Version 4.2.0

This commit is contained in:
Neo committed 2025-12-19 05:44:59 -08:00
1 parent 0dc2aee5ed
commit 96997ddd8e
2074 files changed
+125454 -55780

No files matched your search

+106 -56
View File
@@ -1,12 +1,11 @@
<?php
/**
* @brief Login Handler
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Community Suite
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 13 Mar 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS;
@@ -58,7 +57,7 @@ class _Login
{
static::$allHandlers[ $row['login_key'] ] = \IPS\Login\LoginAbstract::constructFromData( $row );
}
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for IPS4 for example */ }
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't been updated for 4.x for example */ }
}
if ( \IPS\Dispatcher::hasInstance() === TRUE )
@@ -98,7 +97,7 @@ class _Login
{
static::$handlers[ $row['login_key'] ] = \IPS\Login\LoginAbstract::constructFromData( $row );
}
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for IPS4 for example */ }
catch ( \RuntimeException $e ) { /* Skip over any which error (may happen if they haven't bee updated for 4.x for example */ }
}
if( \IPS\Dispatcher::i()->controllerLocation == 'front' )
@@ -115,6 +114,17 @@ class _Login
return static::$handlers;
}
/**
* Return a single handler object
*
* @throws UnderflowException
* @return \IPS\Login
*/
public static function getHandler( $handler )
{
return \IPS\Login\LoginAbstract::constructFromData( \IPS\Db::i()->select( '*', 'core_login_handlers', array( 'login_key=?', $handler ) )->first() );
}
/**
* @brief URL
@@ -135,6 +145,11 @@ class _Login
* @brief Show flag options (remember me, anonymous) on form?
*/
public $flagOptions = TRUE;
/**
* @brief Which handler was used?
*/
public $usedHandler = NULL;
/**
* Constructor
@@ -147,6 +162,12 @@ class _Login
$this->url = $url;
}
/**
* @brief Force a URL to send to post-login
* @note Useful when you need to redirect the user to another URL that is not local to this installation
*/
public static $forcedRedirectUrl = NULL;
/**
* Fetch the URL to redirect to
*
@@ -154,39 +175,43 @@ class _Login
*/
public static function getDestination()
{
$ref = NULL;
/* If there's an explicit ref value, go there */
if( !empty( \IPS\Request::i()->ref ) )
/* Try and get a referrer... */
try
{
try
/* Are we forcing the user to be sent to a specific URL? */
if( static::$forcedRedirectUrl !== NULL )
{
$ref = \IPS\Http\Url::createFromString( @base64_decode( \IPS\Request::i()->ref ) ?: \IPS\Request::i()->ref );
return $ref;
return static::$forcedRedirectUrl;
}
catch ( \Exception $e ) { }
}
/* Don't redirect to an external domain unless explicitly requested, and don't redirect back to ACP */
if( isset( $_SERVER['HTTP_REFERER'] ) AND empty( \IPS\Request::i()->ips_force_return ) )
{
if( parse_url( \IPS\Settings::i()->base_url, PHP_URL_HOST ) != parse_url( $_SERVER['HTTP_REFERER'], PHP_URL_HOST ) )
/* Get the URL we need to redirect to */
if ( isset( \IPS\Request::i()->ref ) and $decoded = @base64_decode( \IPS\Request::i()->ref ) )
{
unset( $_SERVER['HTTP_REFERER'] );
$ref = \IPS\Http\Url::createFromString( $decoded );
}
elseif ( isset( $_SERVER['HTTP_REFERER'] ) )
{
$ref = \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] );
}
else
{
$ourBaseReferer = str_replace( \IPS\Settings::i()->base_url, '', $_SERVER['HTTP_REFERER'] );
if( mb_strpos( $ourBaseReferer, \IPS\CP_DIRECTORY ) === 0 )
{
unset( $_SERVER['HTTP_REFERER'] );
}
throw new \DomainException;
}
$ref = isset( $_SERVER['HTTP_REFERER'] ) ? \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal('');
/* Make sure it's internal and to the front-end */
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
{
throw new \DomainException;
}
/* Strip the csrf and return */
return $ref->stripQueryString( 'csrfKey' );
}
/* And if anything goes wrong, just use the base URL */
catch ( \Exception $e )
{
return \IPS\Http\Url::internal('');
}
return isset( $ref ) ? $ref->stripQueryString( 'csrfKey' ) : \IPS\Http\Url::internal( '' );
}
/**
@@ -290,8 +315,8 @@ class _Login
$classname = 'IPS\Helpers\Form\Email';
}
$standardForm->class = 'ipsForm_vertical';
$standardForm->add( new $classname( 'auth', NULL, TRUE, array( '_loginType' => $standardTypes, 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'auth' ) );
$standardForm->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'password' ) );
$standardForm->add( new $classname( 'auth', NULL, TRUE, array( 'placeholder' => \IPS\Member::loggedIn()->language()->words['auth'], '_loginType' => $standardTypes, 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'auth' ) );
