Version 3.4.5

This commit is contained in:
Neo committed 2025-12-19 00:38:12 -08:00
1 parent fb6b5baabc
commit e4478369d8
1360 files changed
+228921 -179445

No files matched your search

+3 -3
View File
@@ -3,9 +3,9 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Remote API integration gateway file
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
+3 -3
View File
@@ -3,9 +3,9 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Remote API integration gateway file
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
* @todo http://community.invisionpower.com/tracker/issue-20920-liveid-logout/
*
+53 -65
View File
@@ -3,17 +3,17 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Remote API Server
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2013-03-21 17:38:09 -0400 (Thu, 21 Mar 2013) $
* </pre>
*
* @author $Author: bfarber $
* @author $Author: AndyMillne $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 12109 $
*
*/
@@ -92,6 +92,13 @@ class API_Server
if ( $this->__authenticate( $api_key, $api_module, 'fetchOnlineUsers' ) !== FALSE )
{
//-----------------------------------------
// Add log
//-----------------------------------------
$this->addLogging( $api_key );
if ( !ipsRegistry::$settings['au_cutoff'] )
{
ipsRegistry::$settings[ 'au_cutoff'] = 15 ;
@@ -232,6 +239,12 @@ class API_Server
if ( $this->__authenticate( $api_key, $api_module, 'fetchStats' ) !== FALSE )
{
//-----------------------------------------
// Add log
//-----------------------------------------
$this->addLogging( $api_key );
$stats = $this->registry->cache()->getCache('stats');
$most_time = ipsRegistry::getClass('class_localization')->getDate( $stats['most_date'], 'LONG' );
@@ -281,6 +294,13 @@ class API_Server
if ( $this->__authenticate( $api_key, $api_module, 'helloBoard' ) !== FALSE )
{
//-----------------------------------------
// Add log
//-----------------------------------------
$this->addLogging( $api_key );
//-----------------------------------------
// Upgrade history?
//-----------------------------------------
@@ -318,11 +338,10 @@ class API_Server
* @param string $member_key Member key to check for
* @param integer $forum_id Forum id to post in
* @param string $topic_title Topic title
* @param string $topic_description Topic description
* @param string $post_content Posted content
* @return string xml
*/
public function postTopic( $api_key, $api_module, $member_field, $member_key, $forum_id, $topic_title, $topic_description, $post_content )
public function postTopic( $api_key, $api_module, $member_field, $member_key, $forum_id, $topic_title, $post_content )
{
//-----------------------------------------
// INIT
@@ -346,21 +365,14 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Member field...
//-----------------------------------------
$member = IPSMember::load( $member_key, 'all', $member_field );
//-----------------------------------------
// Got a member?
//-----------------------------------------
@@ -459,14 +471,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Member field...
@@ -573,14 +578,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Fetch forum list
@@ -632,14 +630,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
$member = IPSMember::load( $search_string, 'all', $search_type );
@@ -681,14 +672,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Get some classes
@@ -742,14 +726,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Get some classes
@@ -790,7 +767,7 @@ class API_Server
* @param bool $view_as_guest Treat user as a guest
* @return string xml
*/
public function fetchTopics( $api_key, $api_module, $forum_ids, $order_field, $order_by, $offset, $limit, $view_as_guest )
public function fetchTopics( $api_key, $api_module, $forum_ids, $order_field, $order_by, $offset, $limit, $view_as_guest, $parse_display )
{
//-----------------------------------------
// INIT
@@ -804,6 +781,7 @@ class API_Server
$offset = intval( $offset );
$limit = intval( $limit );
$view_as_guest = intval( $view_as_guest );
$parse_display = intval( $parse_display );
//-----------------------------------------
// Authenticate
@@ -815,14 +793,7 @@ class API_Server
// Add log
//-----------------------------------------
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
$this->addLogging( $api_key );
//-----------------------------------------
// Get API classes
@@ -841,7 +812,7 @@ class API_Server
$topic_view->topic_list_config['offset'] = $offset;
$topic_view->topic_list_config['limit'] = $limit;
$topics = $topic_view->return_topic_list_data( $view_as_guest );
$topics = $topic_view->return_topic_list_data( $view_as_guest, $parse_display );
//-----------------------------------------
// Return the data
@@ -851,6 +822,23 @@ class API_Server
exit();
}
}
/**
* Adds logging obviously :)
*
* @param string $api_key Authentication Key
*/
public function addLogging( $api_key )
{
if ( ipsRegistry::$settings['xmlrpc_log_type'] != 'failed' )
{
$this->registry->DB()->insert( 'api_log', array( 'api_log_key' => $api_key,
'api_log_ip' => $_SERVER['REMOTE_ADDR'],
'api_log_date' => time(),
'api_log_query' => $this->classApiServer->raw_request,
'api_log_allowed' => 1 ) );
}
}
/**
* Checks to see if the request is allowed
@@ -3,9 +3,9 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Remote API Server configuration
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
@@ -3,17 +3,17 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Defines the allowed methods a remote server may request and the in/out parameters
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2013-03-21 17:38:09 -0400 (Thu, 21 Mar 2013) $
* </pre>
*
* @author $Author: bfarber $
* @author $Author: AndyMillne $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 12109 $
*
*/
@@ -50,6 +50,7 @@ $ALLOWED_METHODS['fetchTopics'] = array(
'offset' => 'integer',
'limit' => 'integer',
'view_as_guest' => 'integer',
'parse_display' => 'integer',
),
'out' => array(
'response' => 'xmlrpc'
@@ -125,7 +126,6 @@ $ALLOWED_METHODS['postTopic'] = array(
'member_key' => 'string',
'forum_id' => 'integer',
'topic_title' => 'string',
'topic_description' => 'string',
'post_content' => 'string',
),
'out' => array(
+1 -1
View File
@@ -2,7 +2,7 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Facebook channel file
* Last Updated: $Date: 2012-01-31 11:24:24 +0000 (Tue, 31 Jan 2012) $
* </pre>
+3 -3
View File
@@ -2,10 +2,10 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Main public executable wrapper.
