Version 4.0.13.1

This commit is contained in:
Neo committed 2025-12-19 04:57:54 -08:00
1 parent f9e857d255
commit c6a86f0d9b
7517 files changed
+597400 -668041

No files matched your search

Whitespace-only changes.
@@ -0,0 +1,42 @@
<?php
/**
* @brief Send/Discard handler for pending support replies
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 25 Apr 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
try
{
$reply = \IPS\nexus\Support\Reply::load( \IPS\Request::i()->id );
if ( \IPS\Request::i()->key !== md5( $reply->item()->email_key . $reply->date ) )
{
throw new \OutOfRangeException;
}
}
catch ( \OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2X206/1', 404, '' );
}
if ( $reply->type !== \IPS\nexus\Support\Reply::REPLY_PENDING )
{
\IPS\Output::i()->error( 'support_reply_not_pending', '1X206/2', 403, '' );
}
if ( \IPS\Request::i()->send )
{
$reply->sendPending();
}
else
{
$reply->delete();
}
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core', 'front' )->blankTemplate( \IPS\Theme::i()->getTemplate( 'support', 'nexus', 'front' )->pendingDone( \IPS\Request::i()->send ? 'support_pending_sent' : 'support_pending_discarded' ) ) );
@@ -0,0 +1,53 @@
<?php
/**
* @brief 2Checkout Gateway
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 18 Mar 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
try
{
$transaction = \IPS\nexus\Transaction::load( \IPS\Request::i()->nexustransactionid );
if ( $transaction->status !== \IPS\nexus\Transaction::STATUS_PENDING )
{
throw new \OutofRangeException;
}
}
catch ( \OutOfRangeException $e )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=nexus&module=payments&controller=checkout&do=transaction&id=&t=" . \IPS\Request::i()->nexustransactionid, 'front', 'nexus_checkout', \IPS\Settings::i()->nexus_https ) );
}
$settings = json_decode( $transaction->method->settings, TRUE );
$hash = mb_strtoupper( md5( $settings['word'] . $settings['sid'] . ( \IPS\NEXUS_TEST_GATEWAYS ? 1 : \IPS\Request::i()->order_number ) . number_format( $transaction->amount->amount, 2 ) ) );
if ( $hash !== \IPS\Request::i()->key )
{
\IPS\Output::i()->redirect( $transaction->invoice->checkoutUrl()->setQueryString( array( '_step' => 'checkout_pay', 'err' => $transaction->member->language()->get('gateway_err') ) ) );
}
if ( \IPS\Request::i()->credit_card_processed !== 'Y' )
{
\IPS\Output::i()->redirect( $transaction->invoice->checkoutUrl()->setQueryString( array( '_step' => 'checkout_pay', 'err' => $transaction->member->language()->get('card_refused') ) ) );
}
$transaction->gw_id = \IPS\Request::i()->order_number;
$transaction->save();
$maxMind = NULL;
if ( \IPS\Settings::i()->maxmind_key )
{
$maxMind = new \IPS\nexus\Fraud\MaxMind\Request;
$maxMind->setTransaction( $transaction );
}
$transaction->checkFraudRulesAndCapture( $maxMind );
$transaction->sendNotification();
\IPS\Session::i()->setMember( $transaction->invoice->member ); // This is in case the checkout was a guest, meaning checkFraudRulesAndCapture() may have just created an account. There is no security issue as we have just verified they were just bounced back from 2CheckOut
\IPS\Output::i()->redirect( $transaction->url() );
@@ -0,0 +1,90 @@
<?php
/**
* @brief Authorize.Net DPM Gateway
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 17 Mar 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
try
{
$invoice = \IPS\nexus\Invoice::load( \IPS\Request::i()->x_invoice_num );
}
catch ( \Exception $e )
{
\IPS\Output::i()->sendOutput( '', 404 );
exit;
}
try
{
/* Load Gateway */
$gateway = \IPS\nexus\Gateway::load( \IPS\Request::i()->payment_method );
$settings = json_decode( $gateway->settings, TRUE );
/* Check MD5 hash */
