Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

@@ -12,7 +12,7 @@
namespace IPS\core\modules\admin\applications;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -23,6 +23,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
*/
class _oauth extends \IPS\Node\Controller
{
/**
* @brief Has been CSRF-protected
*/
public static $csrfProtected = TRUE;
/**
* Node Class
*/
@@ -41,7 +46,6 @@ class _oauth extends \IPS\Node\Controller
public function execute()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'oauth_manage' );
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'system/api.css', 'core', 'admin' ) );
return parent::execute();
}
@@ -85,9 +89,16 @@ class _oauth extends \IPS\Node\Controller
\IPS\Output::i()->error( 'node_error', '2C362/1', 404, '' );
}
if ( $client->type === 'mobile' )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=mobile&controller=mobile" ) );
}
$secret = NULL;
if ( isset( \IPS\Request::i()->newSecret ) and \IPS\Member::loggedIn()->hasAcpRestriction( 'core', 'applications', 'oauth_secrets' ) )
{
\IPS\Session::i()->csrfCheck();
$secret = \IPS\Login::generateRandomString( 48 );
$client->client_secret = password_hash( $secret, PASSWORD_DEFAULT );
$client->brute_force = NULL;
@@ -118,14 +129,14 @@ class _oauth extends \IPS\Node\Controller
$return['ban'] = array(
'icon' => 'ban',
'title' => 'oauth_brute_force_ban',
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=bfRemove&ban=1&client_id={$client->client_id}" )->setQueryString( 'ip', $row['ip_address'] )
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=bfRemove&ban=1&client_id={$client->client_id}" )->setQueryString( 'ip', $row['ip_address'] )->csrf()
);
if ( $row['fails'] >= 3 )
{
$return['unlock'] = array(
'icon' => 'unlock',
'title' => 'oauth_brute_force_unlock',
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=bfRemove&client_id={$client->client_id}" )->setQueryString( 'ip', $row['ip_address'] )
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=bfRemove&client_id={$client->client_id}" )->setQueryString( 'ip', $row['ip_address'] )->csrf()
);
}
return $return;
@@ -145,6 +156,8 @@ class _oauth extends \IPS\Node\Controller
*/
protected function bfRemove()
{
\IPS\Session::i()->csrfCheck();
try
{
$client = \IPS\Api\OAuthClient::load( \IPS\Request::i()->client_id );
@@ -211,6 +224,53 @@ class _oauth extends \IPS\Node\Controller
\IPS\Output::i()->error( 'node_error', '2C362/3', 404, '' );
}
if ( $client )
{
$columns = array(
'access_token_expires' => (bool) $client->access_token_length,
'refresh_token_expires' => (bool) ( $client->use_refresh_tokens and $client->refresh_token_length ),
'scope' => (bool) ( $client->scopes and json_decode( $client->scopes ) ),
'auth_user_agent' => ( \in_array( 'authorization_code', explode( ',', $client->grant_types ) ) or \in_array( 'implicit', explode( ',', $client->grant_types ) ) ),
'issue_user_agent' => ( \in_array( 'authorization_code', explode( ',', $client->grant_types ) ) or \in_array( 'password', explode( ',', $client->grant_types ) ) or \in_array( 'client_credentials', explode( ',', $client->grant_types ) ) ),
);
}
else
{
$columns = array(
'access_token_expires' => FALSE,
'refresh_token_expires' => FALSE,
'scope' => FALSE,
'auth_user_agent' => FALSE,
'issue_user_agent' => FALSE,
);
$count = 0;
foreach ( new \IPS\Patterns\ActiveRecordIterator( \IPS\Db::i()->select( '*', 'core_oauth_clients', array( \IPS\Db::i()->findInSet( 'oauth_grant_types', array( 'authorization_code', 'implicit', 'password' ) ) ) ), 'IPS\Api\OAuthClient' ) as $_client )
{
$count++;
