2/accessToken?" . http_build_query( array(
|
||||
|
||||
+14
-6
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Windows Live Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -27,6 +26,11 @@ class _Live extends LoginAbstract
|
||||
* @brief Icon
|
||||
*/
|
||||
public static $icon = 'windows';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = 'Microsoft';
|
||||
|
||||
/**
|
||||
* Get Form
|
||||
@@ -64,6 +68,11 @@ class _Live extends LoginAbstract
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'CSRF_FAIL', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
if( !isset( \IPS\Request::i()->code ) OR !\IPS\Request::i()->code )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'denied_oauth', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
/* Send HTTP request */
|
||||
$response = \IPS\Http\Url::external( 'https://login.live.com/oauth20_token.srf' )->request()->post( array(
|
||||
@@ -188,5 +197,4 @@ class _Live extends LoginAbstract
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
}
|
||||
+106
-56
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 13 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS;
|
||||
@@ -58,7 +57,7 @@ class _Login
|
||||
{
|
||||
static::$allHandlers[ $row['login_key'] ] = \IPS\Login\LoginAbstract::constructFromData( $row );
|
||||
}
|
||||
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for IPS4 for example */ }
|
||||
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't been updated for 4.x for example */ }
|
||||
}
|
||||
|
||||
if ( \IPS\Dispatcher::hasInstance() === TRUE )
|
||||
@@ -98,7 +97,7 @@ class _Login
|
||||
{
|
||||
static::$handlers[ $row['login_key'] ] = \IPS\Login\LoginAbstract::constructFromData( $row );
|
||||
}
|
||||
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for IPS4 for example */ }
|
||||
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for 4.x for example */ }
|
||||
}
|
||||
|
||||
if( \IPS\Dispatcher::i()->controllerLocation == 'front' )
|
||||
@@ -115,6 +114,17 @@ class _Login
|
||||
|
||||
return static::$handlers;
|
||||
}
|
||||
|
||||
/**
|
||||
* Return a single handler object
|
||||
*
|
||||
* @throws UnderflowException
|
||||
* @return \IPS\Login
|
||||
*/
|
||||
public static function getHandler( $handler )
|
||||
{
|
||||
return \IPS\Login\LoginAbstract::constructFromData( \IPS\Db::i()->select( '*', 'core_login_handlers', array( 'login_key=?', $handler ) )->first() );
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief URL
|
||||
@@ -135,6 +145,11 @@ class _Login
|
||||
* @brief Show flag options (remember me, anonymous) on form?
|
||||
*/
|
||||
public $flagOptions = TRUE;
|
||||
|
||||
/**
|
||||
* @brief Which handler was used?
|
||||
*/
|
||||
public $usedHandler = NULL;
|
||||
|
||||
/**
|
||||
* Constructor
|
||||
@@ -147,6 +162,12 @@ class _Login
|
||||
$this->url = $url;
|
||||
}
|
||||
|
||||
/**
|
||||
* @brief Force a URL to send to post-login
|
||||
* @note Useful when you need to redirect the user to another URL that is not local to this installation
|
||||
*/
|
||||
public static $forcedRedirectUrl = NULL;
|
||||
|
||||
/**
|
||||
* Fetch the URL to redirect to
|
||||
*
|
||||
@@ -154,39 +175,43 @@ class _Login
|
||||
*/
|
||||
public static function getDestination()
|
||||
{
|
||||
$ref = NULL;
|
||||
/* If there's an explicit ref value, go there */
|
||||
if( !empty( \IPS\Request::i()->ref ) )
|
||||
/* Try and get a referrer... */
|
||||
try
|
||||
{
|
||||
try
|
||||
/* Are we forcing the user to be sent to a specific URL? */
|
||||
if( static::$forcedRedirectUrl !== NULL )
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( @base64_decode( \IPS\Request::i()->ref ) ?: \IPS\Request::i()->ref );
|
||||
return $ref;
|
||||
return static::$forcedRedirectUrl;
|
||||
}
|
||||
catch ( \Exception $e ) { }
|
