Version 4.0.13.1

This commit is contained in:
Neo committed 2025-12-19 04:57:54 -08:00
1 parent f9e857d255
commit c6a86f0d9b
7517 files changed
+597400 -668041

No files matched your search

@@ -0,0 +1,376 @@
<?php
/**
* @brief ACP Dashboard
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @since 2 July 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\core\modules\admin\overview;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* ACP Dashboard
*/
class _dashboard extends \IPS\Dispatcher\Controller
{
/**
* Show the ACP dashboard
*
* @return void
*/
protected function manage()
{
\IPS\Output::i()->jsFiles = array_merge( \IPS\Output::i()->jsFiles, \IPS\Output::i()->js('admin_dashboard.js', 'core') );
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'system/dashboard.css', 'core', 'admin' ) );
/* Figure out which blocks we should show */
$toShow = $this->current( TRUE );
/* Now grab dashboard extensions */
$blocks = array();
$info = array();
foreach ( \IPS\Application::allExtensions( 'core', 'Dashboard', TRUE, 'core' ) as $key => $extension )
{
if ( !method_exists( $extension, 'canView' ) or $extension->canView() )
{
$info[ $key ] = array(
'name' => \IPS\Member::loggedIn()->language()->addToStack('block_' . $key ),
'key' => $key,
'app' => \substr( $key, 0, \strpos( $key, '_' ) )
);
if( method_exists( $extension, 'getBlock' ) )
{
foreach( $toShow as $row )
{
if( in_array( $key, $row ) )
{
$blocks[ $key ] = $extension->getBlock();
break;
}
}
}
}
}
/* ACP Bulletin */
$bulletin = isset( \IPS\Data\Store::i()->acpBulletin ) ? \IPS\Data\Store::i()->acpBulletin : NULL;
if ( !$bulletin or $bulletin['time'] < ( time() - 86400 ) )
{
try
{
$bulletins = \IPS\Http\Url::ips('bulletin')->request()->get()->decodeJson();
\IPS\Data\Store::i()->acpBulletin = array(
'time' => time(),
'content' => $bulletins
);
}
catch( \RuntimeException $e )
{
$bulletins = array();
}
}
else
{
$bulletins = $bulletin['content'];
}
foreach ( $bulletins as $k => $data )
{
if ( count( $data['files'] ) )
{
$skip = TRUE;
foreach ( $data['files'] as $file )
{
if ( filemtime( \IPS\ROOT_PATH . '/' . $file ) < $data['timestamp'] )
{
$skip = FALSE;
}
}
if ( $skip )
{
unset( $bulletins[ $k ] );
}
}
}
/* Warnings */
$warnings = array();
$tasks = \IPS\Db::i()->select( '*', 'core_tasks', 'lock_count >= 3' );
$keys = array();
foreach( $tasks as $task )
{
$keys[] = $task['key'];
}
if ( !empty( $keys ) )
{
$warnings[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_tasks_broken' ),
'description' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_tasks_broken_desc', TRUE, array( 'sprintf' => array( \IPS\Member::loggedIn()->language()->formatList( $keys ) ) ) )
);
}
if( isset( \IPS\Data\Store::i()->failedMailCount ) AND \IPS\Data\Store::i()->failedMailCount >= 3 )
{
$warnings[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_email_broken' ),
'description' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_email_broken_desc', TRUE )
);
}
$supportAccount = \IPS\Member::load( 'nobody@invisionpower.com', 'email' );
if ( $supportAccount->member_id )
{
$warnings[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_support_account' ),
'description' => \IPS\Member::loggedIn()->language()->addToStack( 'dashboard_support_account_desc', TRUE, array( 'sprintf' => array( $supportAccount->acpUrl() ) ) )
);
}
/* Get new core update available data */
$system = \IPS\Application::load( 'core' );
$update = array();
if( $system->update_version )
{
$versions = json_decode( $system->update_version, TRUE );
if ( is_array( $versions ) and !isset( $versions[0] ) and isset( $versions['longversion'] ) )
{
$versions = array( $versions );
}
$update = array();
foreach ( $versions as $data )
{
if( !empty($data['longversion']) AND $data['longversion'] > $system->long_version )
{
if( $data['released'] AND intval($data['released']) == $data['released'] AND \strlen($data['released']) == 10 )
{
$data['released'] = (string) \IPS\DateTime::ts( $data['released'] )->localeDate();
}
$update[] = $data;
}
}
}
/* Don't show the ACP header bar */
\IPS\Output::i()->hiddenElements[] = 'acpHeader';
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('dashboard');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'dashboard' )->dashboard( $update, $toShow, $blocks, $info, $bulletins, $warnings );
}
/**
* Return a json-encoded array of the current blocks to show
*
* @param bool $return Flag to indicate if the array should be returned instead of output
* @return void
*/
public function current( $return=FALSE )
{
if( \IPS\Settings::i()->acp_dashboard_blocks )
{
$blocks = json_decode( \IPS\Settings::i()->acp_dashboard_blocks, TRUE );
}
else
{
$blocks = array();
}
$toShow = isset( $blocks[ \IPS\Member::loggedIn()->member_id ] ) ? $blocks[ \IPS\Member::loggedIn()->member_id ] : array();
if( !$toShow OR !isset( $toShow['main'] ) OR !isset( $toShow['side'] ) )
{
$toShow = array(
'main' => array( 'core_BackgroundQueue', 'core_Registrations' ),
'side' => array( 'core_AdminNotes', 'core_OnlineUsers' ),
);
$blocks[ \IPS\Member::loggedIn()->member_id ] = $toShow;
\IPS\Settings::i()->acp_dashboard_blocks = json_encode( $blocks );
\IPS\Db::i()->update( 'core_sys_conf_settings', array( 'conf_value' => \IPS\Settings::i()->acp_dashboard_blocks ), array( 'conf_key=?', 'acp_dashboard_blocks' ) );