* Set-up and load module to run
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
+3 -3
View File
@@ -3,8 +3,8 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* Last Updated: $LastChangedDate: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* IP.Board v3.4.5
* Last Updated: $LastChangedDate: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @package IP.Board
* @link http://www.invisionpower.com
* @since 3.0.0
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
@@ -3,8 +3,8 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* Last Updated: $LastChangedDate: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* IP.Board v3.4.5
* Last Updated: $LastChangedDate: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -13,7 +13,7 @@
* @package IP.Board
* @link http://www.invisionpower.com
* @since 3.0.0
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
+70 -6
View File
@@ -4,9 +4,9 @@
*
* $Copyright: $
* $License: $
* $Author: mark $
* $LastChangedDate: 2012-02-22 12:07:55 -0500 (Wed, 22 Feb 2012) $
* $Revision: 10349 $
* $Author: bfarber $
* $LastChangedDate: 2013-04-12 18:05:43 -0400 (Fri, 12 Apr 2013) $
* $Revision: 12171 $
* @since 22nd February 2012
*/
@@ -20,10 +20,74 @@ require_once( IPS_ROOT_PATH . 'sources/base/ipsController.php' );/*noLibHook*/
$registry = ipsRegistry::instance();
$registry->init();
if ( ipsRegistry::$settings['ipb_reg_number'] and ipsRegistry::$request['key'] == md5( ipsRegistry::$settings['ipb_reg_number'] ) )
if ( $_GET['cdnCheck'] )
{
ipsRegistry::DB()->update( 'cache_store', array( 'cs_rebuild' => 1 ), "cs_key='licenseData'" );
ipsRegistry::cache()->putWithCacheLib( 'licenseData', 'rebuildCache', 200 );
echo 'OK';
exit;
}
else
{
if ( ipsRegistry::$settings['ipb_reg_number'] and ipsRegistry::$request['key'] == ipsRegistry::$settings['ipb_reg_number'] )
{
switch ( ipsRegistry::$request['do'] )
{
case 'reset':
ipsRegistry::DB()->update( 'cache_store', array( 'cs_rebuild' => 1 ), "cs_key='licenseData'" );
ipsRegistry::cache()->putWithCacheLib( 'licenseData', 'rebuildCache', 200 );
break;
case 'cdnoff':
$settings = array( 'ips_cdn' => FALSE, 'ipb_img_url' => '', 'ipb_css_url' => '', 'ipb_js_url' => '', 'upload_url' => '' );
if ( IPSLib::appIsInstalled('downloads') )
{
$settings['idm_screenshot_url'] = str_replace( ipsRegistry::$request['url'], ipsRegistry::$settings['board_url'], $settings['idm_screenshot_url'] );
}
if ( IPSLib::appIsInstalled('gallery') )
{
$settings['gallery_images_url'] = str_replace( ipsRegistry::$request['url'], ipsRegistry::$settings['board_url'], $settings['gallery_images_url'] );
}
IPSLib::updateSettings( $settings );
echo "OK";
break;
case 'cdnon':
$settings = array( 'ips_cdn' => TRUE, 'ipb_img_url' => ipsRegistry::$request['url'], 'ipb_css_url' => ipsRegistry::$request['url'], 'ipb_js_url' => ipsRegistry::$request['url'], 'upload_url' => ipsRegistry::$request['url'] . '/uploads' );
if ( IPSLib::appIsInstalled('downloads') )
{
if ( substr( ipsRegistry::$settings['idm_localsspath'], 0, 11 ) === '{root_path}' )
{
$settings['idm_screenshot_url'] = str_replace( '{root_path}', ipsRegistry::$request['url'], ipsRegistry::$settings['idm_localsspath'] );
}
}
if ( IPSLib::appIsInstalled('gallery') )
{
$this_script = str_replace( '\\', '/', getenv( 'SCRIPT_FILENAME' ) );
if( $this_script )
{
$this_script = str_replace( '/'.CP_DIRECTORY.'/index.php', '', $this_script );
if ( substr( ipsRegistry::$settings['gallery_images_path'], 0, strlen( $this_script ) ) === $this_script )
{
$settings['gallery_images_url'] = str_replace( '\\', '/', str_replace( $this_script, ipsRegistry::$request['url'], ipsRegistry::$settings['gallery_images_path'] ) );
}
}
}
IPSLib::updateSettings( $settings );
if ( ipsRegistry::$settings['ips_cdn'] )
{
echo "OK";
}
else
{
echo "FLUSH";
}
break;
}
}
}
exit;
@@ -0,0 +1,48 @@
<?php
class ipsConnect_custom
{
/**
* Constructor
*
* @param ipsRegistry
*/
public function __construct( $registry )
{
$this->registry = $registry;
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->lang = $this->registry->getClass('class_localization');
$this->member = $this->registry->member();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
}
/**
* Login
* Note: will be fired even if login fails
*
* @param array|null Member data
* @param string Status code