||||
}
|
||||
|
||||
/* Don't redirect to an external domain unless explicitly requested, and don't redirect back to ACP */
|
||||
if( isset( $_SERVER['HTTP_REFERER'] ) AND empty( \IPS\Request::i()->ips_force_return ) )
|
||||
{
|
||||
if( parse_url( \IPS\Settings::i()->base_url, PHP_URL_HOST ) != parse_url( $_SERVER['HTTP_REFERER'], PHP_URL_HOST ) )
|
||||
/* Get the URL we need to redirect to */
|
||||
if ( isset( \IPS\Request::i()->ref ) and $decoded = @base64_decode( \IPS\Request::i()->ref ) )
|
||||
{
|
||||
unset( $_SERVER['HTTP_REFERER'] );
|
||||
$ref = \IPS\Http\Url::createFromString( $decoded );
|
||||
}
|
||||
elseif ( isset( $_SERVER['HTTP_REFERER'] ) )
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] );
|
||||
}
|
||||
else
|
||||
{
|
||||
$ourBaseReferer = str_replace( \IPS\Settings::i()->base_url, '', $_SERVER['HTTP_REFERER'] );
|
||||
|
||||
if( mb_strpos( $ourBaseReferer, \IPS\CP_DIRECTORY ) === 0 )
|
||||
{
|
||||
unset( $_SERVER['HTTP_REFERER'] );
|
||||
}
|
||||
throw new \DomainException;
|
||||
}
|
||||
|
||||
$ref = isset( $_SERVER['HTTP_REFERER'] ) ? \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal('');
|
||||
|
||||
/* Make sure it's internal and to the front-end */
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
{
|
||||
throw new \DomainException;
|
||||
}
|
||||
|
||||
/* Strip the csrf and return */
|
||||
return $ref->stripQueryString( 'csrfKey' );
|
||||
}
|
||||
/* And if anything goes wrong, just use the base URL */
|
||||
catch ( \Exception $e )
|
||||
{
|
||||
return \IPS\Http\Url::internal('');
|
||||
}
|
||||
|
||||
return isset( $ref ) ? $ref->stripQueryString( 'csrfKey' ) : \IPS\Http\Url::internal( '' );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -290,8 +315,8 @@ class _Login
|
||||
$classname = 'IPS\Helpers\Form\Email';
|
||||
}
|
||||
$standardForm->class = 'ipsForm_vertical';
|
||||
$standardForm->add( new $classname( 'auth', NULL, TRUE, array( '_loginType' => $standardTypes, 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'auth' ) );
|
||||
$standardForm->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'password' ) );
|
||||
$standardForm->add( new $classname( 'auth', NULL, TRUE, array( 'placeholder' => \IPS\Member::loggedIn()->language()->words['auth'], '_loginType' => $standardTypes, 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'auth' ) );
|
||||
$standardForm->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'placeholder' => \IPS\Member::loggedIn()->language()->addToStack( 'password', FALSE ), 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'password' ) );
|
||||
|
||||
/* Are we adding the referer value to the form? */
|
||||
if( !$skipReferer )
|
||||
@@ -306,7 +331,7 @@ class _Login
|
||||
{
|
||||
$standardForm->add( new \IPS\Helpers\Form\Checkbox( 'signin_anonymous' ) );
|
||||
}
|
||||
$standardForm->addButton( 'forgotten_password', 'link', \IPS\Http\Url::internal( 'app=core&module=system&controller=lostpass', 'front', 'lostpassword' ), 'ipsButton_link' );
|
||||
$standardForm->addButton( 'forgotten_password', 'link', \IPS\Http\Url::internal( 'app=core&module=system&controller=lostpass', 'front', 'lostpassword' ), 'ipsButton ipsButton_small ipsButton_fullWidth ipsButton_link' );
|
||||
}
|
||||
|
||||
$this->forms['_standard'] = $standardForm;
|
||||
@@ -387,7 +412,12 @@ class _Login
|
||||
/* If we passed, log in! */
|
||||
if ( $member->member_id )
|
||||
{
|
||||
/* http://community.invisionpower.com/4bugtrack/upgrading-within-admincp-r3097 - we can't find any reason not checking this is desired at this time */
|
||||
/* Set which handler processed it */
|
||||
if ( $handler !== '_standard' ) // If _standard, is set in authenticateStandard()
|
||||
{
|
||||
$this->usedHandler = $handler;
|
||||
}
|
||||
|
||||