unset( \IPS\Data\Store::i()->settings );
}
if( $return === TRUE )
{
return $toShow;
}
\IPS\Output::i()->output = json_encode( $toShow );
}
/**
* Return an individual block's HTML
*
* @return void
*/
public function getBlock()
{
$output = '';
/* Loop through the dashboard extensions in the specified application */
foreach( \IPS\Application::load( \IPS\Request::i()->appKey )->extensions( 'core', 'Dashboard', 'core' ) as $key => $_extension )
{
if( \IPS\Request::i()->appKey . '_' . $key == \IPS\Request::i()->blockKey )
{
if( method_exists( $_extension, 'getBlock' ) )
{
$output = $_extension->getBlock();
}
break;
}
}
\IPS\Output::i()->output = $output;
}
/**
* Update our current block configuration/order
*
* @return void
* @note When submitted via AJAX, the array should be json-encoded
*/
public function update()
{
if( \IPS\Settings::i()->acp_dashboard_blocks )
{
$blocks = json_decode( \IPS\Settings::i()->acp_dashboard_blocks, TRUE );
}
else
{
$blocks = array();
}
$saveBlocks = \IPS\Request::i()->blocks;
if( !isset( $saveBlocks['main'] ) )
{
$saveBlocks['main'] = array();
}
if( !isset( $saveBlocks['side'] ) )
{
$saveBlocks['side'] = array();
}
$blocks[ \IPS\Member::loggedIn()->member_id ] = $saveBlocks;
\IPS\Settings::i()->acp_dashboard_blocks = json_encode( $blocks );
\IPS\Db::i()->update( 'core_sys_conf_settings', array( 'conf_value' => \IPS\Settings::i()->acp_dashboard_blocks ), array( 'conf_key=?', 'acp_dashboard_blocks' ) );
unset( \IPS\Data\Store::i()->settings );
if( \IPS\Request::i()->isAjax() )
{
\IPS\Output::i()->output = 1;
return;
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=dashboard" ), 'saved' );
}
/**
* Download latest version
*
* @return void
*/
public function upgrade()
{
/* Init */
\IPS\Output::i()->jsFiles = array_merge( \IPS\Output::i()->jsFiles, \IPS\Output::i()->js('admin_dashboard.js', 'core') );
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('ips_suite_upgrade');
/* Are all our apps up to date */
$coreAppVersion = \IPS\Application::load('core')->long_version;
foreach ( \IPS\Application::applications() as $application )
{
if ( in_array( $application->directory, \IPS\Application::$ipsApps ) and $application->long_version != $coreAppVersion )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'delta_upgrade_mismatch_versions', FALSE, array( 'sprintf' => array( $application->version, $application->_title, \IPS\Application::load('core')->version, $application->_title ) ) ), '1C283/1', 403, '' );
}
}
/* Build the login form */
$form = new \IPS\Helpers\Form( 'download', 'download' );
if ( isset( \IPS\Request::i()->version ) )
{
$form->hiddenValues['version'] = \IPS\Request::i()->version;
}
$form->addMessage('download_upgrade_blurb');
$form->add( new \IPS\Helpers\Form\Email( 'ips_email_address', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Password( 'ips_password', NULL, TRUE ) );
/* Handle submissions */
if ( $values = $form->values() )
{
$key = \IPS\IPS::licenseKey();
$url = \IPS\Http\Url::ips( 'build/' . $key['key'] )->setQueryString( 'ip', \IPS\Request::i()->ipAddress() );
if ( \IPS\USE_DEVELOPMENT_BUILDS )
{
$url = $url->setQueryString( 'development', 1 );
}
elseif ( isset( $values['version'] ) )
{
$url = $url->setQueryString( 'versionToDownload', $values['version'] );
}
if ( \IPS\CP_DIRECTORY !== 'admin' )
{
$url = $url->setQueryString( 'cp_directory', \IPS\CP_DIRECTORY );
}
try
{
$response = $url->request( 30 )->login( $values['ips_email_address'], $values['ips_password'] )->get();
switch ( $response->httpResponseCode )
{
case 200:
if ( !preg_match( '/^ips_[a-z0-9]{5}$/', (string) $response ) )
{
\IPS\Log::i( LOG_DEBUG )->write( (string) $response );
$form->error = \IPS\Member::loggedIn()->language()->addToStack('download_upgrade_error');
break;
}
else
{
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'overview' )->deltaUpgradeInstructions( \IPS\Http\Url::ips( 'download/' . $response ), $response );
return;
}
case 304:
if ( \IPS\Db::i()->select( 'MIN(app_long_version)', 'core_applications', \IPS\Db::i()->in( 'app_directory', \IPS\Application::$ipsApps ) )->first() < \IPS\Application::getAvailableVersion('core') )
{
\IPS\Output::i()->redirect( 'upgrade' );
}
$form->error = \IPS\Member::loggedIn()->language()->addToStack('download_upgrade_nothing');
break;
default:
$form->error = (string) $response;
}
}
catch ( \Exception $exception )
{
\IPS\Log::i( LOG_DEBUG )->write( get_class( $exception ) . "\n" . $exception->getCode() . ": " . $exception->getMessage() . "\n" . $exception->getTraceAsString() );
$form->error = \IPS\Member::loggedIn()->language()->addToStack('download_upgrade_error');
}
}
/* Display */
\IPS\Output::i()->output = $form;
}
}
@@ -0,0 +1,759 @@
<?php
/**
* @brief File Settings
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @since 06 May 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\core\modules\admin\overview;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* File Settings
*/
class _files extends \IPS\Dispatcher\Controller
{
/**
* Execute
*
* @return void
*/
public function execute()
{
parent::execute();
}
/**
* Manage Attachment Types
*
* @return void
*/
protected function manage()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'files_view' );
