Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\core\modules\front\system;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -22,6 +22,11 @@ if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
*/
|
||||
class _lostpass extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/**
|
||||
* @brief Is this for displaying "content"? Affects if advertisements may be shown
|
||||
*/
|
||||
public $isContentPage = FALSE;
|
||||
|
||||
/**
|
||||
* Execute
|
||||
*
|
||||
@@ -51,7 +56,7 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
/* Build the form */
|
||||
$form = new \IPS\Helpers\Form( "lostpass", 'request_password' );
|
||||
$form->add( new \IPS\Helpers\Form\Email( 'email_address', NULL, TRUE, array( 'bypassProfanity' => TRUE ), function( $val ){
|
||||
$form->add( new \IPS\Helpers\Form\Email( 'email_address', NULL, TRUE, array( 'bypassProfanity' => \IPS\Helpers\Form\Text::BYPASS_PROFANITY_ALL ), function( $val ){
|
||||
if( !\IPS\Login::emailIsInUse( $val ) )
|
||||
{
|
||||
throw new \LogicException( 'lost_pass_no_email' );
|
||||
@@ -173,6 +178,9 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function validate()
|
||||
{
|
||||
/* Prevent the vid key from being exposed in referrers */
|
||||
\IPS\Output::i()->sendHeader( "Referrer-Policy: origin" );
|
||||
|
||||
try
|
||||
{
|
||||
$record = \IPS\Db::i()->select( '*', 'core_validating', array( 'vid=? AND member_id=? AND lost_pass=1', \IPS\Request::i()->vid, \IPS\Request::i()->mid ) )->first();
|
||||
@@ -184,8 +192,8 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
|
||||
/* Show form for new password */
|
||||
$form = new \IPS\Helpers\Form( "resetpass", 'save' );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'showMeter' => \IPS\Settings::i()->password_strength_meter ) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password_confirm', NULL, TRUE, array( 'confirm' => 'password' ) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'protect' => TRUE, 'showMeter' => \IPS\Settings::i()->password_strength_meter, 'checkStrength' => TRUE, 'strengthMember' => \IPS\Member::load( \IPS\Request::i()->mid ) ) ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password_confirm', NULL, TRUE, array( 'protect' => TRUE, 'confirm' => 'password' ) ) );
|
||||
|
||||
/* Set new password */
|
||||
if ( $values = $form->values() )
|
||||
@@ -203,16 +211,19 @@ class _lostpass extends \IPS\Dispatcher\Controller
|
||||
$member->save();
|
||||
}
|
||||
|
||||
/* Log in, and invalidate all other sessions */
|
||||
\IPS\Session::i()->setMember( $member );
|
||||
$member->invalidateSessionsAndLogins( \IPS\Session::i()->id );
|
||||
\IPS\Member\Device::loadOrCreate( $member )->updateAfterAuthentication( isset( \IPS\Request::i()->cookie['login_key'] ) );
|
||||
|
||||
/* Delete validating record and log in */
|
||||
\IPS\Db::i()->delete( 'core_validating', array( 'member_id=? AND lost_pass=1', $member->member_id ) );
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' ) );
|
||||
$success = new \IPS\Login\Success( $member, \IPS\Login\Handler::findMethod( 'IPS\Login\Handler\Standard' ) );
|
||||
if ( $success->mfa() )
|
||||
{
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $success->member->member_id, 'anonymous' => $success->anonymous, 'remember' => $success->rememberMe, 'destination' => (string) \IPS\Http\Url::internal( '' ), 'handler' => $success->handler->id );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' )->setQueryString( '_mfaLogin', 1 ) );
|
||||
}
|
||||
$success->process();
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( '' )->setQueryString( '_fromLogin', 1 ) );
|
||||
}
|
||||
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
|
||||
Reference in new issue
Block a user