//if( \IPS\Dispatcher::hasInstance() AND \IPS\Dispatcher::i()->controllerLocation != 'setup' )
|
||||
//{
|
||||
/* Check if the account is locked */
|
||||
@@ -466,6 +496,7 @@ class _Login
|
||||
try
|
||||
{
|
||||
$member = $handlers[ $key ]->authenticate( $values );
|
||||
$this->usedHandler = $key;
|
||||
break;
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
@@ -496,28 +527,9 @@ class _Login
|
||||
*/
|
||||
protected function checkIfAccountIsLocked( $member )
|
||||
{
|
||||
if ( \IPS\Settings::i()->ipb_bruteforce_attempts and isset( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) and count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) >= \IPS\Settings::i()->ipb_bruteforce_attempts )
|
||||
$unlockTime = static::accountUnlockTime( $member );
|
||||
if ( $unlockTime !== FALSE )
|
||||
{
|
||||
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
|
||||
{
|
||||
$failedLogins = $member->failed_logins[ \IPS\Request::i()->ipAddress() ];
|
||||
sort( $failedLogins );
|
||||
|
||||
while ( count( $failedLogins ) > \IPS\Settings::i()->ipb_bruteforce_attempts )
|
||||
{
|
||||
array_pop( $failedLogins );
|
||||
}
|
||||
$unlockTime = \IPS\DateTime::ts( array_pop( $failedLogins ) );
|
||||
$unlockTime->add( new \DateInterval( 'PT' . \IPS\Settings::i()->ipb_bruteforce_period . 'M' ) );
|
||||
$timeToUnlock = $unlockTime->diff( new DateTime() );
|
||||
|
||||
/* If Unlock Time is in the past, return FALSE to avoid the exception and allow login */
|
||||
if ( $unlockTime->getTimestamp() < time() )
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
|
||||
/* Notify the member if they've been locked */
|
||||
if( count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) == \IPS\Settings::i()->ipb_bruteforce_attempts )
|
||||
{
|
||||
@@ -535,7 +547,7 @@ class _Login
|
||||
|
||||
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
|
||||
{
|
||||
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_locked_unlock', FALSE, array( 'pluralize' => array( $timeToUnlock->format('%i') ) ) ) );
|
||||
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_locked_unlock', FALSE, array( 'pluralize' => array( $unlockTime->diff( new DateTime() )->format('%i') ) ) ) );
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -544,6 +556,44 @@ class _Login
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Check if an account is locked - returns FALSE if account is unlocked, an \IPS\DateTime object if the account is locked until a certain time, or TRUE if account is unlocked indefinitely
|
||||
*
|
||||
* @param \IPS\Member $member The account
|
||||
* @return \IPS\DateTime|bool
|
||||
*/
|
||||
public static function accountUnlockTime( $member )
|
||||
{
|
||||
if ( \IPS\Settings::i()->ipb_bruteforce_attempts and isset( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) and count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) >= \IPS\Settings::i()->ipb_bruteforce_attempts )
|
||||
{
|
||||
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
|
||||
{
|
||||
$failedLogins = $member->failed_logins[ \IPS\Request::i()->ipAddress() ];
|
||||
sort( $failedLogins );
|
||||
|
||||
while ( count( $failedLogins ) > \IPS\Settings::i()->ipb_bruteforce_attempts )
|
||||
{
|
||||
array_pop( $failedLogins );
|
||||
}
|
||||
$unlockTime = \IPS\DateTime::ts( array_pop( $failedLogins ) );
|
||||
$unlockTime->add( new \DateInterval( 'PT' . \IPS\Settings::i()->ipb_bruteforce_period . 'M' ) );
|
||||
|
||||
/* If Unlock Time is in the past, return FALSE to avoid the exception and allow login */
|
||||
if ( $unlockTime->getTimestamp() < time() )
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* Otherwise that is what we're returning */
|
||||
return $unlockTime;
|
||||
}
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Compare hashes in fixed length, time constant manner.