if ( \IPS\Request::i()->x_MD5_Hash != mb_strtoupper( md5( $settings['hash'] . $settings['login'] . \IPS\Request::i()->x_trans_id . \IPS\Request::i()->x_amount ) ) )
{
throw new \Exception( $invoice->member->language()->addToStack('gateway_err') );
}
/* Was it accepted? */
if ( \IPS\Request::i()->x_response_code != 1 )
{
throw new \IPS\nexus\Gateway\AuthorizeNet\Exception( \IPS\Request::i()->x_response_reason_code );
}
/* Create a transaction */
$transaction = new \IPS\nexus\Transaction;
$transaction->member = \IPS\Member::load( \IPS\Request::i()->x_cust_id );
$transaction->invoice = $invoice;
$transaction->method = $gateway;
$transaction->amount = \IPS\Request::i()->x_amount;
$transaction->currency = $invoice->currency;
$transaction->gw_id = \IPS\Request::i()->x_trans_id;
$transaction->ip = \IPS\Request::i()->x_customer_ip;
$extra = $transaction->extra;
$extra['lastFour'] = str_replace( 'X', '', \IPS\Request::i()->x_account_number );
$transaction->extra = $extra;
$transaction->auth = \IPS\DateTime::create()->add( new \DateInterval( 'P30D' ) );
/* Create a MaxMind request */
$maxMind = NULL;
if ( \IPS\Settings::i()->maxmind_key )
{
$maxMind = new \IPS\nexus\Fraud\MaxMind\Request;
$maxMind->setTransaction( $transaction );
$maxMind->setTransactionType( 'creditcard' );
$maxMind->setAVS( \IPS\Request::i()->x_avs_code );
}
/* Check Fraud Rules and capture */
$transaction->checkFraudRulesAndCapture( $maxMind );
$transaction->sendNotification();
/* Show thanks screen */
$url = $transaction->url();
}
catch ( \Exception $e )
{
$url = $invoice->checkoutUrl()->setQueryString( array( '_step' => 'checkout_pay', 'err' => $e->getMessage() ) );
}
?>
<html>
<head>
<script type='text/javascript' charset='utf-8'>
window.location='<?php echo $url; ?>';
</script>
<noscript>
<meta http-equiv='refresh' content='1;url=<?php echo $url; ?>'>
</noscript>
</head>
<body></body>
</html>
Whitespace-only changes.
@@ -0,0 +1,52 @@
<?php
/**
* @brief PayPal Gateway
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 07 Mar 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
\IPS\Session\Front::i();
try
{
$transaction = \IPS\nexus\Transaction::load( \IPS\Request::i()->nexusTransactionId );
if ( $transaction->status !== \IPS\nexus\Transaction::STATUS_PENDING )
{
throw new \OutofRangeException;
}
}
catch ( \OutOfRangeException $e )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=nexus&module=payments&controller=checkout&do=transaction&id=&t=" . \IPS\Request::i()->nexusTransactionId, 'front', 'nexus_checkout', \IPS\Settings::i()->nexus_https ) );
}
try
{
$response = $transaction->method->api( "payments/payment/{$transaction->gw_id}/execute", array(
'payer_id' => \IPS\Request::i()->PayerID,
) );
$maxMind = NULL;
if ( \IPS\Settings::i()->maxmind_key )
{
$maxMind = new \IPS\nexus\Fraud\MaxMind\Request;
$maxMind->setTransaction( $transaction );
$maxMind->setTransactionType( 'paypal' );
}
$transaction->checkFraudRulesAndCapture( $maxMind );
$transaction->sendNotification();
\IPS\Session::i()->setMember( $transaction->invoice->member ); // This is in case the checkout was a guest, meaning checkFraudRulesAndCapture() may have just created an account. There is no security issue as we have just verified they were just bounced back from PayPal
\IPS\Output::i()->redirect( $transaction->url() );
}
catch ( \Exception $e )
{
\IPS\Output::i()->redirect( $transaction->invoice->checkoutUrl()->setQueryString( array( '_step' => 'checkout_pay', 'err' => $e->getMessage() ) ) );
}
@@ -0,0 +1,64 @@
<?php
/**
* @brief SagePay Gateway
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 19 Mar 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
function returnData( $status, $detail, $returnUrl )