* SUCCESS login successful
* WRONG_AUTH Password incorrect
* NO_USER Identifier did not match member account
* MISSING_DATA Identifier or password was blank
* ACCOUNT_LOCKED Account has been locked by brute-force prevention
*/
public function login( $member, $statusCode )
{
}
/**
* Logout
*
* @param array Member data
*/
public function logout( $member )
{
}
}
+10
View File
@@ -0,0 +1,10 @@
<html>
<head><title>IP.Board - Bulletin Board System</title></head>
<body>
<h1>403: IP.Board -&gt; Forbidden</h1>
<hr>
You have reached this page in error, please use your back button to return to the forum.
<hr>
<a href="http://www.invisionpower.com">IP.Board</a>
</body>
</html>
+775
View File
@@ -0,0 +1,775 @@
<?php
/**
* @file ipsconnect.php IPS Connect
*
* $Copyright: $
* $License: $
* $Author: mark $
* $LastChangedDate: 2011-04-06 04:34:47 -0400 (Wed, 06 Apr 2011) $
* $Revision: 8267 $
* @since 18th July 2012
*/
/**
*
* @class ipsConnect
* @brief This is where you put the code for your application
*
*/
class ipsConnect
{
/**
* Constructor
*
* Use this to do any initiation required by your application
*/
public function __construct()
{
//-----------------------------------------
// Init IPB
//-----------------------------------------
define( 'IPS_ENFORCE_ACCESS', TRUE );
define( 'IPB_THIS_SCRIPT', 'public' );
require_once( '../../initdata.php' );
require_once( IPS_ROOT_PATH . 'sources/base/ipsRegistry.php' );
require_once( IPS_ROOT_PATH . 'sources/base/ipsController.php' );
$this->registry = ipsRegistry::instance();
$this->registry->init();
//-----------------------------------------
// Set up shortcuts
//-----------------------------------------
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->lang = $this->registry->getClass('class_localization');
$this->member = $this->registry->member();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
$this->masterKey = md5( md5( $this->settings['sql_user'] . $this->settings['sql_pass'] ) . $this->settings['board_start'] );
//-----------------------------------------
// Init han_login
//-----------------------------------------
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/handlers/han_login.php', 'han_login' );
$this->han_login = new $classToLoad( $this->registry );
$this->han_login->init();
}
/**
* Process Login
*
* @param string Identifier - may be 'id', 'email' or 'username'
* @param string Value for identifier (for example, the user's ID number)
* @param string The password, md5 encoded
* @param string md5( IPS Connect Key (see login method) . Identifier Value )
* @param string Redirect URL, Base64 encoded
* @param string md5( IPS Connect Key . $redirect )
* @return mixed If the redirect URL is provided, this function should redirect the user to that URL with additional paramaters:
* connect_status value from below
* connect_id the ID number in this app
* connect_username the username
* connect_displayname the display name
* connect_email the email address
* connect_unlock If the account is locked, the time that it was locked
* connect_unlock_period The number of minutes until the account is unlocked (will be 0 if account does not automatically unlock)
* If blank, will output to screen a JSON object with the same parameters
* Values:
* SUCCESS login successful
* WRONG_AUTH Password incorrect
* NO_USER Identifier did not match member account
* MISSING_DATA Identifier or password was blank
* ACCOUNT_LOCKED Account has been locked by brute-force prevention
*/
public function login( $identifier, $identifierValue, $md5Password, $key, $redirect, $redirectHash )
{
$member = NULL;
$statusCode = 'MISSING_DATA';
$secondsUntilUnlock = 0;
$revalidateUrl = '';
/* Check */
if ( in_array( $identifier, array( 'id', 'email', 'username' ) ) )
{
$member = IPSMember::load( $identifierValue, 'none', $identifier );
if ( $member['member_id'] )
{
/* Check we're not blocked */
if ( $this->settings['ipb_bruteforce_attempts'] > 0 )
{
$failed_attempts = explode( ",", IPSText::cleanPermString( $member['failed_logins'] ) );
$failed_count = 0;
$total_failed = 0;
$thisip_failed = 0;
$non_expired_att = array();
if( is_array($failed_attempts) AND count($failed_attempts) )
{
foreach( $failed_attempts as $entry )
{
if ( ! strpos( $entry, "-" ) )
{
continue;
}
list ( $timestamp, $ipaddress ) = explode( "-", $entry );
