Version 4.2.0
This commit is contained in:
1 parent
0dc2aee5ed
commit
96997ddd8e
2074 files changed
+125454
-55780
No files matched your search
+41
-41
@@ -1,12 +1,11 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Front Session Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Community Suite
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 11 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
|
||||
namespace IPS\Session;
|
||||
@@ -78,7 +77,7 @@ class _Front extends \IPS\Session
|
||||
$session = NULL;
|
||||
|
||||
/* Get user agent info */
|
||||
$this->userAgent = \IPS\Http\Useragent::parse();
|
||||
$this->userAgent = \IPS\Http\Useragent::parse();
|
||||
|
||||
/* Get from the database */
|
||||
try
|
||||
@@ -126,7 +125,7 @@ class _Front extends \IPS\Session
|
||||
/* If this is a guest and the "running time" on this is less than 30 seconds ago, or if a member and less than 15 seconds ago, we don't need a database write */
|
||||
if ( ( !$session['member_id'] and $session['running_time'] > ( time() - 30 ) ) or ( $session['member_id'] and $session['running_time'] > ( time() - 15 ) ) )
|
||||
{
|
||||
$this->save = FALSE;
|
||||
$this->save = TRUE;
|
||||
}
|
||||
|
||||
/* Set member */
|
||||
@@ -146,49 +145,58 @@ class _Front extends \IPS\Session
|
||||
}
|
||||
|
||||
/* If we don't have a member, check the cookies */
|
||||
if ( !$this->member->member_id and isset( \IPS\Request::i()->cookie['member_id'] ) and isset( \IPS\Request::i()->cookie['pass_hash'] ) )
|
||||
$device = NULL;
|
||||
if ( !$this->member->member_id and isset( \IPS\Request::i()->cookie['device_key'] ) and isset( \IPS\Request::i()->cookie['member_id'] ) and isset( \IPS\Request::i()->cookie['login_key'] ) )
|
||||
{
|
||||
try
|
||||
/* Get the member we're trying to authenticate against - do not process cookie-based login if the account is locked */
|
||||
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
|
||||
if ( $member->member_id and \IPS\Login::accountUnlockTime( $member ) === FALSE )
|
||||
{
|
||||
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
|
||||
if ( $member->member_login_key AND \IPS\Request::i()->cookie['pass_hash'] AND \IPS\Login::compareHashes( (string) $member->member_login_key, (string) \IPS\Request::i()->cookie['pass_hash'] ) )
|
||||
/* Load and authenticate device device data */
|
||||
try
|
||||
{
|
||||
/* Authenticate */
|
||||
$device = \IPS\Member\Device::loadAndAuthenticate( \IPS\Request::i()->cookie['device_key'], $member, \IPS\Request::i()->cookie['login_key'] );
|
||||
|
||||
/* Refresh the device key cookie */
|
||||
\IPS\Request::i()->setCookie( 'device_key', \IPS\Request::i()->cookie['device_key'], ( new \IPS\DateTime )->add( new \DateInterval( 'P1Y' ) ) );
|
||||
|
||||
/* Set member in session */
|
||||
$this->member = $member;
|
||||
|
||||
/* Renew those cookies */
|
||||
$expire = new \IPS\DateTime;
|
||||
$expire->add( new \DateInterval( 'P3M' ) );
|
||||
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', $member->member_login_key, $expire );
|
||||
|
||||
if( isset( \IPS\Request::i()->cookie['anon_login'] ) and \IPS\Request::i()->cookie['anon_login'] )
|
||||
{
|
||||
\IPS\Request::i()->setCookie( 'anon_login', 1, $expire );
|
||||
}
|
||||
/* Update device */
|
||||
$device->updateAfterAuthentication( TRUE, NULL, FALSE );
|
||||
}
|
||||
else
|
||||
/* If the device_key/login_key combination wasn't valid, this may be someone trying to bruteforce... */
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
/* ... so log it as a failed login */
|
||||
$failedLogins = is_array( $member->failed_logins ) ? $member->failed_logins : array();
|
||||