{
echo "Status={$status}\r\nStatusDetail={$detail}\r\nRedirectURL={$returnUrl}";
exit;
}
/* Load */
try
{
$transaction = \IPS\nexus\Transaction::load( \IPS\Request::i()->VendorTxCode );
if ( $transaction->status !== \IPS\nexus\Transaction::STATUS_PENDING )
{
throw new \OutofRangeException;
}
}
catch ( \OutOfRangeException $e )
{
returnData( 'ERROR', 'NO_TRANSACTION', \IPS\Settings::i()->base_url );
}
/* Authenticate */
$settings = json_decode( $transaction->method->settings, TRUE );
$extra = $transaction->extra;
if ( \IPS\Request::i()->VPSSignature !== mb_strtoupper( md5( \IPS\Request::i()->VPSTxId . \IPS\Request::i()->VendorTxCode . \IPS\Request::i()->Status . \IPS\Request::i()->TxAuthNo . mb_strtolower( $settings['vendor'] ) . \IPS\Request::i()->AVSCV2 . $extra['sagepaySecurityKey'] . \IPS\Request::i()->AddressResult . \IPS\Request::i()->PostCodeResult . \IPS\Request::i()->CV2Result . \IPS\Request::i()->GiftAid . \IPS\Request::i()->__get('3DSecureStatus') . \IPS\Request::i()->CAVV . \IPS\Request::i()->AddressStatus . \IPS\Request::i()->PayerStatus . \IPS\Request::i()->CardType . \IPS\Request::i()->Last4Digits . \IPS\Request::i()->DeclineCode . \IPS\Request::i()->ExpiryDate . \IPS\Request::i()->FraudResponse . \IPS\Request::i()->BankAuthCode ) ) )
{
returnData( 'INVALID', 'MD5', $transaction->invoice->checkoutUrl()->setQueryString( array( '_step' => 'checkout_pay', 'err' => $transaction->member->language()->get( 'gateway_err' ) ) ) );
}
/* Save the auth code */
$extra['sagepayAuth'] = \IPS\Request::i()->TxAuthNo;
$transaction->extra = $extra;
$transaction->save();
/* Handle */
if ( \IPS\Request::i()->Status === 'OK' )
{
$maxMind = NULL;
if ( \IPS\Settings::i()->maxmind_key )
{
$maxMind = new \IPS\nexus\Fraud\MaxMind\Request;
$maxMind->setTransaction( $transaction );
}
$transaction->checkFraudRulesAndCapture( $maxMind );
$transaction->sendNotification();
}
/* Respond */
returnData( 'OK', 'MD5', $transaction->url() );
Whitespace-only changes.
@@ -0,0 +1,315 @@
<?php
/**
* @brief License Key API
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 01 Apr 2015
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
if ( \IPS\NEXUS_LKEY_API_ALLOW_IP_OVERRIDE )
{
$_SERVER['REMOTE_ADDR'] = isset( \IPS\Request::i()->ip ) ? \IPS\Request::i()->ip : $_SERVER['REMOTE_ADDR'];
}
class ApiException extends \Exception { }
class Api
{
/**
* Output Error
*
* @param int $code Status code
* @param string $message Status message
* @return void
*/
public function error( $code, $message )
{
\IPS\Output::i()->sendOutput( json_encode( array( 'errorCode' => $code, 'errorMessage' => $message ) ), 400, 'application/json' );
}
/**
* Get key
*
* @param bool $validateIdentifier Should the identifier be validated?
* @return \IPS\nexus\Purchase\LicenseKey
*/
protected function getKey( $validateIdentifier=FALSE )
{
try
{
$key = \IPS\nexus\Purchase\LicenseKey::load( isset( \IPS\Request::i()->key ) ? \IPS\Request::i()->key : NULL );
if ( $validateIdentifier and $identifier = $this->getIdentifier( $key ) and ( !isset( \IPS\Request::i()->identifier ) or $identifier != \IPS\Request::i()->identifier ) )
{
throw new ApiException( 'BAD_KEY_OR_ID', 101 );
}
if ( !$key->active )
{
throw new ApiException( 'INACTIVE', 102 );
}
if ( $key->purchase->cancelled )
{
throw new ApiException( 'INACTIVE', 103 );
}
if ( !$key->purchase->active )
{
throw new ApiException( 'INACTIVE', 104 );
}
return $key;
}
catch ( \OutOfRangeException $e )
{
throw new ApiException( 'BAD_KEY_OR_ID', 101 );
}
}
/**
* Get identifier
*
* @param \IPS\nexus\Purchase\LicenseKey $key The license key
* @return string|NULL
*/
protected function getIdentifier( \IPS\nexus\Purchase\LicenseKey $key )
{