if ( ! $timestamp )
{
continue;
}
$total_failed++;
if ( $ipaddress != $this->member->ip_address )
{
continue;
}
$thisip_failed++;
if ( $this->settings['ipb_bruteforce_period'] AND
$timestamp < time() - ($this->settings['ipb_bruteforce_period']*60) )
{
continue;
}
$non_expired_att[] = $entry;
$failed_count++;
}
sort($non_expired_att);
$oldest_entry = array_shift( $non_expired_att );
list($oldest,) = explode( "-", $oldest_entry );
}
if( $thisip_failed >= $this->settings['ipb_bruteforce_attempts'] )
{
if( $this->settings['ipb_bruteforce_unlock'] )
{
if( $failed_count >= $this->settings['ipb_bruteforce_attempts'] )
{
$secondsUntilUnlock = $oldest;
$statusCode = 'ACCOUNT_LOCKED';
}
}
else
{
$statusCode = 'ACCOUNT_LOCKED';
}
}
}
/* Check the password is valid */
if ( $statusCode != 'ACCOUNT_LOCKED' )
{
if ( IPSMember::authenticateMember( $member['member_id'], $md5Password ) )
{
/* Are we validating? */
if ( $member['ipsconnect_revalidate_url'] )
{
$statusCode = 'VALIDATING';
$revalidateUrl = $member['ipsconnect_revalidate_url'];
}
else
{
$validating = ipsRegistry::DB()->buildAndFetch( array( 'select' => '*', 'from' => 'validating', 'where' => "member_id={$member['member_id']} AND new_reg=1" ) );
if ( $validating['vid'] )
{
$statusCode = 'VALIDATING';
if( $validating['user_verified'] == 1 OR $this->settings['reg_auth_type'] == 'admin' )
{
$revalidateUrl = 'ADMIN_VALIDATION';
}
else
{
$revalidateUrl = ipsRegistry::getClass('output')->buildUrl( 'app=core&amp;module=global&amp;section=register&amp;do=reval', 'public' );
}
}
}
if ( $statusCode != 'VALIDATING' )
{
/* Login Successful */
$statusCode = 'SUCCESS';
/* Log us in locally */
$this->han_login->loginWithoutCheckingCredentials( $member['member_id'], TRUE );
/* Run memberSync */
IPSLib::runMemberSync( 'onLogin', $member );
}
}
else
{
/* Login Failed */
$statusCode = 'WRONG_AUTH';
/* Append failed login */
if( $this->settings['ipb_bruteforce_attempts'] > 0 )
{
$failed_logins = explode( ",", $member['failed_logins'] );
$failed_logins[] = time() . '-' . $this->member->ip_address;
$failed_count = 0;
$total_failed = 0;
$non_expired_att = array();
foreach( $failed_logins as $entry )
{
list($timestamp,$ipaddress) = explode( "-", $entry );
if( !$timestamp )
{
continue;
}
$total_failed++;
if( $ipaddress != $this->member->ip_address )
{
continue;
}
if( $this->settings['ipb_bruteforce_period'] > 0
AND $timestamp < time() - ($this->settings['ipb_bruteforce_period']*60) )
{
continue;
}
$failed_count++;
$non_expired_att[] = $entry;
}
if( $member['member_id'] AND !$this->settings['failed_done'] )
{
IPSMember::save( $member['email'], array(
'core' => array(
'failed_logins' => implode( ",", $non_expired_att ),
'failed_login_count' => $total_failed
)
) );
}
}
}
}
}
else
{
$statusCode = 'NO_USER';
}
}
/* Run any custom code */
$this->_runCustom( 'login', array( $member, $statusCode ) );
/* Hide the email if necessary */
if ( $statusCode != 'SUCCESS' and $identifier != 'email' )
{
$member['email'] = '';
}
/* Return */
if ( $redirect )
{
$redirect = ( ( $key == md5( $this->masterKey . $identifierValue ) ) and ( $redirectHash == md5( $this->masterKey . $redirect ) ) ) ? $redirect : base64_encode( $this->settings['board_url'] );
}
$this->_return( $redirect, array( 'connect_status' => $statusCode, 'connect_id' => $member['member_id'], 'connect_username' => $member['name'], 'connect_displayname' => $member['members_display_name'], 'connect_email' => $member['email'], 'connect_unlock' => $secondsUntilUnlock, 'connect_revalidate_url'=> $revalidateUrl, 'connect_unlock_period' => $this->settings['ipb_bruteforce_period'] ) );
}
/**
* Process Logout
*
* @param int ID number
* @param string md5( IPS Connect Key (see login method) . ID number )
* @param string Redirect URL, Base64 encoded
* @param string md5( IPS Connect Key . $redirect )
* @return mixed If the redirect URL is provided, this function should redirect the user to that URL
* If blank, will output blank screen
*/
public function logout( $id, $key, $redirect, $redirectHash )
{
if ( $key != md5( $this->masterKey . $id ) )
{
$this->_return( base64_encode( $this->settings['board_url'] ) );
}
IPSCookie::set( "ipsconnect_" . md5( $this->settings['board_url'] . '/interface/ipsconnect/ipsconnect.php' ), '0', 1, 0, FALSE, FALSE );
