Version 4.2.0

This commit is contained in:
Neo committed 2025-12-19 05:44:59 -08:00
1 parent 0dc2aee5ed
commit 96997ddd8e
2074 files changed
+125454 -55780

No files matched your search

+41 -41
View File
@@ -1,12 +1,11 @@
<?php
/**
* @brief Front Session Handler
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Community Suite
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 11 Mar 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\Session;
@@ -78,7 +77,7 @@ class _Front extends \IPS\Session
$session = NULL;
/* Get user agent info */
$this->userAgent = \IPS\Http\Useragent::parse();
$this->userAgent = \IPS\Http\Useragent::parse();
/* Get from the database */
try
@@ -126,7 +125,7 @@ class _Front extends \IPS\Session
/* If this is a guest and the "running time" on this is less than 30 seconds ago, or if a member and less than 15 seconds ago, we don't need a database write */
if ( ( !$session['member_id'] and $session['running_time'] > ( time() - 30 ) ) or ( $session['member_id'] and $session['running_time'] > ( time() - 15 ) ) )
{
$this->save = FALSE;
$this->save = TRUE;
}
/* Set member */
@@ -146,49 +145,58 @@ class _Front extends \IPS\Session
}
/* If we don't have a member, check the cookies */
if ( !$this->member->member_id and isset( \IPS\Request::i()->cookie['member_id'] ) and isset( \IPS\Request::i()->cookie['pass_hash'] ) )
$device = NULL;
if ( !$this->member->member_id and isset( \IPS\Request::i()->cookie['device_key'] ) and isset( \IPS\Request::i()->cookie['member_id'] ) and isset( \IPS\Request::i()->cookie['login_key'] ) )
{
try
/* Get the member we're trying to authenticate against - do not process cookie-based login if the account is locked */
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
if ( $member->member_id and \IPS\Login::accountUnlockTime( $member ) === FALSE )
{
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
if ( $member->member_login_key AND \IPS\Request::i()->cookie['pass_hash'] AND \IPS\Login::compareHashes( (string) $member->member_login_key, (string) \IPS\Request::i()->cookie['pass_hash'] ) )
/* Load and authenticate device device data */
try
{
/* Authenticate */
$device = \IPS\Member\Device::loadAndAuthenticate( \IPS\Request::i()->cookie['device_key'], $member, \IPS\Request::i()->cookie['login_key'] );
/* Refresh the device key cookie */
\IPS\Request::i()->setCookie( 'device_key', \IPS\Request::i()->cookie['device_key'], ( new \IPS\DateTime )->add( new \DateInterval( 'P1Y' ) ) );
/* Set member in session */
$this->member = $member;
/* Renew those cookies */
$expire = new \IPS\DateTime;
$expire->add( new \DateInterval( 'P3M' ) );
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
\IPS\Request::i()->setCookie( 'pass_hash', $member->member_login_key, $expire );
if( isset( \IPS\Request::i()->cookie['anon_login'] ) and \IPS\Request::i()->cookie['anon_login'] )
{
\IPS\Request::i()->setCookie( 'anon_login', 1, $expire );
}
/* Update device */
$device->updateAfterAuthentication( TRUE, NULL, FALSE );
}
else
/* If the device_key/login_key combination wasn't valid, this may be someone trying to bruteforce... */
catch ( \OutOfRangeException $e )
{
/* ... so log it as a failed login */
$failedLogins = is_array( $member->failed_logins ) ? $member->failed_logins : array();
$failedLogins[ \IPS\Request::i()->ipAddress() ][] = time();
$member->failed_logins = $failedLogins;
$member->save();
/* Then set us as a guest and clear out those cookies */
$this->member = new \IPS\Member;
\IPS\Request::i()->setCookie( 'member_id', NULL );
\IPS\Request::i()->setCookie( 'pass_hash', NULL );
\IPS\Request::i()->clearLoginCookies();
}
}
catch ( \OutOfRangeException $e )
// If the member no longer exists, or the account is locked, set us as a guest and clear out those cookies
else
{
$this->member = new \IPS\Member;
\IPS\Request::i()->setCookie( 'member_id', NULL );
\IPS\Request::i()->setCookie( 'pass_hash', NULL );
\IPS\Request::i()->clearLoginCookies();
}
}
/* Work out the type */
if ( $this->member->member_id )
{
if ( ( $session and $session['login_type'] === static::LOGIN_TYPE_ANONYMOUS ) or isset( \IPS\Request::i()->cookie['anon_login'] ) and \IPS\Request::i()->cookie['anon_login'] )
if ( ( $session and $session['login_type'] === static::LOGIN_TYPE_ANONYMOUS ) or $device and $device->anonymous )
{
$type = static::LOGIN_TYPE_ANONYMOUS;
}
else if ( ! $this->member->name or ! $this->member->email )
else if ( !$this->member->name or !$this->member->email )
{
$type = static::LOGIN_TYPE_INCOMPLETE;
}
@@ -219,8 +227,8 @@ class _Front extends \IPS\Session
'current_module' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_module'] : '' ) : '',
'current_controller' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_controller'] : NULL ) : NULL,
'current_id' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['current_id'] : NULL ) : intval( \IPS\Request::i()->id ),
'uagent_key' => $this->userAgent->useragentKey,
'uagent_version' => $this->userAgent->useragentVersion ?: '',
'uagent_key' => $this->userAgent->browser ?: '',
'uagent_version' => $this->userAgent->browserVersion ?: '',
'uagent_type' => $this->userAgent->spider ? 'search' : 'browser',
'search_thread_id' => $session ? intval( $session['search_thread_id'] ) : 0,
'search_thread_time' => $session ? $session['search_thread_time'] : 0,
@@ -236,7 +244,7 @@ class _Front extends \IPS\Session
if( $this->userAgent->spider )
{
/* Is this Facebook? Do we need to treat them as a user of a different group? */
if( $this->userAgent->useragentKey == 'facebook' )
if( $this->userAgent->spider == 'facebook' )
{
if( \IPS\core\ShareLinks\Service::load( 'facebook', 'share_key' )->enabled )
{
@@ -262,14 +270,6 @@ class _Front extends \IPS\Session
{
parent::setMember( $member );
/* Make sure login key has been set */
$member->checkLoginKey();
/* Set the cookie */
$expire = new \IPS\DateTime;
$expire->add( new \DateInterval( 'P3M' ) );
\IPS\Request::i()->setCookie( 'member_id', $member->member_id, $expire );
/* Make sure session handler saves during write() */
$this->save = TRUE;
}
@@ -283,7 +283,7 @@ class _Front extends \IPS\Session
*/
public function write( $sessionId, $data )
{
if ( $data !== $this->data['data'] or $this->data['member_id'] != $this->member->member_id )
if ( !isset( $this->data['data'] ) or $data !== $this->data['data'] or $this->data['member_id'] != $this->member->member_id )
{
$this->save = TRUE;
}