$identifier = NULL;
switch ( $key->identifier )
{
case 'name':
$identifier = \IPS\nexus\Customer::load( $key->member )->cm_name;
break;
case 'email':
$identifier = \IPS\nexus\Customer::load( $key->member )->email;
break;
case 'username':
$identifier = \IPS\nexus\Customer::load( $key->member )->name;
break;
default:
$cfields = $key->purchase->custom_fields;
if ( isset( $cfields[ $key->identifier ] ) )
{
$identifier = $cfields[ $key->identifier ];
}
break;
}
return $identifier;
}
/**
* Activate
*
* @return void
*/
public function activate()
{
$key = $this->getKey( FALSE );
if ( $key->max_uses != -1 and $key->uses >= $key->max_uses )
{
throw new ApiException( 'MAX_USES', 201 );
}
$identifier = $this->getIdentifier( $key );
$providedIdentifier = isset( \IPS\Request::i()->identifier ) ? \IPS\Request::i()->identifier : NULL;
if ( isset( \IPS\Request::i()->setIdentifier ) and \IPS\Request::i()->setIdentifier )
{
if ( $identifier != $providedIdentifier )
{
if ( $identifier or in_array( $key->identifier, array( 'name', 'email', 'username' ) ) )
{
throw new ApiException( 'BAD_KEY_OR_ID', 101 );
}
else
{
$cfields = $key->purchase->custom_fields;
$cfields[ $key->identifier ] = \IPS\Request::i()->setIdentifier;
$key->purchase->custom_fields = $cfields;
$key->purchase->save();
}
}
}
elseif( $identifier != $providedIdentifier )
{
throw new ApiException( 'BAD_KEY_OR_ID', 101 );
}
if ( defined( 'NEXUS_LKEY_API_ALLOW_IP_OVERRIDE' ) )
{
$ip = $this->params['ip'] ? $this->params['ip'] : $_SERVER['REMOTE_ADDR'];
}
else
{
$ip = $_SERVER['REMOTE_ADDR'];
}
$activateData = $key->activate_data;
$k = empty( $activateData ) ? 0 : max( array_keys( $activateData ) );
$k++;
$activateData[ $k ] = array(
'activated' => time(),
'ip' => $ip,
'last_checked' => 0,
'extra' => isset( \IPS\Request::i()->extra ) ? json_decode( \IPS\Request::i()->extra ) : NULL,
);
$key->activate_data = $activateData;
$key->uses++;
$key->save();
\IPS\nexus\Customer::load( $key->member )->log( 'lkey', array( 'type' => 'activated', 'key' => $key->key, 'ps_id' => $key->purchase->id ), FALSE );
\IPS\Output::i()->sendOutput( json_encode( array( 'response' => 'OKAY', 'usage_id' => $k ) ), 200, 'application/json' );
}
/**
* Check
*
* @return void
*/
public function check()
{
try
{
$key = $this->getKey();
}
catch ( ApiException $e )
{
switch ( $e->getCode() )
{
case 102:
case 103:
\IPS\Output::i()->sendOutput( json_encode( array( 'status' => 'INACTIVE' ) ), 200, 'application/json' );
case 104:
\IPS\Output::i()->sendOutput( json_encode( array( 'status' => 'EXPIRED' ) ), 200, 'application/json' );
default:
throw $e;
}
}
$activateData = $key->activate_data;
if ( !isset( \IPS\Request::i()->usage_id ) or !isset( $activateData[ \IPS\Request::i()->usage_id ] ) )
{
throw new ApiException( 'BAD_USAGE_ID', 303 );
}
if ( \IPS\NEXUS_LKEY_API_CHECK_IP and $activateData[ \IPS\Request::i()->usage_id ]['ip'] != $_SERVER['REMOTE_ADDR'] )
{
throw new ApiException( 'BAD_IP', 304 );
}
$activateData[ \IPS\Request::i()->usage_id ]['last_checked'] = time();
$key->activate_data = $activateData;
$key->save();
\IPS\Output::i()->sendOutput( json_encode( array( 'status' => 'ACTIVE', 'uses' => $key->uses, 'max_uses' => $key->max_uses ) ), 200, 'application/json' );
}
/**
* Get Information
*
* @return void
*/
public function info()
{
$key = $this->getKey();
$children = array();
foreach ( $key->purchase->children( NULL ) as $child )
{
$children[ $child->id ] = array(
'id' => $child->id,
'name' => $child->name,
'app' => $child->app,
'type' => $child->type,
'item_id' => $child->item_id,
'active' => $child->cancelled ? 0 : $child->active,
'start' => $child->start,
'expire' => $child->expire,
'lkey' => $child->licenseKey() ? $child->licenseKey()->key : NULL,