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('uploaded_files');
\IPS\Output::i()->sidebar['actions'] = array();
if ( \IPS\Member::loggedIn()->hasAcpRestriction( 'core', 'overview', 'files_settings' ) )
{
\IPS\Output::i()->sidebar['actions']['settings'] = array(
'icon' => 'cog',
'link' => \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=settings' ),
'title' => 'storage_settings',
);
\IPS\Output::i()->sidebar['actions']['images'] = array(
'icon' => 'cog',
'link' => \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=imagesettings' ),
'title' => 'image_settings',
);
}
if ( \IPS\Member::loggedIn()->hasAcpRestriction( 'core', 'overview', 'orphaned_files' ) )
{
\IPS\Output::i()->sidebar['actions']['orphaned'] = array(
'icon' => 'cog',
'link' => \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=orphaned' ),
'title' => 'orphaned_files',
'data' => array( 'confirm' => '', 'confirmMessage' => \IPS\Member::loggedIn()->language()->addToStack('orphaned_files_confirm') )
);
}
$table = new \IPS\Helpers\Table\Db( 'core_attachments', \IPS\Http\Url::internal( 'app=core&module=overview&controller=files' ) );
$table->filters = array(
'images' => "attach_is_image=1",
'files' => "attach_is_image=0",
);
$table->include = array( 'attach_file', 'attach_filesize', 'attach_date', 'attach_member_id' );
if ( $table->filter !== 'images' )
{
$table->include[] = 'attach_hits';
}
$table->noSort = array( 'attach_type' );
$table->quickSearch = 'attach_file';
$table->parsers = array(
'attach_file' => function( $val, $row ) use ( $table )
{
$url = \IPS\Http\Url::external( \IPS\File::get( 'core_Attachment', $row['attach_location'] )->url )->makeSafeForAcp( $row['attach_is_image'] );
if ( $row['attach_is_image'] and $table->filter === 'images' )
{
return "<a href='{$url}' target='_blank'><img src='{$url}' style='max-height:200px'></a>";
}
$val = htmlentities( $val, \IPS\HTMLENTITIES, 'UTF-8', FALSE );
return "<a href='{$url}' target='_blank'>{$val}</a>";
},
'attach_filesize' => function( $val )
{
if ( $val < 1024 )
{
return "{$val}B";
}
elseif ( $val < 1048576 )
{
return round( ( $val / 1024 ), 2 ) . 'KB';
}
elseif ( $val < 1073741824 )
{
return round( ( $val / 1048576 ), 2 ) . 'MB';
}
else
{
return round( ( $val / 1073741824 ), 2 ) . 'GB';
}
},
'attach_date' => function( $val )
{
return \IPS\DateTime::ts( $val );
},
'attach_hits' => function( $val, $row )
{
return $row['attach_is_image'] ? '' : $val;
},
'attach_member_id' => function( $val )
{
return "<a href='" . \IPS\Http\Url::internal( 'app=core&module=members&controller=members&do=edit&id=' . $val ) . "'>" . htmlentities( \IPS\Member::load( $val )->name, \IPS\HTMLENTITIES, 'UTF-8', FALSE ) . '</a>';
}
);
$table->advancedSearch = array(
'attach_file' => \IPS\Helpers\Table\SEARCH_CONTAINS_TEXT,
'attach_ext' => \IPS\Helpers\Table\SEARCH_CONTAINS_TEXT,
'attach_hits' => \IPS\Helpers\Table\SEARCH_NUMERIC,
'attach_date' => \IPS\Helpers\Table\SEARCH_DATE_RANGE,
'attach_member_id' => \IPS\Helpers\Table\SEARCH_MEMBER,
'attach_filesize' => \IPS\Helpers\Table\SEARCH_NUMERIC,
);
$table->rowButtons = function( $row )
{
$buttons = array();
$buttons['view'] = array(
'icon' => 'search',
'title' => 'attach_view_locations',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=lookup&id={$row['attach_id']}" ),
'data' => array( 'ipsDialog' => '', 'ipsDialog-title' => $row['attach_file'] )
);
if ( \IPS\Member::loggedIn()->hasAcpRestriction( 'core', 'overview', 'files_delete' ) )
{
$buttons['delete'] = array(
'icon' => 'times-circle',
'title' => 'delete',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=delete&id={$row['attach_id']}" ),
'data' => array( 'delete' => '' ),
);
}
return $buttons;
};
\IPS\Output::i()->output = (string) $table;
}
/**
* Lookup attachment locations
*
* @return void
*/
public function lookup()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'files_view' );
$loadedExtensions = array();
$locations = array();
foreach ( \IPS\Db::i()->select( '*', 'core_attachments_map', array( 'attachment_id=?', intval( \IPS\Request::i()->id ) ) ) as $map )
{
if ( !isset( $loadedExtensions[ $map['location_key'] ] ) )
{
$exploded = explode( '_', $map['location_key'] );
try
{
$extensions = \IPS\Application::load( $exploded[0] )->extensions( 'core', 'EditorLocations' );
if ( isset( $extensions[ $exploded[1] ] ) )
{
$loadedExtensions[ $map['location_key'] ] = $extensions[ $exploded[1] ];
}
}
catch ( \OutOfRangeException $e ){ }
}
if ( isset( $loadedExtensions[ $map['location_key'] ] ) )
{
try
{
if ( $url = $loadedExtensions[ $map['location_key'] ]->attachmentLookup( $map['id1'], $map['id2'], $map['id3'] ) )
{
$locations[] = $url;
}
}
catch ( \LogicException $e ) { }
}
}
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global' )->block( NULL, \IPS\Theme::i()->getTemplate( 'members', 'core', 'global' )->attachmentLocations( $locations, FALSE ) );
}
/**
* Delete attachment
*
* @return void
*/
public function delete()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'files_delete' );
try
{
$attachment = \IPS\Db::i()->select( '*', 'core_attachments', array( 'attach_id=?', \IPS\Request::i()->id ) )->first();
try
{
\IPS\File::get( 'core_Attachment', $attachment['attach_location'] )->delete();
\IPS\File::get( 'core_Attachment', $attachment['attach_thumb_location'] )->delete();