if ( $_client->access_token_length )
{
$columns['access_token_expires'] = TRUE;
}
if ( $_client->use_refresh_tokens and $_client->refresh_token_length )
{
$columns['refresh_token_expires'] = TRUE;
}
if ( $_client->scopes and json_decode( $_client->scopes ) )
{
$columns['scope'] = TRUE;
}
if ( \in_array( 'authorization_code', explode( ',', $_client->grant_types ) ) or \in_array( 'implicit', explode( ',', $_client->grant_types ) ) )
{
$columns['auth_user_agent'] = TRUE;
}
if ( \in_array( 'authorization_code', explode( ',', $_client->grant_types ) ) or \in_array( 'password', explode( ',', $_client->grant_types ) ) or \in_array( 'client_credentials', explode( ',', $_client->grant_types ) ) )
{
$columns['issue_user_agent'] = TRUE;
}
}
}
$table = new \IPS\Helpers\Table\Db( 'core_oauth_server_access_tokens', $baseUrl, array( $client ? array( 'client_id=?', $client->client_id ) : array( 'member_id=?', $member->member_id ) ) );
$table->langPrefix = 'oauth_authorization_';
$table->include = array();
@@ -220,27 +280,35 @@ class _oauth extends \IPS\Node\Controller
$table->include[] = 'member_id';
$table->advancedSearch['member_id'] = \IPS\Helpers\Table\SEARCH_MEMBER;
}
else
elseif ( $count > 1 )
{
$table->include[] = 'client_id';
}
$table->include[] = 'issued';
$table->include[] = 'status';
$table->advancedSearch['issued'] = \IPS\Helpers\Table\SEARCH_DATE_RANGE;
if ( !$client or $client->access_token_length )
if ( $columns['access_token_expires'] )
{
$table->include[] = 'access_token_expires';
$table->advancedSearch['access_token_expires'] = \IPS\Helpers\Table\SEARCH_DATE_RANGE;
}
if ( !$client or ( $client->use_refresh_tokens and $client->refresh_token_length ) )
if ( $columns['refresh_token_expires'] )
{
$table->include[] = 'refresh_token_expires';
$table->advancedSearch['refresh_token_expires'] = \IPS\Helpers\Table\SEARCH_DATE_RANGE;
}
if ( !$client or ( $client->scopes and json_decode( $client->scopes ) ) )
if ( $columns['scope'] )
{
$table->include[] = 'scope';
}
if ( $columns['auth_user_agent'] )
{
$table->include[] = 'auth_user_agent';
}
if ( $columns['issue_user_agent'] )
{
$table->include[] = 'issue_user_agent';
}
$table->noSort = array( 'status', 'scope' );
$table->sortBy = $table->sortBy ?: 'issued';
$table->parsers = array(
@@ -315,6 +383,31 @@ class _oauth extends \IPS\Node\Controller
{
return '';
}
},
'auth_user_agent' => function( $val, $row )
{
if ( $row['device_key'] )
{
try
{
$device = \IPS\Member\Device::load( $row['device_key'] );
return \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->basicUrl( \IPS\Http\Url::internal( "app=core&module=members&controller=devices&do=device&key={$row['device_key']}&member={$row['member_id']}" ), FALSE, (string) \IPS\Http\UserAgent::parse( $val ), FALSE );
}
catch ( \OutOfRangeException $e ) { }
}
return (string) \IPS\Http\UserAgent::parse( $val );
},
'issue_user_agent' => function( $val )
{
$agent = \IPS\Http\UserAgent::parse( $val );
if ( $agent->ipsApp )
{
return \IPS\Theme::i()->getTemplate( 'api', 'core', 'admin' )->clientDetails( $val, $agent );
}
else
{
return \IPS\Theme::i()->getTemplate( 'api', 'core', 'admin' )->clientDetails( $val );
}
}
);
$table->rowButtons = function( $row ) use ( $client ) {
@@ -322,12 +415,12 @@ class _oauth extends \IPS\Node\Controller
'revoke' => array(
'icon' => 'times-circle',
'title' => 'oauth_app_revoke',
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeToken&client_id={$row['client_id']}&member_id={$row['member_id']}&token={$row['access_token']}" )->setQueryString( 'r', $client ? 'c' : 'm' ),