$standardForm->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'placeholder' => \IPS\Member::loggedIn()->language()->addToStack( 'password', FALSE ), 'bypassProfanity' => TRUE ), NULL, NULL, NULL, 'password' ) );
/* Are we adding the referer value to the form? */
if( !$skipReferer )
@@ -306,7 +331,7 @@ class _Login
{
$standardForm->add( new \IPS\Helpers\Form\Checkbox( 'signin_anonymous' ) );
}
$standardForm->addButton( 'forgotten_password', 'link', \IPS\Http\Url::internal( 'app=core&module=system&controller=lostpass', 'front', 'lostpassword' ), 'ipsButton_link' );
$standardForm->addButton( 'forgotten_password', 'link', \IPS\Http\Url::internal( 'app=core&module=system&controller=lostpass', 'front', 'lostpassword' ), 'ipsButton ipsButton_small ipsButton_fullWidth ipsButton_link' );
}
$this->forms['_standard'] = $standardForm;
@@ -387,7 +412,12 @@ class _Login
/* If we passed, log in! */
if ( $member->member_id )
{
/* http://community.invisionpower.com/4bugtrack/upgrading-within-admincp-r3097 - we can't find any reason not checking this is desired at this time */
/* Set which handler processed it */
if ( $handler !== '_standard' ) // If _standard, is set in authenticateStandard()
{
$this->usedHandler = $handler;
}
//if( \IPS\Dispatcher::hasInstance() AND \IPS\Dispatcher::i()->controllerLocation != 'setup' )
//{
/* Check if the account is locked */
@@ -466,6 +496,7 @@ class _Login
try
{
$member = $handlers[ $key ]->authenticate( $values );
$this->usedHandler = $key;
break;
}
catch ( \IPS\Login\Exception $e )
@@ -496,28 +527,9 @@ class _Login
*/
protected function checkIfAccountIsLocked( $member )
{
if ( \IPS\Settings::i()->ipb_bruteforce_attempts and isset( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) and count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) >= \IPS\Settings::i()->ipb_bruteforce_attempts )
$unlockTime = static::accountUnlockTime( $member );
if ( $unlockTime !== FALSE )
{
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
{
$failedLogins = $member->failed_logins[ \IPS\Request::i()->ipAddress() ];
sort( $failedLogins );
while ( count( $failedLogins ) > \IPS\Settings::i()->ipb_bruteforce_attempts )
{
array_pop( $failedLogins );
}
$unlockTime = \IPS\DateTime::ts( array_pop( $failedLogins ) );
$unlockTime->add( new \DateInterval( 'PT' . \IPS\Settings::i()->ipb_bruteforce_period . 'M' ) );
$timeToUnlock = $unlockTime->diff( new DateTime() );
/* If Unlock Time is in the past, return FALSE to avoid the exception and allow login */
if ( $unlockTime->getTimestamp() < time() )
{
return FALSE;
}
}
/* Notify the member if they've been locked */
if( count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) == \IPS\Settings::i()->ipb_bruteforce_attempts )
{
@@ -535,7 +547,7 @@ class _Login
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
{
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_locked_unlock', FALSE, array( 'pluralize' => array( $timeToUnlock->format('%i') ) ) ) );
throw new \IPS\Login\Exception( \IPS\Member::loggedIn()->language()->addToStack( 'login_err_locked_unlock', FALSE, array( 'pluralize' => array( $unlockTime->diff( new DateTime() )->format('%i') ) ) ) );
}
else
{
@@ -544,6 +556,44 @@ class _Login
}
}
/**
* Check if an account is locked - returns FALSE if account is unlocked, an \IPS\DateTime object if the account is locked until a certain time, or TRUE if account is unlocked indefinitely
*
* @param \IPS\Member $member The account
* @return \IPS\DateTime|bool
*/
public static function accountUnlockTime( $member )
{
if ( \IPS\Settings::i()->ipb_bruteforce_attempts and isset( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) and count( $member->failed_logins[ \IPS\Request::i()->ipAddress() ] ) >= \IPS\Settings::i()->ipb_bruteforce_attempts )
{
if ( \IPS\Settings::i()->ipb_bruteforce_period and \IPS\Settings::i()->ipb_bruteforce_unlock )
{
$failedLogins = $member->failed_logins[ \IPS\Request::i()->ipAddress() ];
sort( $failedLogins );
while ( count( $failedLogins ) > \IPS\Settings::i()->ipb_bruteforce_attempts )
{
array_pop( $failedLogins );
}
$unlockTime = \IPS\DateTime::ts( array_pop( $failedLogins ) );
$unlockTime->add( new \DateInterval( 'PT' . \IPS\Settings::i()->ipb_bruteforce_period . 'M' ) );
/* If Unlock Time is in the past, return FALSE to avoid the exception and allow login */
if ( $unlockTime->getTimestamp() < time() )
{
return FALSE;
}
/* Otherwise that is what we're returning */
return $unlockTime;
}
return TRUE;
}
return FALSE;
}
/**
* Compare hashes in fixed length, time constant manner.
*