$member = IPSMember::load( intval( $id ), 'none', 'id' );
if ( $member['member_id'] )
{
IPSCookie::set( "member_id" , "0" );
IPSCookie::set( "pass_hash" , "0" );
if( is_array( $_COOKIE ) )
{
foreach( $_COOKIE as $cookie => $value)
{
if ( stripos( $cookie, $this->settings['cookie_id'] . 'ipbforumpass' ) !== false AND ! strstr( $value, 'mobileApp' ) )
{
IPSCookie::set( str_replace( $this->settings['cookie_id'], "", $cookie ), '-', -1 );
}
}
}
$this->member->sessionClass()->convertMemberToGuest();
$privacy = intval( IPSMember::isLoggedInAnon($member) );
IPSMember::save( $member['member_id'], array( 'core' => array( 'login_anonymous' => "{$privacy}&0", 'last_activity' => IPS_UNIX_TIME_NOW ) ) );
IPSLib::runMemberSync( 'onLogOut', $member );
$this->han_login->logoutCallback( $member );
/* Run any custom code */
$this->_runCustom( 'logout', array( $member ) );
}
if ( $redirect )
{
$redirect = ( $redirectHash == md5( $this->masterKey . $redirect ) ) ? $redirect : base64_encode( $this->settings['board_url'] );
}
$this->_return( $redirect );
}
/**
* Register a new account
*
* @param string Key - this can be anything which is known only to the applications. Never reveal this key publically.
* For IPS Community Suite installs, this key can be obtained in the Login Management page in the ACP
* @param string Username
* @param string Display name
* @param string The password, md5 encoded
* @param string Email address
* @return void Outputs to screen JSON object with 2 parameters
'status' One of the following values:
BAD_KEY The key provided was invalid
SUCCESS Account created
EMAIL_IN_USE Email is already in use
USERNAME_IN_USE Username is already in use
BAD_KEY Key was invalid
MISSING_DATA Not all data was provided
FAIL Other error
'id' with master ID number (0 if fail) - if user already exists, will provide ID of existing user
*/
public function register( $key, $username, $displayname, $md5Password, $email, $revalidateUrl )
{
//-----------------------------------------
// Checks
//-----------------------------------------
/* Key is good */
if ( $key != $this->masterKey )
{
echo json_encode( array( 'status' => 'BAD_KEY', 'id' => 0 ) );
exit;
}
/* We have the data */
if ( !$email or !$md5Password )
{
echo json_encode( array( 'status' => 'MISSING_DATA', 'id' => 0 ) );
exit;
}
/* Email/Username is not in use */
$member = IPSMember::load( $email, 'none', 'email' );
if ( $member['member_id'] )
{
echo json_encode( array( 'status' => 'EMAIL_IN_USE', 'id' => $member['member_id'] ) );
exit;
}
if ( $username )
{
$member = IPSMember::load( $username, 'none', 'username' );
if ( $member['member_id'] )
{
echo json_encode( array( 'status' => 'USERNAME_IN_USE', 'id' => $member['member_id'] ) );
exit;
}
}
//-----------------------------------------
// Create
//-----------------------------------------
/* Set basic data */
$tables = array( 'members' => array( 'email' => $email, 'md5_hash_password' => $md5Password ) );
if ( $displayname and !$username )
{
$username = $displayname;
}
/* Are we validating? */
if ( $revalidateUrl )
{
$tables['members']['member_group_id'] = ipsRegistry::$settings['auth_group'];
$tables['members']['ipsconnect_revalidate_url'] = base64_decode( $revalidateUrl );
}
/* Create */
if ( $username )
{
$tables['members']['name'] = $username;
if ( $displayname )
{
$tables['members']['members_display_name'] = $displayname;
}
$member = IPSMember::create( $tables, TRUE, TRUE );
}
else
{
$member = IPSMember::create( $tables, FALSE, TRUE, FALSE );
}
//-----------------------------------------
// Return
//-----------------------------------------
if ( $member['member_id'] )
{
echo json_encode( array( 'status' => 'SUCCESS', 'id' => $member['member_id'] ) );
exit;
}
else
{
echo json_encode( array( 'status' => 'FAIL', 'id' => 0 ) );
exit;
}
}
/**
* Validate Cookie Data
*
* @param string JSON encoded cookie data
* @return void Outputs to screen a JSON object with the bollowing properties:
* connect_status SUCCESS or FAIL
* connect_id the ID number in this app
* connect_username the username
* connect_displayname the display name
* connect_email the email address
*/
public function cookies( $data )
{
$cookies = json_decode( stripslashes( urldecode( $data ) ), TRUE );
if ( isset( $cookies[ ipsRegistry::$settings['cookie_id'] . 'member_id' ] ) )
{