'link' => \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeToken&client_id={$row['client_id']}&member_id={$row['member_id']}&token={$row['access_token']}" )->setQueryString( 'r', $client ? 'c' : 'm' )->csrf(),
'data' => array( 'delete' => '' )
)
);
};
$revokeAllLink = $client ? \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeAllTokens&client_id={$client->client_id}" ) : \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeAllTokens&member_id={$member->member_id}" );
$revokeAllLink = $client ? \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeAllTokens&client_id={$client->client_id}" )->csrf() : \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=revokeAllTokens&member_id={$member->member_id}" )->csrf();
$table->rootButtons = array(
'revoke' => array(
'icon' => 'times-circle',
@@ -341,15 +434,30 @@ class _oauth extends \IPS\Node\Controller
if ( $client )
{
\IPS\Output::i()->title = $client->_title;
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "app=core&module=applications&controller=api&tab=oauth" ), 'oauth_clients' );
if ( $client->type !== 'mobile' )
{
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "app=core&module=applications&controller=api&tab=oauth" ), 'oauth_clients' );
}
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=view&client_id={$client->client_id}" ), $client->_title );
\IPS\Output::i()->breadcrumb[] = array( NULL, 'oauth_view_authorizations' );
}
else
{
\IPS\Output::i()->title = $member->name;
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "app=core&module=members&controller=members&do=edit&id={$member->member_id}" ), $member->name );
\IPS\Output::i()->breadcrumb[] = array( NULL, 'oauth_member_authorizations' );
\IPS\Output::i()->breadcrumb[] = array( \IPS\Http\Url::internal( "app=core&module=members&controller=members&do=view&id={$member->member_id}" ), $member->name );
if ( $count > 1 )
{
\IPS\Output::i()->breadcrumb[] = array( NULL, 'oauth_member_authorizations' );
}
else
{
foreach ( new \IPS\Patterns\ActiveRecordIterator( \IPS\Db::i()->select( '*', 'core_oauth_clients', array( \IPS\Db::i()->findInSet( 'oauth_grant_types', array( 'authorization_code', 'implicit', 'password' ) ) ) ), 'IPS\Api\OAuthClient' ) as $_client )
{
\IPS\Output::i()->breadcrumb[] = array( NULL, $_client->_title );
break;
}
}
}
}
@@ -362,6 +470,7 @@ class _oauth extends \IPS\Node\Controller
protected function revokeToken()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'oauth_tokens' );
\IPS\Session::i()->csrfCheck();
\IPS\Db::i()->delete( 'core_oauth_server_access_tokens', array( 'client_id=? AND access_token=?', \IPS\Request::i()->client_id, \IPS\Request::i()->token ) );
\IPS\Session::i()->log( 'acplogs__oauth_revoke_token', array( 'core_oauth_client_' . \IPS\Request::i()->client_id => TRUE ) );
@@ -388,6 +497,7 @@ class _oauth extends \IPS\Node\Controller
protected function revokeAllTokens()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'oauth_tokens' );
\IPS\Session::i()->csrfCheck();
if ( \IPS\Request::i()->member_id )
{
@@ -398,7 +508,7 @@ class _oauth extends \IPS\Node\Controller
else
{
\IPS\Db::i()->delete( 'core_oauth_server_access_tokens', array( 'client_id=?', \IPS\Request::i()->client_id ) );
\IPS\Session::i()->log( 'acplogs__oauth_revoke_client', array( 'core_oauth_client_' . $client->client_id => TRUE ) );
\IPS\Session::i()->log( 'acplogs__oauth_revoke_client', array( 'core_oauth_client_' . \IPS\Request::i()->client_id => TRUE ) );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=applications&controller=oauth&do=tokens" )->setQueryString( 'client_id', \IPS\Request::i()->client_id ) );
}
}