Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

+33 -12
View File
@@ -11,7 +11,7 @@
namespace IPS\core\modules\admin\staff;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
*/
class _admin extends \IPS\Dispatcher\Controller
{
/**
* @brief Has been CSRF-protected
*/
public static $csrfProtected = TRUE;
/**
* Execute
*
@@ -231,7 +236,7 @@ class _admin extends \IPS\Dispatcher\Controller
elseif ( $values['acprestrictions_member'] )
{
\IPS\Dispatcher::i()->checkAcpPermission( 'restrictions_add_member' );
if ( $values['acprestrictions_member'] === \IPS\Member::loggedIn() )
if ( $values['acprestrictions_member']->member_id === \IPS\Member::loggedIn()->member_id )
{
$form->error = \IPS\Member::loggedIn()->language()->addToStack('acprestrictions_noself');
}
@@ -245,7 +250,7 @@ class _admin extends \IPS\Dispatcher\Controller
{
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", $rowId, $values['acprestrictions_type'] ) );
if ( !count( $current ) )
if ( !\count( $current ) )
{
$current = array(
'row_id' => $rowId,
@@ -274,6 +279,7 @@ class _admin extends \IPS\Dispatcher\Controller
/**
* Edit
*
* @csrfChecked Uses form helper 7 Oct 2019
* @return void
*/
protected function edit()
@@ -281,7 +287,7 @@ class _admin extends \IPS\Dispatcher\Controller
try
{
/* Get record */
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", \intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
}
catch ( \UnderflowException $e )
{
@@ -346,17 +352,19 @@ class _admin extends \IPS\Dispatcher\Controller
*/
protected function save()
{
\IPS\Session::i()->csrfCheck();
/* Get record */
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", \intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
if ( !$current )
{
\IPS\Output::i()->error( 'node_error', '2C113/2', 404, '' );
}
$permissions = ( \IPS\Request::i()->admin_use_restrictions == 'no' ) ? '*' : json_encode( ( is_array( \IPS\Request::i()->r ) ) ? \IPS\Request::i()->r : array() );
$permissions = ( \IPS\Request::i()->admin_use_restrictions == 'no' ) ? '*' : json_encode( ( \is_array( \IPS\Request::i()->r ) ) ? \IPS\Request::i()->r : array() );
/* Save */
\IPS\Db::i()->update( 'core_admin_permission_rows', array( 'row_perm_cache' => $permissions, 'row_updated' => time() ), array( "row_id=? AND row_id_type=?", intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) );
\IPS\Db::i()->update( 'core_admin_permission_rows', array( 'row_perm_cache' => $permissions, 'row_updated' => time() ), array( "row_id=? AND row_id_type=?", \intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) );
unset( \IPS\Data\Store::i()->administrators );
@@ -374,7 +382,7 @@ class _admin extends \IPS\Dispatcher\Controller
*/
protected function delete()
{
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
$current = \IPS\Db::i()->select( '*', 'core_admin_permission_rows', array( "row_id=? AND row_id_type=?", \intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) )->first();
if ( $current['row_id_type'] === 'member' )
{
@@ -414,7 +422,7 @@ class _admin extends \IPS\Dispatcher\Controller
}
\IPS\Session::i()->log( 'acplog__acpr_deleted', array( $name => FALSE ) );
\IPS\Db::i()->delete( 'core_admin_permission_rows', array( 'row_id=? AND row_id_type=?', intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) );
\IPS\Db::i()->delete( 'core_admin_permission_rows', array( 'row_id=? AND row_id_type=?', \intval( \IPS\Request::i()->id ), \IPS\Request::i()->type ) );
unset ( \IPS\Data\Store::i()->administrators );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=staff&controller=admin' ) );
@@ -489,13 +497,26 @@ class _admin extends \IPS\Dispatcher\Controller
$table->sortDirection = $table->sortDirection ?: 'desc';
/* Search */
$table->quickSearch = array( array( 'note', 'word_custom', 'word_default' ), 'note' );
$table->advancedSearch = array(
'member_id' => \IPS\Helpers\Table\SEARCH_MEMBER,
'ip_address' => \IPS\Helpers\Table\SEARCH_CONTAINS_TEXT,
'ctime' => \IPS\Helpers\Table\SEARCH_DATE_RANGE,
);
/* Custom quick search function to search unicode entities in JSON encoded data */
$table->quickSearch = function( $val )
{
$searchTerm = mb_strtolower( trim( \IPS\Request::i()->quicksearch ) );
$jsonSearchTerm = str_replace( '\\', '\\\\\\', trim( json_encode( trim( \IPS\Request::i()->quicksearch ) ), '"' ) );
return array(
"(`note` LIKE CONCAT( '%', ?, '%' ) OR LOWER(`word_custom`) LIKE CONCAT( '%', ?, '%' ) OR LOWER(`word_default`) LIKE CONCAT( '%', ?, '%' ))",
$jsonSearchTerm,
$searchTerm,
$searchTerm
);
};
$table->joins = array(
array( 'from' => array( 'core_sys_lang_words', 'w' ), 'where' => "w.word_key=lang_key AND w.lang_id=" . \IPS\Member::loggedIn()->language()->id )
);
@@ -529,7 +550,7 @@ class _admin extends \IPS\Dispatcher\Controller
\IPS\Dispatcher::i()->checkAcpPermission( 'restrictions_adminlogs_prune' );
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Number( 'prune_log_admin', \IPS\Settings::i()->prune_log_admin, FALSE, array( 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, \IPS\Member::loggedIn()->language()->addToStack('after'), \IPS\Member::loggedIn()->language()->addToStack('days'), 'prune_log_admin' ) );
$form->add( new \IPS\Helpers\Form\Interval( 'prune_log_admin', \IPS\Settings::i()->prune_log_admin, FALSE, array( 'valueAs' => \IPS\Helpers\Form\Interval::DAYS, 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, \IPS\Member::loggedIn()->language()->addToStack('after'), NULL, 'prune_log_admin' ) );
if ( $values = $form->values() )
{
@@ -612,7 +633,7 @@ class _admin extends \IPS\Dispatcher\Controller
\IPS\Dispatcher::i()->checkAcpPermission( 'restrictions_acploginlogs_prune' );
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Number( 'prune_log_adminlogin', \IPS\Settings::i()->prune_log_adminlogin, FALSE, array( 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, \IPS\Member::loggedIn()->language()->addToStack('after'), \IPS\Member::loggedIn()->language()->addToStack('days'), 'prune_log_adminlogin' ) );
$form->add( new \IPS\Helpers\Form\Interval( 'prune_log_adminlogin', \IPS\Settings::i()->prune_log_adminlogin, FALSE, array( 'valueAs' => \IPS\Helpers\Form\Interval::DAYS, 'unlimited' => 0, 'unlimitedLang' => 'never' ), NULL, \IPS\Member::loggedIn()->language()->addToStack('after'), NULL, 'prune_log_adminlogin' ) );
if ( $values = $form->values() )
{