$member = IPSMember::load( $cookies[ ipsRegistry::$settings['cookie_id'] . 'member_id' ] );
if ( $member['member_id'] and $member['member_login_key'] == $cookies[ ipsRegistry::$settings['cookie_id'] . 'pass_hash' ] and ( !$member['member_login_key_expire'] or time() <= $member['member_login_key_expire'] ) )
{
$statusCode = 'SUCCESS';
$revalidateUrl = '';
if ( $member['ipsconnect_revalidate_url'] )
{
$statusCode = 'VALIDATING';
$revalidateUrl = $member['ipsconnect_revalidate_url'];
}
else
{
$validating = ipsRegistry::DB()->buildAndFetch( array( 'select' => '*', 'from' => 'validating', 'where' => "member_id={$member['member_id']} AND new_reg=1" ) );
if ( $validating['vid'] )
{
$statusCode = 'VALIDATING';
if( $validating['user_verified'] == 1 OR $this->settings['reg_auth_type'] == 'admin' )
{
$revalidateUrl = 'ADMIN_VALIDATION';
}
else
{
$revalidateUrl = ipsRegistry::getClass('output')->buildUrl( 'app=core&amp;module=global&amp;section=register&amp;do=reval', 'public' );
}
}
}
echo json_encode( array(
'connect_status' => $statusCode,
'connect_id' => $member['member_id'],
'connect_username' => $member['name'],
'connect_displayname' => $member['members_display_name'],
'connect_email' => $member['email'],
'connect_revalidate_url'=> $revalidateUrl,
) );
exit;
}
}
echo json_encode( array( 'connect_status' => 'FAIL' ) );
exit;
}
/**
* Check data
*
* @param string Key - this can be anything which is known only to the applications. Never reveal this key publically.
* For IPS Community Suite installs, this key can be obtained in the Login Management page in the ACP
* @param int If provided, do not throw an error if the "existing user" is the user with this ID
* @param string Username
* @param string Display Name
* @param string Email address
* @return void Outputs to screen a JSON object with four properties (status, username, displayname, email) - 'status' will say "SUCCESS" - the remainding 3 properties will each contain a boolean value, or NULL if no value was provided.
* The boolean value indicates if it is OK to register a new account with that data (this may be because there is no existing user with that, or the app allows duplicates of that data)
* If the key is incorrect - 'status' will be "BAD_KEY" and the remaining 3 parameters will all be NULL.
*/
public function check( $key, $id, $username, $displayname, $email )
{
$return = array( 'username' => NULL, 'displayname' => NULL, 'email' => NULL );
$member = array();
if ( $id )
{
$member = IPSMember::load( $id );
}
if ( $key != $this->masterKey )
{
echo json_encode( array_merge( array( 'status' => 'BAD_KEY' ), $return ) );
exit;
}
if ( $username )
{
$return['username'] = IPSMember::getFunction()->checkNameExists( $username, $member, 'name', TRUE ) ? FALSE : TRUE;
}
if ( $displayname )
{
$return['displayname'] = IPSMember::getFunction()->checkNameExists( $displayname, $member, 'members_display_name', TRUE ) ? FALSE : TRUE;
}
if ( $email )
{
$return['email'] = IPSMember::checkByEmail( $email ) ? FALSE : TRUE;
}
echo json_encode( array_merge( array( 'status' => 'SUCCESS' ), $return ) );
exit;
}
/**
* Change account data
*
* @param int ID number
* @param string md5( IPS Connect Key (see login method) . ID number )
* @param string New username (blank means do not change)
* @param string New displayname (blank means do not change)
* @param string New email address (blank means do not change)
* @param string New password, md5 encoded (blank means do not change)
* @param string Redirect URL, Base64 encoded
* @param string md5( IPS Connect Key . $redirect )
* @return mixed If the redirect URL is provided, this function should redirect the user to that URL with a single paramater - 'status'
* If blank, will output to screen a JSON object with the same parameter
* Values:
* BAD_KEY Invalid Key
* NO_USER ID number not match any member account
* SUCCESS Information changed successfully
* USERNAME_IN_USE The chosen username was in use and as a result NO information was changed
* DISPLAYNAME_IN_USE The chosen username was in use and as a result NO information was changed
* EMAIL_IN_USE The chosen username was in use and as a result NO information was changed
* MISSING_DATA No details to be changed were provided
*/
public function change( $id, $key, $username, $displayname, $email, $md5Password, $redirect, $redirectHash )