|
||||
*
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Abstract Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 15 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -57,6 +56,11 @@ abstract class _LoginAbstract extends \IPS\Node\Model
|
||||
* @brief Icon
|
||||
*/
|
||||
public static $icon = 'lock';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = NULL;
|
||||
|
||||
/**
|
||||
* @brief Disable the copy button - useful when the forms are very distinctly different
|
||||
@@ -322,7 +326,7 @@ abstract class _LoginAbstract extends \IPS\Node\Model
|
||||
$member->members_bitoptions['view_sigs'] = TRUE;
|
||||
|
||||
/* Set name - if it already exists, we'll leave it blank and they'll be prompted to fill it in */
|
||||
if ( $name !== NULL and ( !\IPS\Settings::i()->username_characters or preg_match( '/^[' . str_replace( '\-', '-', preg_quote( \IPS\Settings::i()->username_characters, '/' ) ) . ']*$/i', $name ) ) )
|
||||
if ( $name !== NULL and ( !\IPS\Settings::i()->username_characters or preg_match( '/^[' . str_replace( '\-', '-', preg_quote( \IPS\Settings::i()->username_characters, '/' ) ) . ']*$/iu', $name ) ) )
|
||||
{
|
||||
$existingUsername = \IPS\Member::load( $name, 'name' );
|
||||
if ( !$existingUsername->member_id )
|
||||
@@ -399,9 +403,9 @@ abstract class _LoginAbstract extends \IPS\Node\Model
|
||||
{
|
||||
$member->$k = $v;
|
||||
|
||||
if( $k == 'members_pass_hash' )
|
||||
if( $k == 'members_pass_hash' or $k == 'email' )
|
||||
{
|
||||
$member->member_login_key = '';
|
||||
$member->invalidateSessionsAndLogins( \IPS\Session::i()->id );
|
||||
}
|
||||
}
|
||||
$member->save();
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Twitter Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 18 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
@@ -28,6 +27,11 @@ class _Twitter extends LoginAbstract
|
||||
*/
|
||||
public static $icon = 'twitter';
|
||||
|
||||
/**
|
||||
* @brief Logo
|
||||
*/
|
||||
public static $logo = 'Twitter';
|
||||
|
||||
/**
|
||||
* @brief Share Service
|
||||
*/
|
||||
@@ -64,7 +68,7 @@ class _Twitter extends LoginAbstract
|
||||
{
|
||||
if ( isset( \IPS\Request::i()->denied ) )
|
||||
{
|
||||
throw new \IPS\Login\Exception( 'generic_error', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
throw new \IPS\Login\Exception( 'denied_oauth', \IPS\Login\Exception::INTERNAL_ERROR );
|
||||
}
|
||||
|
||||
try
|
||||
@@ -218,8 +222,20 @@ class _Twitter extends LoginAbstract
|
||||
unset( $params[ $k ] );
|
||||
}
|
||||
}
|
||||
|
||||
$signatureBaseString = mb_strtoupper( $method ) . '&' . rawurlencode( $url ) . '&' . rawurlencode( http_build_query( $OAuthAuthorization, NULL, '&' ) ) . ( count( $params ) ? ( rawurlencode( '&' ) . rawurlencode( http_build_query( $params, NULL, NULL, PHP_QUERY_RFC3986 ) ) ) : '' );
|
||||
|
||||
/* Media handling needs specific handling as a multipart form and not a signed param list */
|
||||
$media = NULL;
|
||||
if ( isset( $params['media'] ) )
|
||||
{
|
||||
$media = $params['media'];
|
||||
unset( $params['media'] );
|
||||
}
|
||||
|
||||
/* All keys sent in the signature must be in alphabetical order, that includes oAuth keys and user sent params */
|
||||
$allKeys = array_merge( $OAuthAuthorization, $params );
|
||||
ksort( $allKeys );
|
||||
|
||||
$signatureBaseString = mb_strtoupper( $method ) . '&' . rawurlencode( $url ) . '&' . rawurlencode( http_build_query( $allKeys, NULL, '&', PHP_QUERY_RFC3986 ) );
|
||||
$signingKey = rawurlencode( $this->settings['consumer_secret'] ) . '&' . rawurlencode( $secret ?: $token );
|
||||
$OAuthAuthorizationEncoded = array();
|
||||
foreach ( $OAuthAuthorization as $k => $v )
|
||||
@@ -233,9 +249,26 @@ class _Twitter extends LoginAbstract
|
||||
}
|
||||
}
|
||||
$OAuthAuthorizationHeader = 'OAuth ' . implode( ', ', $OAuthAuthorizationEncoded );
|
||||
|
||||
$headers = array( 'Authorization' => $OAuthAuthorizationHeader );
|
||||
|
||||
/* Build the multipart media request */
|
||||
if ( $media )
|
||||
{
|
||||
$mimeBoundary = sha1( microtime() );
|
||||
$headers['Content-Type'] = 'multipart/form-data; boundary=' . $mimeBoundary;
|
||||
|
||||
$data = '--' . $mimeBoundary . "\r\n";
|
||||
$data .= 'Content-Disposition: form-data; name="media";' . "\r\n";
|
||||
$data .= 'Content-Type: application/octet-stream' . "\r\n" . "\r\n";
|
||||
$data .= $media . "\r\n";
|
||||
$data .= '--' . $mimeBoundary . '--' . "\r\n" . "\r\n";
|
||||
|
||||
$params = $data;
|
||||
}
|
||||
|
||||
/* Send the request */
|
||||
return \IPS\Http\Url::external( $url )->request()->setHeaders( array( 'Authorization' => $OAuthAuthorizationHeader ) )->$method( $params );
|
||||
return \IPS\Http\Url::external( $url )->request()->setHeaders( $headers )->$method( $params );
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Internal Login Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 13 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Login;
|
||||
|
||||
Reference in new issue
Block a user