Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _ajax extends \IPS\core\modules\front\system\ajax
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Save ACP Tabs
|
||||
*
|
||||
@@ -29,7 +34,9 @@ class _ajax extends \IPS\core\modules\front\system\ajax
|
||||
*/
|
||||
protected function saveTabs()
|
||||
{
|
||||
if ( is_array( \IPS\Request::i()->tabOrder ) )
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
if ( \is_array( \IPS\Request::i()->tabOrder ) )
|
||||
{
|
||||
$tabs = array();
|
||||
|
||||
@@ -55,6 +62,8 @@ class _ajax extends \IPS\core\modules\front\system\ajax
|
||||
*/
|
||||
protected function searchKeywords()
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
if ( \IPS\IN_DEV )
|
||||
{
|
||||
$url = base64_decode( \IPS\Request::i()->url );
|
||||
@@ -76,7 +85,7 @@ class _ajax extends \IPS\core\modules\front\system\ajax
|
||||
);
|
||||
}
|
||||
|
||||
if( count( $inserts ) )
|
||||
if( \count( $inserts ) )
|
||||
{
|
||||
\IPS\Db::i()->insert( 'core_acp_search_index', $inserts );
|
||||
}
|
||||
@@ -95,7 +104,7 @@ class _ajax extends \IPS\core\modules\front\system\ajax
|
||||
$keywords[ $url ]['keywords'] = array_unique( $entry['keywords'] );
|
||||
}
|
||||
|
||||
\file_put_contents( \IPS\ROOT_PATH . "/applications/{$qs['app']}/data/acpsearch.json", json_encode( $keywords, version_compare( PHP_VERSION, '5.4.0' ) >= 0 ? JSON_PRETTY_PRINT : 0 ) );
|
||||
\file_put_contents( \IPS\ROOT_PATH . "/applications/{$qs['app']}/data/acpsearch.json", json_encode( $keywords, JSON_PRETTY_PRINT ) );
|
||||
}
|
||||
|
||||
\IPS\Output::i()->json( 'ok' );
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _background extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
@@ -55,9 +60,11 @@ class _background extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function process()
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
$self = $this;
|
||||
$multiRedirect = new \IPS\Helpers\MultipleRedirect(
|
||||
\IPS\Http\Url::internal('app=core&module=system&controller=background&do=process'),
|
||||
\IPS\Http\Url::internal('app=core&module=system&controller=background&do=process')->csrf(),
|
||||
function( $data ) use ( $self )
|
||||
{
|
||||
/* Make sure the task is locked */
|
||||
@@ -66,11 +73,11 @@ class _background extends \IPS\Dispatcher\Controller
|
||||
$task->next_run = time() + 900;
|
||||
$task->save();
|
||||
|
||||
if ( ! is_array( $data ) )
|
||||
if ( ! \is_array( $data ) )
|
||||
{
|
||||
$count = $self->getCount();
|
||||
|
||||
return array( array( 'count' => $count, 'done' => 0 ), 'Starting...' );
|
||||
return array( array( 'count' => $count, 'done' => 0 ), \IPS\Member::loggedIn()->language()->addToStack('background_process_starting') );
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -78,9 +85,6 @@ class _background extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/* Run the next queue task, if any */
|
||||
$queueData = \IPS\Task::runQueue();
|
||||
|
||||
/* Update count */
|
||||
$data['count'] = $self->getCount();
|
||||
}
|
||||
catch ( \UnderflowException $e )
|
||||
{
|
||||
@@ -109,7 +113,7 @@ class _background extends \IPS\Dispatcher\Controller
|
||||
if ( isset( $json['count'] ) )
|
||||
{
|
||||
/* If the offset is larger than the count, then we should just show the count instead (to avoid situations where it will display 150 / 139, for example) */
|
||||
$offset = intval( $queueData['offset'] );
|
||||
$offset = \intval( $queueData['offset'] );
|
||||
if ( $offset > $json['count'] )
|
||||
{
|
||||
$offset = $json['count'];
|
||||
@@ -150,9 +154,13 @@ class _background extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
$data = json_decode( $row['data'], TRUE );
|
||||
|
||||
if ( isset( $data['count'] ) )
|
||||
if( isset( $data['realCount'] ) )
|
||||
{
|
||||
$count += intval( $data['count'] );
|
||||
$count += \intval( $data['realCount'] );
|
||||
}
|
||||
elseif ( isset( $data['count'] ) )
|
||||
{
|
||||
$count += \intval( $data['count'] );
|
||||
}
|
||||
else
|
||||
{