}
catch ( \Exception $e ) { }
\IPS\Db::i()->delete( 'core_attachments', array( 'attach_id=?', \IPS\Request::i()->id ) );
\IPS\Session::i()->log( 'acplogs__file_deleted', array( $attachment['attach_file'] => FALSE ) );
}
catch ( \UnderflowException $e ) { }
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=files" ) );
}
/**
* Image Settings
*
* @return void
*/
protected function imagesettings()
{
/* Init */
\IPS\Dispatcher::i()->checkAcpPermission( 'files_settings' );
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Radio( 'image_suite', \IPS\Settings::i()->image_suite, TRUE, array(
'options' => array( 'gd' => 'imagesuite_gd', 'imagemagick' => 'imagesuite_imagemagick' ),
'toggles' => array( 'imagemagick' => array(), 'gd' => array( 'image_jpg_quality', 'image_png_quality_gd' ) ),
'disabled'=> class_exists( 'Imagick', FALSE ) ? array() : array( 'imagemagick' )
) ) );
$form->add( new \IPS\Helpers\Form\Number( 'image_jpg_quality', \IPS\Settings::i()->image_jpg_quality, FALSE, array( 'min' => 0, 'max' => 100, 'range' => TRUE ), NULL, NULL, NULL, 'image_jpg_quality' ) );
$form->add( new \IPS\Helpers\Form\Number( 'image_png_quality_gd', \IPS\Settings::i()->image_png_quality_gd, FALSE, array( 'min' => 0, 'max' => 9, 'range' => TRUE ), NULL, NULL, NULL, 'image_png_quality_gd' ) );
if ( $values = $form->values() )
{
$form->saveAsSettings();
\IPS\Session::i()->log( 'acplogs__image_settings_updated' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=imagesettings' ), 'saved' );
}
/* Display */
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('image_settings');
\IPS\Output::i()->output = $form;
}
/**
* Upload Settings
*
* @return void
*/
protected function settings()
{
/* Init */
\IPS\Dispatcher::i()->checkAcpPermission( 'files_settings' );
$activeTab = isset( \IPS\Request::i()->tab ) ? \IPS\Request::i()->tab : 'settings';
/* Settings form */
if ( $activeTab === 'settings' )
{
$settings = json_decode( \IPS\Settings::i()->upload_settings, TRUE );
$configurations = array();
foreach ( \IPS\Db::i()->select( '*', 'core_file_storage' ) as $row )
{
$classname = 'IPS\File\\' . $row['method'];
$configurations[ $row['id'] ] = $classname::displayName( json_decode( $row['configuration'], TRUE ) );
}
$form = new \IPS\Helpers\Form;
$form->addMessage( 'filestorage_move_info' );
foreach ( \IPS\Application::allExtensions( 'core', 'FileStorage', FALSE, NULL, NULL, TRUE ) as $name => $obj )
{
$disabled = ( isset( $settings[ "filestorage__{$name}" ] ) and is_array( $settings[ "filestorage__{$name}" ] ) ) ? TRUE : FALSE;
$value = NULL;
if ( isset( $settings[ "filestorage__{$name}" ] ) )
{
if ( is_array( $settings[ "filestorage__{$name}" ] ) )
{
$copyOfSettings = $settings[ "filestorage__{$name}" ];
$value = array_shift( $copyOfSettings );
}
else
{
$value = $settings[ "filestorage__{$name}" ];
}
}
$form->add( new \IPS\Helpers\Form\Select( 'filestorage__' . $name, $value, TRUE, array( 'options' => $configurations, 'disabled' => $disabled ) ) );
if ( $disabled )
{
\IPS\Member::loggedIn()->language()->words[ 'filestorage__' . $name . '_warning' ] = \IPS\Member::loggedIn()->language()->addToStack( 'file_storage_move_in_progress' );
}
}
if ( $values = $form->values() )
{
$rebuild = FALSE;
/* Queue theme first */
if( isset( $values['filestorage__core_Theme'] ) and $settings['filestorage__core_Theme'] != $values['filestorage__core_Theme'] )
{
$rebuild = TRUE;
$extension = new \IPS\core\extensions\core\FileStorage\Theme;
\IPS\Task::queue( 'core', 'MoveFiles', array( 'storageExtension' => 'filestorage__core_Theme', 'oldConfiguration' => $settings[ 'filestorage__core_Theme' ], 'newConfiguration' => $values[ 'filestorage__core_Theme' ], 'count' => $extension->count() ), 1 );
/* Add to allowed storage methods so when moving files, we can accept old config or new config if move is in progress. Important: order is array(x, y) x is the new location (pos 0), y is the old location (pos 1)*/
$values['filestorage__core_Theme'] = array( $values['filestorage__core_Theme'], $settings['filestorage__core_Theme'] );
}
foreach ( $values as $k => $v )
{
if ( isset( $settings[$k] ) AND !is_array( $settings[$k] ) )
{
if ( $settings[ $k ] != $v and $k != 'filestorage__core_Theme' )
{
$rebuild = TRUE;
$exploded = explode( '_', $k );
$classname = "IPS\\{$exploded[2]}\\extensions\\core\\FileStorage\\{$exploded[3]}";
$extension = new $classname;
$count = $extension->count();
if ( $count )
{
\IPS\Task::queue( 'core', 'MoveFiles', array( 'storageExtension' => $k, 'oldConfiguration' => $settings[ $k ], 'newConfiguration' => $values[ $k ], 'count' => $count ), 2 );
/* Add to allowed storage methods so when moving files, we can accept old config or new config if move is in progress. Important: order is array(x, y) x is the new location (pos 0), y is the old location (pos 1)*/
$values[ $k ] = array( $v, $settings[ $k ] );
}
}
}
}
if( $rebuild )
{
\IPS\Task::queue( 'core', 'DeleteMovedFiles', array( 'delete' => true ), 5, array( 'delete' ) ); /* We use a key in the data array just to trigger the code that deletes duplicate tasks */
}
\IPS\Db::i()->update( 'core_sys_conf_settings', array( 'conf_value' => json_encode( $values ) ), array( 'conf_key=?', 'upload_settings' ) );
unset( \IPS\Data\Store::i()->settings );
