Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

@@ -11,7 +11,7 @@
namespace IPS\core\modules\admin\system;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
*/
class _login extends \IPS\Dispatcher\Controller
{
/**
* @brief Has been CSRF-protected
*/
public static $csrfProtected = TRUE;
/**
* Log In
*
@@ -30,11 +35,26 @@ class _login extends \IPS\Dispatcher\Controller
protected function manage()
{
/* Do we have an unfinished upgrade? */
if ( !\IPS\IN_DEV and ( \IPS\RECOVERY_MODE !== TRUE OR !isset( \IPS\Request::i()->noWarning ) ) and \IPS\Settings::i()->setup_in_progress )
{
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeStarted.php' );
session_abort();
exit;
}
/* Do we have an upgrade available to install? */
if ( !\IPS\IN_DEV and !isset( \IPS\Request::i()->noWarning ) )
{
if( \IPS\Application::load('core')->long_version < \IPS\Application::getAvailableVersion('core') and \IPS\Application::load('core')->version != \IPS\Application::getAvailableVersion( 'core', TRUE ) )
{
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailable.html' );
if ( \IPS\CIC )
{
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailableCic.php' );
}
else
{
include( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/upgrade/upgradeAvailable.php' );
}
session_abort();
exit;
}
@@ -87,18 +107,18 @@ class _login extends \IPS\Dispatcher\Controller
else
{
$error = 'no_access_cp';
$this->log( 'fail' );
$this->_log( 'fail' );
}
}
}
catch ( \IPS\Login\Exception $e )
{
$error = $e->getMessage();
$this->log( 'fail' );
$this->_log( 'fail' );
}
/* Have we been sent here because of an IP address mismatch? */
if ( is_null( $error ) AND isset( \IPS\Request::i()->error ) )
if ( \is_null( $error ) AND isset( \IPS\Request::i()->error ) )
{
switch( \IPS\Request::i()->error )
{
@@ -169,6 +189,9 @@ class _login extends \IPS\Dispatcher\Controller
*/
protected function _doLogin( $member, $bypass2FA = FALSE )
{
/* Check if we need to send any ACP notifications */
\IPS\core\extensions\core\AdminNotifications\ConfigurationError::runChecksAndSendNotifications();
/* Set the referer in the URL */
$url = \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'admin', 'login' );
if ( isset( \IPS\Request::i()->ref ) )
@@ -192,37 +215,35 @@ class _login extends \IPS\Dispatcher\Controller
\IPS\Session::i()->setMember( $member );
/* Log */
$this->log( 'ok' );
$this->_log( 'ok' );
/* Clean out any existing session ID in the URL */
$queryString = array();
if( isset( \IPS\Request::i()->ref ) )
{
$_queryString = array();
parse_str( preg_replace( "/adsess=([a-zA-Z0-9]+)(?:&|$)/", '', base64_decode( \IPS\Request::i()->ref ) ), $_queryString );
foreach ( $_queryString as $k => $v )
{
if ( in_array( $k, array( 'app', 'module', 'controller', 'id' ) ) )
{
$queryString[ $k ] = $v;
}
}
parse_str( base64_decode( \IPS\Request::i()->ref ), $queryString );
}
/* Set the cookie */
\IPS\Request::i()->setCookie( 'acp_login_key', \IPS\Session::i()->cookieKey );
/* Do we need to show the installation onboard screen? */
if( isset( \IPS\Settings::i()->onboard_complete ) AND ( \IPS\Settings::i()->onboard_complete == 0 OR ( \IPS\Settings::i()->onboard_complete != 1 AND \IPS\Settings::i()->onboard_complete < time() ) ) )
{
/* We flag that onboarding is complete now so that if the admin clicks away from the page they're not immediately taken back. This is supposed to be helpful, not a hindrance. */
\IPS\Settings::i()->changeValues( array( 'onboard_complete' => 1 ) );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=onboard&do=initial", 'admin' )->csrf() );
}
/* Boink - if we're in recovery mode, go there */
if ( \IPS\RECOVERY_MODE === TRUE )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=support&controller=recovery" ), '', 303 );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=support&controller=recovery" )->csrf(), '', 303 );
}
else
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( http_build_query( $queryString, '', '&' ) ), '', 303 );
}
}
/**
* Log Out
*
@@ -230,16 +251,19 @@ class _login extends \IPS\Dispatcher\Controller
*/
protected function logout()
{
\IPS\Session::i()->csrfCheck();
session_destroy();
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login&_fromLogout=1" )->csrf() );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login&_fromLogout=1" ) );
}
/**
* Log
*
* @param string $status Status ['fail','ok']
* @return void
*/
protected function log( $status )
protected function _log( $status )
{
/* Generate request details */
foreach( \IPS\Request::i() as $k => $v )
@@ -253,7 +277,7 @@ class _login extends \IPS\Dispatcher\Controller
$save = array(
'admin_ip_address' => \IPS\Request::i()->ipAddress(),
'admin_username' => \IPS\Request::i()->auth ?: '',
'admin_username' => \IPS\Request::i()->auth ? \substr( \IPS\Request::i()->auth, 0, 255 ) : '',
'admin_time' => time(),
'admin_success' => ( $status == 'ok' ) ? 1 : 0,
'admin_request' => json_encode( $request ),