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,5 +22,12 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _editor extends \IPS\core\modules\front\system\editor
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
// This class only exists to extend the front-end controller
|
||||
// so that within the ACP we can call this endpoint and the
|
||||
// CSRF checks will work
|
||||
}
|
||||
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _language extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
@@ -43,6 +48,6 @@ class _language extends \IPS\Dispatcher\Controller
|
||||
|
||||
\IPS\Member::loggedIn()->acp_language = (int) \IPS\Request::i()->id;
|
||||
\IPS\Member::loggedIn()->save();
|
||||
\IPS\Output::i()->redirect( isset( $_SERVER['HTTP_REFERER'] ) ? \IPS\Http\Url::external( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal( '' ) );
|
||||
\IPS\Output::i()->redirect( \IPS\Request::i()->referrer() ?: \IPS\Http\Url::internal( '' ) );
|
||||
}
|
||||
}
|
||||
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _livesearch extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _login extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
/**
|
||||
* Log In
|
||||
*
|
||||
@@ -30,11 +35,26 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
protected function manage()
|
||||
{
|
||||
/* Do we have an unfinished upgrade? */
|
||||
if ( !\IPS\IN_DEV and ( \IPS\RECOVERY_MODE !== TRUE OR !isset( \IPS\Request::i()->noWarning ) ) and \IPS\Settings::i()->setup_in_progress )
|
||||
{
|
||||
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeStarted.php' );
|
||||
session_abort();
|
||||
exit;
|
||||
}
|
||||
|
||||
/* Do we have an upgrade available to install? */
|
||||
if ( !\IPS\IN_DEV and !isset( \IPS\Request::i()->noWarning ) )
|
||||
{
|
||||
if( \IPS\Application::load('core')->long_version < \IPS\Application::getAvailableVersion('core') and \IPS\Application::load('core')->version != \IPS\Application::getAvailableVersion( 'core', TRUE ) )
|
||||
{
|
||||
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailable.html' );
|
||||
if ( \IPS\CIC )
|
||||
{
|
||||
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailableCic.php' );
|
||||
}
|
||||
else
|
||||
{
|
||||
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailable.php' );
|
||||
}
|
||||
session_abort();
|
||||
exit;
|
||||
}
|
||||
@@ -87,18 +107,18 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
else
|
||||
{
|
||||
$error = 'no_access_cp';
|
||||
$this->log( 'fail' );
|
||||
$this->_log( 'fail' );
|
||||
}
|
||||
}
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
{
|
||||
$error = $e->getMessage();
|
||||
$this->log( 'fail' );
|
||||
$this->_log( 'fail' );
|
||||
}
|
||||
|
||||
/* Have we been sent here because of an IP address mismatch? */
|
||||
if ( is_null( $error ) AND isset( \IPS\Request::i()->error ) )
|
||||
if ( \is_null( $error ) AND isset( \IPS\Request::i()->error ) )
|
||||
{
|
||||
switch( \IPS\Request::i()->error )
|
||||
{
|
||||
@@ -169,6 +189,9 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function _doLogin( $member, $bypass2FA = FALSE )
|
||||
{
|
||||
/* Check if we need to send any ACP notifications */
|
||||
\IPS\core\extensions\core\AdminNotifications\ConfigurationError::runChecksAndSendNotifications();
|
||||
|
||||
/* Set the referer in the URL */
|
||||
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'admin', 'login' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
@@ -192,37 +215,35 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
\IPS\Session::i()->setMember( $member );
|
||||
|
||||
/* Log */
|
||||
$this->log( 'ok' );
|
||||
$this->_log( 'ok' );
|
||||
|
||||
/* Clean out any existing session ID in the URL */
|
||||
$queryString = array();
|
||||
if( isset( \IPS\Request::i()->ref ) )
|
||||
{
|
||||
$_queryString = array();
|
||||
parse_str( preg_replace( "/adsess=([a-zA-Z0-9]+)(?:&|$)/", '', base64_decode( \IPS\Request::i()->ref ) ), $_queryString );
|
||||
foreach ( $_queryString as $k => $v )
|
||||
{
|
||||
if ( in_array( $k, array( 'app', 'module', 'controller', 'id' ) ) )
|
||||
{
|
||||