/* Clear guest page caches */
\IPS\Data\Cache::i()->clearAll();
\IPS\Session::i()->log( 'acplogs__files_config_moved', array() );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal('app=core&module=overview&controller=files&do=settings&tab=settings'), 'saved' );
}
$activeTabContents = $form;
}
/* Or configurations table */
else
{
$table = new \IPS\Helpers\Table\Db( 'core_file_storage', \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=settings&tab=configurations" ) );
$table->include = array( 'filestorage_method' );
$table->noSort = array( 'filestorage_method' );
$table->parsers = array( 'filestorage_method' => function( $val, $row )
{
$classname = 'IPS\File\\' . $row['method'];
return $classname::displayName( json_decode( $row['configuration'], TRUE ) );
} );
$table->rootButtons = array( 'add' => array(
'icon' => 'plus',
'title' => 'add',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=configurationForm" )
) );
$table->rowButtons = function( $row )
{
return array(
'edit' => array(
'icon' => 'pencil',
'title' => 'edit',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=configurationForm&id={$row['id']}" )
),
'log' => array(
'icon' => 'search',
'title' => 'file_config_log_title',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=configurationLog&id={$row['id']}" )
),
'delete' => array(
'icon' => 'times-circle',
'title' => 'delete',
'link' => \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=configurationForm&id={$row['id']}&delete=1" )
),
);
};
$activeTabContents = $table;
}
/* Display */
if ( \IPS\Request::i()->isAjax() and !isset( \IPS\Request::i()->ajaxValidate ) )
{
\IPS\Output::i()->output = $activeTabContents;
return;
}
else
{
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('storage_settings');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global' )->tabs( array( 'settings' => 'filestorage_settings', 'configurations' => 'filestorage_configurations' ), $activeTab, $activeTabContents, \IPS\Http\Url::internal( "app=core&module=overview&controller=files&do=settings" ) );
}
}
/**
* Add/Edit Configuration
*
* @return void
*/
protected function configurationForm()
{
/* Get existing */
$current = NULL;
$currentHandlerSettings = array();
$createNewAndMove = FALSE;
if ( isset( \IPS\Request::i()->id ) )
{
try
{
$current = \IPS\Db::i()->select( '*', 'core_file_storage', array( 'id=?', intval( \IPS\Request::i()->id ) ) )->first();
$currentHandlerSettings = json_decode( $current['configuration'], TRUE );
if ( in_array( intval( \IPS\Request::i()->id ), json_decode( \IPS\Settings::i()->upload_settings, TRUE ) ) )
{
if ( isset( \IPS\Request::i()->delete ) )
{
\IPS\Output::i()->error( 'file_storage_in_use', '1C158/2', 403, '' );
}
else
{
$createNewAndMove = TRUE;
}
}
else
{
foreach ( \IPS\Db::i()->select( 'data', 'core_queue', array( '`key`=?', 'MoveFiles' ) ) as $data )
{
$data = json_decode( $data, TRUE );
if ( $data['oldConfiguration'] == \IPS\Request::i()->id )
{
\IPS\Output::i()->error( 'file_storage_move_out', '1C158/3', 403, '' );
}
elseif ( $data['newConfiguration'] == \IPS\Request::i()->id )
{
\IPS\Output::i()->error( 'file_storage_move_in', '1C158/4', 403, '' );
}
}
if ( isset( \IPS\Request::i()->delete ) )
{
\IPS\Db::i()->delete( 'core_file_storage', array( 'id=?', intval( \IPS\Request::i()->id ) ) );
unset( \IPS\Data\Store::i()->storageConfigurations );
\IPS\Session::i()->log( 'acplogs__files_config_removed', array() );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=settings&tab=configurations' ) );
}
}
}
catch ( \UnderflowException $e )
{
\IPS\Output::i()->error( 'node_error', '2C158/1', 404, '' );
}
}
/* Get handlers */
$handlers = array();
$handlerSettings = array();
$toggles = array();
foreach ( new \DirectoryIterator( \IPS\ROOT_PATH . '/system/File' ) as $f )
{
if ( !$f->isDot() and mb_substr( $f, -4 ) === '.php' and $f != 'File.php' and $f != 'Iterator.php' )
{
$key = mb_substr( $f, 0, -4 );
$handlers[ $key ] = 'filehandler__' . $key;
$class = 'IPS\File\\' . $key;
foreach ( $class::settings( $currentHandlerSettings ) as $k => $v )
{
if ( is_array( $v ) )
{
$settingClass = '\IPS\Helpers\Form\\' . $v['type'];
$default = isset( $currentHandlerSettings[ $k ] ) ? str_replace( '{root}', \IPS\ROOT_PATH, $currentHandlerSettings[ $k ] ) : NULL;
if ( isset( $v['default'] ) and !$default )
{
$default = str_replace( '{root}', \IPS\ROOT_PATH, $v['default'] );
}
$handlerSettings[ $key ][ $k ] = new $settingClass( "filehandler__{$key}_{$k}", $default, FALSE, isset( $v['options'] ) ? $v['options'] : array(), isset( $v['validate'] ) ? $v['validate'] : NULL, isset( $v['prefix'] ) ? $v['prefix'] : NULL, isset( $v['suffix'] ) ? $v['suffix'] : NULL, "{$key}_{$k}" );
}
else
{
$settingClass = '\IPS\Helpers\Form\\' . $v;
$handlerSettings[ $key ][ $k ] = new $settingClass( "filehandler__{$key}_{$k}", isset( $currentHandlerSettings[ $k ] ) ? $currentHandlerSettings[ $k ] : NULL, FALSE, array(), NULL, NULL, NULL, "{$key}_{$k}" );
}
$toggles[ $key ][ $k ] = "{$key}_{$k}";
}
}
}
/* Build form */
$form = new \IPS\Helpers\Form;
$form->hiddenValues['configurationId'] = isset( \IPS\Request::i()->id ) ? \IPS\Request::i()->id : 0;
if ( isset( \IPS\Request::i()->id ) AND in_array( intval( \IPS\Request::i()->id ), json_decode( \IPS\Settings::i()->upload_settings, TRUE ) ) and $current['method'] !== 'FileSystem')