$failedLogins[ \IPS\Request::i()->ipAddress() ][] = time();
|
||||
$member->failed_logins = $failedLogins;
|
||||
$member->save();
|
||||
|
||||
/* Then set us as a guest and clear out those cookies */
|
||||
$this->member = new \IPS\Member;
|
||||
\IPS\Request::i()->setCookie( 'member_id', NULL );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', NULL );
|
||||
\IPS\Request::i()->clearLoginCookies();
|
||||
}
|
||||
}
|
||||
catch ( \OutOfRangeException $e )
|
||||
// If the member no longer exists, or the account is locked, set us as a guest and clear out those cookies
|
||||
else
|
||||
{
|
||||
$this->member = new \IPS\Member;
|
||||
\IPS\Request::i()->setCookie( 'member_id', NULL );
|
||||
\IPS\Request::i()->setCookie( 'pass_hash', NULL );
|
||||
\IPS\Request::i()->clearLoginCookies();
|
||||
}
|
||||
}
|
||||
|
||||
/* Work out the type */
|
||||
if ( $this->member->member_id )
|
||||
{
|
||||
if ( ( $session and $session['login_type'] === static::LOGIN_TYPE_ANONYMOUS ) or isset( \IPS\Request::i()->cookie['anon_login'] ) and \IPS\Request::i()->cookie['anon_login'] )
|
||||
if ( ( $session and $session['login_type'] === static::LOGIN_TYPE_ANONYMOUS ) or $device and $device->anonymous )
|
||||
{
|
||||
$type = static::LOGIN_TYPE_ANONYMOUS;
|
||||
}
|
||||
else if ( ! $this->member->name or ! $this->member->email )
|
||||
else if ( !$this->member->name or !$this->member->email )
|
||||
{
|
||||
$type = static::LOGIN_TYPE_INCOMPLETE;
|
||||
}
|
||||
@@ -219,8 +227,8 @@ class _Front extends \IPS\Session
|
||||
'current_module' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_module'] : '' ) : '',
|
||||
'current_controller' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_controller'] : NULL ) : NULL,
|
||||
'current_id' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_id'] : NULL ) : intval( \IPS\Request::i()->id ),
|
||||
'uagent_key' => $this->userAgent->useragentKey,
|
||||
'uagent_version' => $this->userAgent->useragentVersion ?: '',
|
||||
'uagent_key' => $this->userAgent->browser ?: '',
|
||||
'uagent_version' => $this->userAgent->browserVersion ?: '',
|
||||
'uagent_type' => $this->userAgent->spider ? 'search' : 'browser',
|
||||
'search_thread_id' => $session ? intval( $session['search_thread_id'] ) : 0,
|
||||
'search_thread_time' => $session ? $session['search_thread_time'] : 0,
|
||||
@@ -236,7 +244,7 @@ class _Front extends \IPS\Session
|
||||
if( $this->userAgent->spider )
|
||||
{
|
||||
/* Is this Facebook? Do we need to treat them as a user of a different group? */
|
||||
if( $this->userAgent->useragentKey == 'facebook' )
|
||||
if( $this->userAgent->spider == 'facebook' )
|
||||
{
|
||||
if( \IPS\core\ShareLinks\Service::load( 'facebook', 'share_key' )->enabled )
|
||||
{
|
||||
@@ -262,14 +270,6 @@ class _Front extends \IPS\Session
|
||||
{
|
||||
parent::setMember( $member );
|
||||
|
||||
/* Make sure login key has been set */
|
||||
$member->checkLoginKey();
|
||||
|
||||
/* Set the cookie */
|
||||
$expire = new \IPS\DateTime;
|
||||
$expire->add( new \DateInterval( 'P3M' ) );
|
||||
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
|
||||
|
||||
/* Make sure session handler saves during write() */
|
||||
$this->save = TRUE;
|
||||
}
|
||||
@@ -283,7 +283,7 @@ class _Front extends \IPS\Session
|
||||
*/
|
||||
public function write( $sessionId, $data )
|
||||
{
|
||||
if ( $data !== $this->data['data'] or $this->data['member_id'] != $this->member->member_id )
|
||||
if ( !isset( $this->data['data'] ) or $data !== $this->data['data'] or $this->data['member_id'] != $this->member->member_id )
|
||||
{
|
||||
$this->save = TRUE;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user