{
if ( $key != md5( $this->masterKey . $id ) )
{
$this->_return( base64_encode( $this->settings['board_url'] ), array( 'status' => 'BAD_KEY' ) );
}
$member = IPSMember::load( intval( $id ), 'none', 'id' );
if ( !$member['member_id'] )
{
$this->_return( $redirect, array( 'status' => 'NO_USER' ) );
}
$update = array();
if ( $username )
{
if ( IPSMember::getFunction()->checkNameExists( $username, $member, 'name', TRUE ) )
{
$this->_return( $redirect, array( 'status' => 'USERNAME_IN_USE' ) );
}
$update['name'] = $username;
}
if ( $displayname )
{
if ( IPSMember::getFunction()->checkNameExists( $displayname, $member, 'members_display_name', TRUE ) )
{
$this->_return( $redirect, array( 'status' => 'DISPLAYNAME_IN_USE' ) );
}
$update['members_display_name'] = $displayname;
}
if ( $email )
{
if ( IPSMember::checkByEmail( $email ) )
{
$this->_return( $redirect, array( 'status' => 'EMAIL_IN_USE' ) );
}
$update['email'] = $email;
}
if ( empty( $update ) )
{
if ( !$md5Password )
{
$this->_return( $redirect, array( 'status' => 'MISSING_DATA' ) );
}
}
else
{
IPSMember::save( $member['member_id'], array( 'members' => $update ) );
}
if ( $md5Password )
{
IPSMember::updatePassword( $member['member_id'], $md5Password );
}
if ( $redirect )
{
$redirect = ( $redirectHash == md5( $this->masterKey . $redirect ) ) ? $redirect : base64_encode( $this->settings['board_url'] );
}
$this->_return( $redirect, array( 'status' => 'SUCCESS' ) );
}
/**
* Account is validated
*
* @param int ID number
* @param string md5( IPS Connect Key (see login method) . ID number )
*/
public function validate( $id, $key )
{
if ( $key != md5( $this->masterKey . $id ) )
{
$this->_return( base64_encode( $this->settings['board_url'] ), array( 'status' => 'BAD_KEY' ) );
}
$member = IPSMember::load( intval( $id ), 'none', 'id' );
if ( !$member['member_id'] )
{
$this->_return( $redirect, array( 'status' => 'NO_USER' ) );
}
if ( $member['member_group_id'] == ipsRegistry::$settings['auth_group'] )
{
IPSMember::save( $member['member_id'], array( 'members' => array( 'member_group_id' => ipsRegistry::$settings['member_group'], 'ipsconnect_revalidate_url' => '' ) ) );
}
ipsRegistry::DB()->delete( 'validating', "member_id={$member['member_id']} and new_reg=1" );
$this->_return( $redirect, array( 'status' => 'SUCCESS' ) );
}
/**
* Delete account(s)
*
* @param array ID Numbers
* @param string md5( IPS Connect Key (see login method) . json_encode( ID number ) )
*/
public function delete( $ids, $key )
{
if ( $key != md5( $this->masterKey . json_encode( $ids ) ) )
{
$this->_return( base64_encode( $this->settings['board_url'] ), array( 'status' => 'BAD_KEY' ) );
}
IPSMember::remove( $ids );
$this->_return( $redirect, array( 'status' => 'SUCCESS' ) );
}
/**
* Handle redirect / output
*
* @param string Redirect URL, Base64 encoded
* @param array Params
* @return null Outputs to screen or redirects
*/
protected function _return( $redirect, $params=array() )
{
if ( $redirect )
{
$this->registry->output->silentRedirect( base64_decode( $redirect ) . ( $_REQUEST['noparams'] ? '' : ( '&' . http_build_query( $params ) ) ) );
exit;
}
else
{
if ( !empty( $params ) )
{
echo json_encode( $params );
}
exit;
}
}
/**
* Run custom actions
*
* @param string method
* @param array params
*/
protected function _runCustom( $method, $params )
{
if ( file_exists( './custom.php' ) )
{
require_once './custom.php';
if ( class_exists( 'ipsConnect_custom' ) )
{
$custom = new ipsConnect_custom( $this->registry );
if ( method_exists( $custom, $method ) )
{
call_user_func_array( array( $custom, $method ), $params );
}
}
}
}
}
/**
*
* Map - can modify to add additional parameters, but the IPS Community Suite will only send the defaults
*
*/
$map = array(
'login' => array( 'idType', 'id', 'password', 'key', 'redirect', 'redirectHash' ),
'logout' => array( 'id', 'key', 'redirect', 'redirectHash' ),
'register' => array( 'key', 'username', 'displayname', 'password', 'email', 'revalidateurl' ),
'cookies' => array( 'data' ),
'check' => array( 'key', 'id', 'username', 'displayname', 'email' ),
'change' => array( 'id', 'key', 'username', 'displayname', 'email', 'password', 'redirect', 'redirectHash' ),
'validate' => array( 'id', 'key' ),
'delete' => array( 'id', 'key' )
);
/**
*
* Process Logic - do not modify
*
*/