{
$form->addMessage( 'files_edit_existing_and_used', 'ipsMessage ipsMessage_info' );
}
$form->add( new \IPS\Helpers\Form\Radio( 'filestorage_method', $current ? $current['method'] : 'FileSystem', TRUE, array( 'options' => $handlers, 'toggles' => $toggles ) ) );
foreach ( $handlerSettings as $handlerKey => $settings )
{
foreach ( $settings as $setting )
{
$form->add( $setting );
}
}
if ( $createNewAndMove )
{
$form->add( new \IPS\Helpers\Form\YesNo( 'filestorage_move', TRUE ) );
}
/* Handle submissions */
if ( $values = $form->values() )
{
try
{
if ( isset( $toggles[ $values['filestorage_method'] ] ) )
{
foreach ( $toggles[ $values['filestorage_method'] ] as $k => $v )
{
$currentHandlerSettings[ $k ] = str_replace( \IPS\ROOT_PATH, '{root}', $values[ 'filehandler__' . $v ] );
}
}
$classname = 'IPS\File\\' . $values['filestorage_method'];
if ( method_exists( $classname, 'testSettings' ) )
{
$classname::testSettings( $currentHandlerSettings );
}
/* Do we really need to create and move? */
if ( $current AND $createNewAndMove )
{
$currentConf = json_decode( $current['configuration'], TRUE );
$createNewAndMove = $classname::moveCheck( $currentHandlerSettings, $currentConf );
}
if ( $current === NULL or $createNewAndMove )
{
$insertId = \IPS\Db::i()->insert( 'core_file_storage', array(
'method' => $values['filestorage_method'],
'configuration' => json_encode( $currentHandlerSettings ),
) );
unset( \IPS\Data\Store::i()->storageConfigurations );
if ( $createNewAndMove )
{
$settings = json_decode( \IPS\Settings::i()->upload_settings, TRUE );
foreach ( $settings as $k => $v )
{
if ( $v == $current['id'] )
{
if ( $values['filestorage_move'] )
{
$exploded = explode( '_', $k );
try
{
$classname = "IPS\\{$exploded[2]}\\extensions\\core\\FileStorage\\{$exploded[3]}";
if( \IPS\Application::appIsEnabled( $exploded[2] ) AND class_exists( $classname ) )
{
$extension = new $classname;
\IPS\Task::queue( 'core', 'MoveFiles', array( 'storageExtension' => $k, 'oldConfiguration' => $v, 'newConfiguration' => $insertId, 'count' => $extension->count() ), 2 );
}
$settings[ $k ] = $insertId;
}
catch( \Exception $e ){}
}
else
{
$settings[ $k ] = $insertId;
}
}
}
\IPS\Db::i()->update( 'core_sys_conf_settings', array( 'conf_value' => json_encode( $settings ) ), array( 'conf_key=?', 'upload_settings' ) );
unset( \IPS\Data\Store::i()->settings );
if ( $values['filestorage_move'] )
{
\IPS\Task::queue( 'core', 'DeleteMovedFiles', array( 'delete' => true ), 5, array( 'delete' ) ); /* We use a key in the data array just to trigger the code that deletes duplicate tasks */
}
}
}
else
{
\IPS\Db::i()->update( 'core_file_storage', array( 'configuration' => json_encode( $currentHandlerSettings ) ), array( 'id=?', $current['id'] ) );
unset( \IPS\Data\Store::i()->storageConfigurations );
}
/* Clear guest page caches */
\IPS\Data\Cache::i()->clearAll();
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=settings&tab=configurations' ), 'saved' );
}
catch ( \LogicException $e )
{
$msg = $e->getMessage();
$form->error = \IPS\Member::loggedIn()->language()->addToStack( $msg );
}
}
\IPS\Output::i()->jsFiles = array_merge( \IPS\Output::i()->jsFiles, \IPS\Output::i()->js( 'admin_files.js', 'core' ) );
\IPS\Output::i()->globalControllers[] = 'core.admin.files.form';
/* Display */
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('storage_settings');
\IPS\Output::i()->output = $form;
}
/**
* Determine if a move is needed (ajax method)
*
* @return void
*/
protected function checkMoveNeeded()
{
try
{
$current = \IPS\Db::i()->select( '*', 'core_file_storage', array( 'id=?', intval( \IPS\Request::i()->id ) ) )->first();
}
catch( \UnderflowException $e )
{
\IPS\Output::i()->error( 'files_invalid_id', '3C158/5', 404, '' );
}
$currentConf = json_decode( $current['configuration'], TRUE );
$needsMoving = FALSE;
if ( in_array( intval( \IPS\Request::i()->id ), json_decode( \IPS\Settings::i()->upload_settings, TRUE ) ) )
{
foreach ( $currentConf as $k => $v )
{
$checkKey = 'filehandler__' . $current['method'] . '_' . $k;
if ( isset( \IPS\Request::i()->$checkKey ) )
{
$currentHandlerSettings[ $k ] = str_replace( \IPS\ROOT_PATH, '{root}', \IPS\Request::i()->$checkKey );
}
}
$classname = 'IPS\File\\' . $current['method'];
/* Do we really need to create and move? */
$needsMoving = $classname::moveCheck( $currentHandlerSettings, $currentConf );
}
\IPS\Output::i()->json( array( 'needsMoving' => (boolean) $needsMoving ) );
}
/**
* View logs for this configuration
*
* @return void
*/
protected function configurationLog()
{
$method = \IPS\Db::i()->select( '*', 'core_file_storage', array( 'id=?', intval( \IPS\Request::i()->id ) ) )->first();
$title = \IPS\Member::loggedIn()->language()->addToStack( 'file_config_log', NULL, array( 'sprintf' => array( $method['method'] ) ) );
/* Create the table */
$table = new \IPS\Helpers\Table\Db( 'core_file_logs', \IPS\Http\Url::internal( 'app=core&module=overview&controller=files&do=configurationLog&id=' . \IPS\Request::i()->id ), array( array( 'log_configuration_id=?', \IPS\Request::i()->id ) ) );
$table->langPrefix = 'files_';
$table->title = $title;
$table->quickSearch = 'log_filename';
$table->sortBy = 'log_date';
$table->filters = array(