);
}
\IPS\Output::i()->sendOutput( json_encode( array(
'key' => $key->key,
'identifier' => $this->getIdentifier( $key ),
'generated' => $key->generated->getTimestamp(),
'expires' => $key->purchase->expire ? $key->purchase->expire->getTimestamp() : NULL,
'usage_data' => $key->activate_data,
'purchase_id' => $key->purchase->id,
'purchase_name' => $key->purchase->name,
'purchase_pkg' => $key->purchase->item_id,
'purchase_active' => $key->purchase->cancelled ? FALSE : $key->purchase->active,
'purchase_start' => $key->purchase->start->getTimestamp(),
'purchase_expire' => $key->purchase->expire ? $key->purchase->expire->getTimestamp() : NULL,
'purchase_children' => $children,
'customer_name' => \IPS\nexus\Customer::load( $key->member )->cm_name,
'customer_email' => \IPS\nexus\Customer::load( $key->member )->email,
'uses' => $key->uses,
'max_uses' => $key->max_uses
) ), 200, 'application/json' );
}
/**
* Update extra information
*
* @return void
*/
public function updateExtra()
{
$key = $this->getKey();
$activateData = $key->activate_data;
if ( !isset( \IPS\Request::i()->usage_id ) or !isset( $activateData[ \IPS\Request::i()->usage_id ] ) )
{
throw new ApiException( 'BAD_USAGE_ID', 303 );
}
if ( \IPS\NEXUS_LKEY_API_CHECK_IP and $activateData[ \IPS\Request::i()->usage_id ]['ip'] != $_SERVER['REMOTE_ADDR'] )
{
throw new ApiException( 'BAD_IP', 304 );
}
$activateData[ \IPS\Request::i()->usage_id ]['extra'] = isset( \IPS\Request::i()->extra ) ? json_decode( \IPS\Request::i()->extra ) : NULL;
$key->activate_data = $activateData;
$key->save();
\IPS\Output::i()->sendOutput( json_encode( array( 'status' => 'OKAY' ) ), 200, 'application/json' );
}
}
$api = new api;
if ( !\IPS\NEXUS_LKEY_API_DISABLE )
{
foreach ( array( 'activate', 'check', 'info', 'updateExtra' ) as $k )
{
if ( isset( \IPS\Request::i()->$k ) )
{
try
{
$api->$k();
}
catch ( ApiException $e )
{
$api->error( $e->getMessage(), $e->getCode() );
}
catch ( Exception $e )
{
$api->error( 0, 'INTERNAL_ERROR' );
}
}
}
$api->error( 0, 'BAD_METHOD' );
}
else
{
$api->error( 0, 'API_DISABLED' );
}
Whitespace-only changes.
@@ -0,0 +1,53 @@
<?php
/**
* @brief Monitoring Respond
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
* @license http://www.invisionpower.com/legal/standards/
* @package IPS Social Suite
* @subpackage Nexus
* @since 07 Aug 2014
* @version SVN_VERSION_NUMBER
*/
require_once '../../../../init.php';
try
{
$server = \IPS\nexus\Hosting\Server::load( \IPS\Request::i()->server );
}
catch ( \OutOfRangeException $e )
{
\IPS\Output::i()->error( 'node_error', '2X230/1', 404, '' );
}
if ( !$server->monitor_fails )
{
\IPS\Output::i()->error( 'monitor_respond_err_online', '1X230/2', 403, '' );
}
if ( \IPS\Request::i()->a === 'a' )
{
if ( $server->monitor_acknowledged )
{
\IPS\Output::i()->error( 'monitor_respond_err_acknowledged', '1X230/3', 403, '' );
}
else
{
$server->monitor_acknowledged = TRUE;
$server->save();
$server->monitoringAcknowledged( \IPS\Request::i()->by );
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core', 'front' )->blankTemplate( \IPS\Theme::i()->getTemplate( 'hosting', 'nexus', 'front' )->monitorRespond( 'monitor_respond_acknowleged' ) ), 200, 'text/html', \IPS\Output::i()->httpHeaders );
}
}
elseif ( \IPS\Request::i()->a === 'r' )
{
$server->monitor_fails = 0;
$server->monitor_acknowledged = 0;
$server->save();
$server->monitoringReset( \IPS\Request::i()->by );
\IPS\Output::i()->sendOutput( \IPS\Theme::i()->getTemplate( 'global', 'core', 'front' )->blankTemplate( \IPS\Theme::i()->getTemplate( 'hosting', 'nexus', 'front' )->monitorRespond( 'monitor_respond_reset' ) ), 200, 'text/html', \IPS\Output::i()->httpHeaders );
}