$queryString[ $k ] = $v;
|
||||
}
|
||||
}
|
||||
parse_str( base64_decode( \IPS\Request::i()->ref ), $queryString );
|
||||
}
|
||||
|
||||
/* Set the cookie */
|
||||
\IPS\Request::i()->setCookie( 'acp_login_key', \IPS\Session::i()->cookieKey );
|
||||
|
||||
|
||||
/* Do we need to show the installation onboard screen? */
|
||||
if( isset( \IPS\Settings::i()->onboard_complete ) AND ( \IPS\Settings::i()->onboard_complete == 0 OR ( \IPS\Settings::i()->onboard_complete != 1 AND \IPS\Settings::i()->onboard_complete < time() ) ) )
|
||||
{
|
||||
/* We flag that onboarding is complete now so that if the admin clicks away from the page they're not immediately taken back. This is supposed to be helpful, not a hindrance. */
|
||||
\IPS\Settings::i()->changeValues( array( 'onboard_complete' => 1 ) );
|
||||
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=onboard&do=initial", 'admin' )->csrf() );
|
||||
}
|
||||
|
||||
/* Boink - if we're in recovery mode, go there */
|
||||
if ( \IPS\RECOVERY_MODE === TRUE )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=support&controller=recovery" ), '', 303 );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=support&controller=recovery" )->csrf(), '', 303 );
|
||||
}
|
||||
else
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( http_build_query( $queryString, '', '&' ) ), '', 303 );
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Log Out
|
||||
*
|
||||
@@ -230,16 +251,19 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function logout()
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
session_destroy();
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login&_fromLogout=1" )->csrf() );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login&_fromLogout=1" ) );
|
||||
}
|
||||
|
||||
/**
|
||||
* Log
|
||||
*
|
||||
* @param string $status Status ['fail','ok']
|
||||
* @return void
|
||||
*/
|
||||
protected function log( $status )
|
||||
protected function _log( $status )
|
||||
{
|
||||
/* Generate request details */
|
||||
foreach( \IPS\Request::i() as $k => $v )
|
||||
@@ -253,7 +277,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
|
||||
$save = array(
|
||||
'admin_ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
'admin_username' => \IPS\Request::i()->auth ?: '',
|
||||
'admin_username' => \IPS\Request::i()->auth ? \substr( \IPS\Request::i()->auth, 0, 255 ) : '',
|
||||
'admin_time' => time(),
|
||||
'admin_success' => ( $status == 'ok' ) ? 1 : 0,
|
||||
'admin_request' => json_encode( $request ),
|
||||
|
||||
@@ -1,49 +0,0 @@
|
||||
<?php
|
||||
/**
|
||||
* @brief Theme Changer
|
||||
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) Invision Power Services, Inc.
|
||||
* @license https://www.invisioncommunity.com/legal/standards/
|
||||
* @package Invision Community
|
||||
* @since 7 Oct 2014
|
||||
*/
|
||||
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* Theme Changer
|
||||
*/
|
||||
class _theme extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function execute()
|
||||
{
|
||||
parent::execute();
|
||||
}
|
||||
|
||||
/**
|
||||
* Manage
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function manage()
|
||||
{
|
||||
\IPS\Session::i()->csrfCheck();
|
||||
|
||||
\IPS\Member::loggedIn()->acp_skin = (int) \IPS\Request::i()->id;
|
||||
\IPS\Member::loggedIn()->save();
|
||||
|
||||
\IPS\Output::i()->redirect( isset( $_SERVER['HTTP_REFERER'] ) ? \IPS\Http\Url::external( $_SERVER['HTTP_REFERER'] ) : \IPS\Http\Url::internal( '' ) );
|
||||
}
|
||||
}
|
||||
File diff suppressed because it is too large.
Load diff
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\admin\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _vle extends \IPS\core\modules\front\system\vle
|
||||
{
|
||||
/**
|
||||
* @brief Has been CSRF-protected
|
||||
*/
|
||||
public static $csrfProtected = TRUE;
|
||||
|
||||
// This class only exists to extend the front-end controller
|
||||
// so that within the ACP we can call this endpoint and the
|
||||
// CSRF checks will work
|
||||
|
||||
Reference in new issue
Block a user