'files_log_filter_error' => array('log_type=?', 'error' ),
'files_log_filter_move' => array('log_type=?', 'move' )
);
$table->include = array( 'log_date', 'log_type', 'log_action', 'log_msg', 'log_filename' );
$table->parsers = array(
'log_filename' => function( $val, $row )
{
return ( ! empty( $row['log_container'] ) ? $row['log_container'] . '/' : '' ) . $val;
},
'log_date' => function( $val )
{
return \IPS\DateTime::ts( $val )->localeDate();
},
'log_type' => function( $val )
{
return \IPS\Member::loggedIn()->language()->addToStack( 'files_type_' . $val );
},
'log_action' => function( $val )
{
return \IPS\Member::loggedIn()->language()->addToStack( 'files_action_' . $val );
}
);
/* Display */
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "&app=core&module=overview&controller=files&do=settings&tab=configurations" ), 'filestorage_settings' );
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'global', 'core' )->block( $title, (string) $table );
\IPS\Output::i()->title = $title;
}
/**
* Remove orphaned files
*
* @return void
*/
protected function orphaned()
{
foreach( \IPS\Db::i()->select( '*', 'core_file_storage', NULL, 'id' ) as $row )
{
\IPS\Task::queue( 'core', 'FindOrphanedFiles', array( 'configurationId' => $row['id'] ), 4, array( 'configurationId' ) );
}
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=files" ), 'orphaned_files_tasks_added' );
}
}
Whitespace-only changes.
@@ -0,0 +1,361 @@
<?php
/**
* @brief Security Settings
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @since 11 Jun 2013
* @version SVN_VERSION_NUMBER
*/
namespace IPS\core\modules\admin\overview;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* Security Settings
*/
class _security extends \IPS\Dispatcher\Controller
{
/**
* Execute
*
* @return void
*/
public function execute()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'security_manage' );
parent::execute();
}
/**
* Security Center
*
* @return void
*/
protected function manage()
{
/* Init */
$content = array();
\IPS\Output::i()->sidebar['actions'] = array(
'settings' => array(
'icon' => 'cog',
'link' => \IPS\Http\Url::internal( 'app=core&module=overview&controller=security&do=settings' ),
'title' => 'security_settings',
'data' => array( 'ipsDialog' => '', 'ipsDialog-title' => \IPS\Member::loggedIn()->language()->addToStack('security_settings') )
),
'list_admins' => array(
'icon' => 'key',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=members&filter=members_filter_administrators' ),
'title' => 'security_list_admins',
),
);
/* open_basedir */
$dir = @dir( '/' );
if ( $dir instanceof Directory )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('open_basedir_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('open_basedir_desc'),
'risk' => "high",
);
}
/* Htaccess Protection */
$needUploads = FALSE;
foreach( \IPS\Db::i()->select( '*', 'core_file_storage', array( 'method=?', 'FileSystem' ) ) as $uploads )
{
$uploads = json_decode( $uploads['configuration'], TRUE );
if( isset( $uploads['dir'] ) )
{
$uploads['dir'] = str_replace( '{root}', \IPS\ROOT_PATH, $uploads['dir'] );
if( !is_file( $uploads['dir'] . '/.htaccess' ) )
{
$needUploads = TRUE;
}
}
}
$storeSettings = json_decode( \IPS\STORE_CONFIG, TRUE );
if ( ( $needUploads OR
( \IPS\STORE_METHOD == 'FileSystem' AND !is_file( str_replace( '{root}', \IPS\ROOT_PATH, $storeSettings['path'] ) . '/.htaccess' ) ) ) AND !\IPS\NO_WRITES )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('htaccess_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('htaccess_desc'),
'risk' => "high",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=htaccess" ),
);
}
/* Configuration File */
if ( is_writable( \IPS\ROOT_PATH . '/conf_global.php' ) AND !\IPS\NO_WRITES )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('conf_writeable_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('conf_writeable_desc'),
'risk' => "high",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=conf" ),
);
}
/* Disabled PHP Functions */
$functionsToDisable = array( 'exec', 'system', 'passhtru', 'pcntl_exec', 'popen', 'proc_open', 'shell_exec' );
$showingFunctionWarning = FALSE;
foreach ( $functionsToDisable as $k => $function )
{
if ( function_exists( $function ) )
{
$showingFunctionWarning = TRUE;
}
else
{
unset( $functionsToDisable[ $k ] );
}
}
if ( $showingFunctionWarning )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('disable_functions_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('disable_functions_desc', FALSE, array( 'sprintf' => array( implode( ', ', $functionsToDisable ) ) ) ),
'risk' => "high",
);
}
/* Display Errors */
if ( ini_get( 'display_errors' ) )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('display_errors_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('display_errors_desc'),
'risk' => "medium",
);
}
/* ACP Directory Name */
if ( \IPS\CP_DIRECTORY == 'admin' )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_desc'),
'risk' => "low",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_learn_more'), 'action' => "app=core&module=overview&controller=security&do=renameAdmin" ),
);
}
/* ACP Password Protection */
if ( ! is_file( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htaccess' ) AND !\IPS\NO_WRITES )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('admin_pass_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('admin_pass_desc'),