$ipsConnect = new ipsConnect();
if ( isset( $_REQUEST['act'] ) and isset( $map[ $_REQUEST['act'] ] ) )
{
$params = array();
foreach ( $map[ $_REQUEST['act'] ] as $k )
{
$params[ $k ] = $_REQUEST[ $k ];
}
call_user_func_array( array( $ipsConnect, $_REQUEST['act'] ), $params );
}
exit;
+3 -3
View File
@@ -2,9 +2,9 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Mobile API
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2012-05-10 16:10:13 -0400 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: bfarber $
@@ -12,7 +12,7 @@
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 10721 $
*
*/
+9 -3
View File
@@ -3,9 +3,9 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Task Handler
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2013-05-13 20:42:41 -0400 (Mon, 13 May 2013) $
* </pre>
*
* @author $Author: bfarber $
@@ -14,13 +14,19 @@
* @package IP.Board
* @subpackage Core
* @link http://www.invisionpower.com
* @version $Revision: 10914 $
* @version $Revision: 12249 $
*/
//ini_set( 'display_errors', 'off' );
if ( !isset($_SERVER['argv'] ) )
{
die;
}
define( 'IPS_ENFORCE_ACCESS', TRUE );
define( 'IPS_IS_SHELL', TRUE );
define( 'NO_SESSION_UPDATE', TRUE );
require_once( str_replace( '/interface/task.php', '/initdata.php', $_SERVER['argv'][0] ) );/*noLibHook*/
require_once( IPS_ROOT_PATH . 'sources/base/ipsRegistry.php' );/*noLibHook*/
+6 -6
View File
@@ -2,18 +2,18 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* IP.Board v3.4.5
* Main public executable wrapper.
* Set-up and load module to run
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* Last Updated: $Date: 2013-02-06 10:51:28 -0500 (Wed, 06 Feb 2013) $
* </pre>
*
* @author $Author: bfarber $
* @author $Author: mark $
* @copyright (c) 2001 - 2008 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 10914 $
* @version $Rev: 11945 $
*
*/
@@ -27,7 +27,7 @@ require_once( IPS_ROOT_PATH . 'sources/base/ipsController.php' );/*noLibHook*/
$registry = ipsRegistry::instance();
$registry->init();
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/twitter/connect.php', 'twitter_connect' );
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/twitter/connect.php', 'twitter_connect', 'core', true );
$twitter = new $classToLoad( $registry );
if ( $_REQUEST['oauth_token'] )
@@ -53,7 +53,7 @@ if ( $_REQUEST['oauth_token'] )
switch( $msg )
{
default:
$registry->getClass('output')->showError( 'twit_ohnoes', 1090094, null, null, 403 );
$registry->getClass('output')->showError( 'twit_ohnoes', 1090094, 1, $msg, 403 );
break;
case 'TWITTER_NOT_SET_UP':
$registry->getClass('output')->showError( 'twit_not_on', 1090095, null, null, 403 );
+76
View File
@@ -0,0 +1,76 @@
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.2.0 Beta 1
* Main public executable wrapper.
* Set-up and load module to run
* Last Updated: $Date: 2011-03-11 12:41:48 -0500 (Fri, 11 Mar 2011) $
* </pre>
*
* @author $Author: ips_terabyte $
* @copyright (c) 2001 - 2008 Invision Power Services, Inc.
* @license http://www.invisionpower.com/community/board/license.html
* @package IP.Board
* @link http://www.invisionpower.com
* @version $Rev: 8042 $
*
*/
define( 'IPS_ENFORCE_ACCESS', TRUE );
define( 'IPB_THIS_SCRIPT', 'public' );
require_once( '../../initdata.php' );/*noLibHook*/
require_once( IPS_ROOT_PATH . 'sources/base/ipsRegistry.php' );/*noLibHook*/
require_once( IPS_ROOT_PATH . 'sources/base/ipsController.php' );/*noLibHook*/
$registry = ipsRegistry::instance();
$registry->init();
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/vkontakte/connect.php', 'vkontakte_connect' );
$vkontakte = new $classToLoad( $registry );
if ( $_REQUEST['code'] )
{
/* From the log in page */
if ( $_REQUEST['key'] )
{
try
{
if ( ! intval( $_REQUEST['m'] ) )
{
$vkontakte->finishLogin();
}
else
{
$vkontakte->finishConnection();
}
}
catch( Exception $error )
{
$msg = $error->getMessage();
switch( $msg )
{
default:
$registry->getClass('output')->showError( 'vk_ohnoes', 1090194, 1, $msg, 403 );
break;
case 'VK_NOT_SET_UP':
$registry->getClass('output')->showError( 'vk_not_on', 1090195, null, null, 403 );
case 'NOT_REMOTE_MEMBER':
$registry->getClass('output')->showError( 'vk_not_remote', 1090196, null, null, 403 );
break;
}
}
}
else
{
$vkontakte->finishConnection();
}
}
else
{
$vkontakte->redirectToConnectPage();
}
exit();