Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _login extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Is this for displaying "content"? Affects if advertisements may be shown
|
||||
*/
|
||||
public $isContentPage = FALSE;
|
||||
|
||||
/**
|
||||
* Log In
|
||||
*
|
||||
@@ -39,7 +44,16 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
$login = new \IPS\Login( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' ) );
|
||||
|
||||
/* What's our referrer? */
|
||||
$postBeforeRegister = NULL;
|
||||
$ref = \IPS\Request::i()->ref;
|
||||
if ( !$ref and isset( \IPS\Request::i()->cookie['post_before_register'] ) )
|
||||
{
|
||||
try
|
||||
{
|
||||
$postBeforeRegister = \IPS\Db::i()->select( '*', 'core_post_before_registering', array( 'secret=?', \IPS\Request::i()->cookie['post_before_register'] ) )->first();
|
||||
}
|
||||
catch( \UnderflowException $e ){}
|
||||
}
|
||||
|
||||
/* Process */
|
||||
$error = NULL;
|
||||
@@ -47,24 +61,30 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
if ( $success = $login->authenticate() )
|
||||
{
|
||||
if ( $ref and $ref = @base64_decode( $ref ) )
|
||||
if ( \IPS\Request::i()->referrer( FALSE, TRUE ) )
|
||||
{
|
||||
$ref = \IPS\Request::i()->referrer( FALSE, TRUE );
|
||||
}
|
||||
elseif ( $postBeforeRegister )
|
||||
{
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' or $ref->openRedirect() )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
$class = $postBeforeRegister['class'];
|
||||
$ref = $class::load( $postBeforeRegister['id'] )->url();
|
||||
}
|
||||
catch ( \Exception $e )
|
||||
catch ( \OutOfRangeException $e )
|
||||
{
|
||||
$ref = \IPS\Http\Url::internal('');
|
||||
}
|
||||
}
|
||||
elseif( !empty( $_SERVER['HTTP_REFERER'] ) )
|
||||
{
|
||||
$_ref = \IPS\Http\Url::createFromString( $_SERVER['HTTP_REFERER'] );
|
||||
$ref = ( $_ref instanceof \IPS\Http\Url\Internal and ( !isset( $_ref->queryString['do'] ) or $_ref->queryString['do'] != 'validating' ) ) ? $_ref : \IPS\Http\Url::internal('');
|
||||
}
|
||||
else
|
||||
{
|
||||
$ref = \IPS\Http\Url::internal('');
|
||||
$ref = \IPS\Http\Url::internal( '' );
|
||||
}
|
||||
|
||||
if ( $success->mfa() )
|
||||
@@ -98,6 +118,9 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('login');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->login( $login, $ref, $error );
|
||||
|
||||
/* Don't cache for a short while to ensure sessions work */
|
||||
\IPS\Request::i()->setCookie( 'noCache', 1 );
|
||||
|
||||
/* Set Session Location */
|
||||
\IPS\Session::i()->setLocation( \IPS\Http\Url::internal( 'app=core&module=system&controller=login', NULL, 'login' ), array(), 'loc_logging_in' );
|
||||
}
|
||||
@@ -129,11 +152,11 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
catch ( \Exception $e ) { }
|
||||
|
||||
/* Have we already done 2FA? */
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member );
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member, FALSE );
|
||||
$output = \IPS\MFA\MFAHandler::accessToArea( 'core', $device->known ? 'AuthenticateFrontKnown' : 'AuthenticateFront', \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'front', 'login' ), $member );
|
||||
if ( !$output )
|
||||
{
|
||||
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'] ) )->process();
|
||||
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'], FALSE ) )->process();
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_fromLogin', 1 ), '', 303 );
|
||||
}
|
||||
|
||||
@@ -188,25 +211,13 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
/* If successful (or if there's no way to reauthenticate which would only happen if a login handler has been deleted)) complete the link... */
|
||||
try
|
||||
{
|
||||
if ( $success = $login->authenticate() or ( !count( $login->usernamePasswordMethods() ) and !count( $login->buttonMethods() ) ) )
|
||||
if ( $success = $login->authenticate() or ( !\count( $login->usernamePasswordMethods() ) and !\count( $login->buttonMethods() ) ) )
|
||||
{
|
||||
$handler->completeLink( $member, $details['details'] );
|
||||
|
||||
unset( $_SESSION['linkAccounts'] );
|
||||
|
||||
$destination = \IPS\Http\Url::internal( '' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
{
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( base64_decode( \IPS\Request::i()->ref ) );
|
||||
if ( $ref instanceof \IPS\Http\Url\Internal and !$ref->openRedirect() )
|
||||
{
|
||||
$destination = $ref;
|
||||
}
|
||||
}
|
||||
catch ( \Exception $e ) { }
|
||||
}
|
||||
$destination = \IPS\Request::i()->referrer( FALSE, TRUE ) ?: \IPS\Http\Url::internal( '' );
|
||||
|
||||
$success = new \IPS\Login\Success( $member, $handler );
|
||||
if ( $success->mfa() )
|
||||
@@ -265,29 +276,8 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
\IPS\Output::i()->redirect( $redirectUrl );
|
||||
}
|
||||
|
||||
/* Do not allow the login_key to be re-used */
|
||||
if ( isset( \IPS\Request::i()->cookie['device_key'] ) )
|
||||
{
|
||||
try
|
||||
{
|
||||
$device = \IPS\Member\Device::loadAndAuthenticate( \IPS\Request::i()->cookie['device_key'], $member );
|
||||
$device->login_key = NULL;
|
||||
$device->save();
|
||||
}
|
||||
catch ( \OutOfRangeException $e ) { }
|
||||
}
|
||||
|
||||
/* Clear cookies */
|
||||
\IPS\Request::i()->clearLoginCookies();
|
||||
|
||||
/* Destroy the session (we have to explicitly reset the session cookie, see http://php.net/manual/en/function.session-destroy.php) */
|
||||
$_SESSION = array();
|
||||
$params = session_get_cookie_params();
|
||||
setcookie( session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"] );
|
||||
session_destroy();
|
||||
|
||||
/* Member sync callback */
|
||||
$member->memberSync( 'onLogout', array( $redirectUrl ) );
|
||||
/* Do it */
|
||||
\IPS\Login::logout( $redirectUrl );
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( $redirectUrl->setQueryString( '_fromLogout', 1 ) );
|
||||
@@ -312,7 +302,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
/* Not logged in as admin? */
|
||||
if ( $admin->member_id != \IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' )->setQueryString( array( 'ref' => base64_encode( \IPS\Request::i()->url() ), '_err' => 'login_as_user_login' ) ) );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' )->addRef( (string) \IPS\Request::i()->url() )->setQueryString( '_err', 'login_as_user_login' ) );
|
||||
}
|
||||
|
||||
/* Do it */
|
||||
|
||||
Reference in new issue
Block a user