'risk' => "low",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=acpHtaccess" ),
);
}
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('security_center');
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'overview' )->security( $content );
}
/**
* Security Settings
*
* @return void
*/
protected function settings()
{
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\YesNo( 'security_remove_acp_link', !\IPS\Settings::i()->security_remove_acp_link, FALSE ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) ); //
if ( $values = $form->values() )
{
$values['security_remove_acp_link'] = $values['security_remove_acp_link'] ? FALSE : TRUE;
$form->saveAsSettings( $values );
\IPS\Session::i()->log( 'acplogs__security_settings' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'saved' );
}
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('security_settings');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate('global')->block( 'storage_settings', $form );
}
/**
* Change conf global permissions
*
* @return void
*/
protected function conf()
{
/* INIT */
$done = FALSE;
/* Try... */
if ( !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
{
\IPS\Output::i()->error( 'conf_not_altered', '2C258/2', 500, '' );
}
/* All Done */
\IPS\Session::i()->log( 'acplogs__security_conf' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'conf_altered' );
}
/**
* Add htaccess files to writeable directory
*
* @return void
*/
protected function htaccess()
{
/* INIT */
$errors = array();
$deny = <<<EOF
#<ipb-protection>
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml)">
Order allow,deny
Deny from all
</Files>
#</ipb-protection>
EOF;
foreach( \IPS\Db::i()->select( '*', 'core_file_storage', array( 'method=?', 'FileSystem' ) ) as $uploads )
{
$uploads = json_decode( $uploads['configuration'], TRUE );
if( isset( $uploads['dir'] ) )
{
$uploads['dir'] = str_replace( '{root}', \IPS\ROOT_PATH, $uploads['dir'] );
if( !is_file( $uploads['dir'] . '/.htaccess' ) )
{
if ( !@\file_put_contents( $uploads['dir'] . '/.htaccess', $deny ) )
{
$errors[] = $uploads['dir'];
}
}
}
}
if ( isset( $uploadSettings['FileSystem']['dir'] ) )
{
$directory = $uploadSettings['FileSystem']['dir'];
if ( !@\file_put_contents( $directory . '/.htaccess', $deny ) )
{
$errors[] = $directory;
}
}
$storeSettings = json_decode( \IPS\STORE_CONFIG, TRUE );
if ( \IPS\STORE_METHOD == 'FileSystem' )
{
$directory = str_replace( '{root}', \IPS\ROOT_PATH, $storeSettings['path'] );
if ( !@\file_put_contents( $directory . '/.htaccess', $deny ) )
{
$errors[] = $directory;
}
}
if( count( $errors ) )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'htaccess_not_written', FALSE, array( 'sprintf' => \IPS\Member::loggedIn()->language()->formatList( $errors ) ) ), '2C258/1', 403, '', array(), $deny );
}
/* All Done */
\IPS\Session::i()->log( 'acplogs__security_htaccess_writeable' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'htaccess_written' );
}
/**
* Rename ACP directory
*
* @return void
*/
protected function renameAdmin()
{
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title');
\IPS\Output::i()->breadcrumb[] = array( NULL, \IPS\Output::i()->title );
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'overview' )->securityRenameAdmin();
}
/**
* ACP Htaccess Protection
*
* @return void
*/
protected function acpHtaccess()
{
if ( !is_writable( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'err_not_writable', FALSE, array( 'sprintf' => array( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) ) ), '1C258/5', 403, '' );
}
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Text( 'username', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE ) );
if ( $values = $form->values() )
{
$done = FALSE;
/* See this for an explanation why ErrorDocument is needed: http://www.myriadinteractive.com/blog/view/id/29/conflict-between-apache-url-rewriting-and-basic-authentication */
$htaccess_auth = "ErrorDocument 401 \"Unauthorized Access\"\n"
. "AuthType Basic\n"
. "AuthName \"IPS Community Suite AdminCP\"\n"
. 'AuthUserFile "' . \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . "/.htpasswd\"\n"
. "Require valid-user\n";
$htaccess_pw = $values['username'] . ":" .
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['password'] : crypt( $values['password'], base64_encode( $values['password'] ) ) );
if ( $FH = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htpasswd', 'w' ) )
{
\fwrite( $FH, $htaccess_pw );
\fclose( $FH );
$FF = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htaccess', 'w' );
\fwrite( $FF, $htaccess_auth );
\fclose( $FF );
$done = TRUE;
\IPS\Session::i()->log( 'acplogs__security_acp_password' );
}
/* All Done */
if ( $done )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'admin_pass_written' );
}
else
{
\IPS\Output::i()->error( 'admin_pass_not_written', '1C258/3', 403, '' );
}
}
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->message( 'admin_pass_warning', 'warning' );
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('admin_pass_title');
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'global' )->block( \IPS\Output::i()->title, $form );
}
}