Version 3.3.4

This commit is contained in:
Neo committed 2025-12-19 00:35:52 -08:00
1 parent 78706903a2
commit fb6b5baabc
2206 files changed
+409828 -382984

No files matched your search

@@ -1,420 +1,423 @@
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.2.3
* Admin session handler
* Last Updated: $Date: 2011-05-05 07:03:47 -0400 (Thu, 05 May 2011) $
* </pre>
*
* @author $Author: ips_terabyte $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license This is NULLED!
* @package IP.Board
* @link http://hatynka.in
* @since Who knows...
* @version $Revision: 8644 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class adminSessions extends ips_MemberRegistry
{
/**
* Variable for session validated
*
* @access protected
* @var array
*/
protected $session_data = array();
/**
* Timeout variable
*
* @access protected
* @var int
*/
protected $_time_out_mins = 120;
/**
* Admin session
*
* @access protected
* @var string
*/
protected $_adsess = '';
/**
* Whether they are validated or not
*
* @access protected
* @var bool
*/
protected $_validated = false;
/**
* Message to display
*
* @access protected
* @var string
*/
protected $_message = '';
/**
* Authorize
*
* @access public
* @return @e void
*/
public function __construct()
{
/* Make object */
$this->registry = ipsRegistry::instance();
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
//--------------------------------------------
// Got a cookie wookey?
//--------------------------------------------
$_adsess = ipsRegistry::$request['adsess'];
$_time_out_mins = ( defined( 'IPB_ACP_SESSION_TIME_OUT' ) ) ? IPB_ACP_SESSION_TIME_OUT : 60;
//-----------------------------------------
// If the cookie doesn't match URL... use URL?
//-----------------------------------------
if ( $_adsess )
{
$this->session_type = 'url';
ipsRegistry::$request['adsess'] = $_adsess;
}
//--------------------------------------------
// Continue...
//--------------------------------------------
if ( ! ipsRegistry::$request['adsess'] )
{
//--------------------------------------------
// No URL adsess found, lets log in.
//--------------------------------------------
return $this->_response( 0, '' );
}
else
{
//--------------------------------------------
// We have a URL adsess, lets verify...
//--------------------------------------------
$this->DB->build( array( 'select' => '*',
'from' => 'core_sys_cp_sessions',
'where' => "session_id='" . IPSText::md5clean( ipsRegistry::$request['adsess'] ) . "'" ) );
$this->DB->execute();
$session_data = $this->DB->fetch();
$_tab_data = unserialize( $session_data['session_app_data'] );
$_tab_data = ( is_array( $_tab_data ) ) ? $_tab_data : array();
if ( $session_data['session_id'] == "" )
{
//--------------------------------------------
// Fail-safe, no DB record found, lets log in..
//--------------------------------------------
return $this->_response( 0, '' );
}
else if ($session_data['session_member_id'] == "")
{
//--------------------------------------------
// No member ID is stored, log in!
//--------------------------------------------
return $this->_response( 0, 'session_nomemberid' );
}
else
{
//--------------------------------------------
// Key is good, check the member details
//--------------------------------------------
$this->DB->build( array(
'select' => 'm.*',
'from' => array( 'members' => 'm' ),
'where' => "member_id=".intval($session_data['session_member_id']),
'add_join' => array( 0 => array( 'select' => 'g.*',
'from' => array( 'groups' => 'g' ),
'where' => 'm.member_group_id=g.g_id',
'type' => 'left'
),
1 => array( 'select' => 's.*',
'from' => array( 'core_sys_login' => 's' ),
'where' => 's.sys_login_id = m.member_id',
'type' => 'left'
)
)
) );
$this->DB->execute();
self::$data_store = $this->DB->fetch();
self::$data_store = self::instance()->setUpSecondaryGroups( self::$data_store );
//--------------------------------------------
// Get perms
//--------------------------------------------
if ( self::$data_store['member_id'] == "" )
{
//--------------------------------------------
// Ut-oh, no such member, log in!
//--------------------------------------------
return $this->_response( 0, 'session_invalidmid' );
}
else
{
//--------------------------------------------
// Member found, check passy
//--------------------------------------------
//if ( $session_data['session_member_login_key'] != self::$data_store['member_login_key'] )
//{
// //--------------------------------------------
// // Passys don't match..
// //--------------------------------------------
//
// return $this->_response( 0, 'Session member password mismatch' );
//}
//else
//{
//--------------------------------------------
// Do we have admin access?
//--------------------------------------------
if (self::$data_store['g_access_cp'] != 1)
{
return $this->_response( 0, 'session_noaccess' );
}
else
{
$this->_validated = TRUE;
}
//}
}
}
}
//--------------------------------------------
// If we're here, we're valid...
//--------------------------------------------
if ( $this->_validated === TRUE )
{
if ( $session_data['session_running_time'] < ( time() - $_time_out_mins * 60 ) )
{
self::$data_store = array();
self::setMember( 0 );
$this->_validated = FALSE;
return $this->_response( 0, 'session_timeout' );
}
//------------------------------
// Are we checking IP's?
//------------------------------
else if ( IPB_ACP_IP_MATCH )
{
$first_ip = preg_replace( "/^([0-9]{1,3})\.([0-9]{1,3})\.([0-9]{1,3})\.([0-9]{1,3})/", "\\1.\\2.\\3", $session_data['session_ip_address'] );
$second_ip = preg_replace( "/^([0-9]{1,3})\.([0-9]{1,3})\.([0-9]{1,3})\.([0-9]{1,3})/", "\\1.\\2.\\3", self::instance()->ip_address );
if ( $first_ip != $second_ip )
{
self::$data_store = array();
self::setMember( 0 );
$this->_validated = FALSE;
return $this->_response( 0, 'session_mismatchip' );
}
}
self::setMember( self::$data_store['member_id'] );
//-----------------------------------------
// Fix up secondary groups
//-----------------------------------------
if ( self::$data_store['mgroup_others'] )
{
$groups_id = explode( ',', self::$data_store['mgroup_others'] );
$masks = array();
$cache = ipsRegistry::cache()->getCache('group_cache');
if ( count( $groups_id ) )
{
foreach( $groups_id as $pid )
{
if ( empty($cache[ $pid ]['g_id']) )
{
continue;
}
//-----------------------------------------
// Got masks?
//-----------------------------------------
if ( $cache[ $pid ]['g_perm_id'] )
{
self::$data_store['g_perm_id'] .= ',' . $cache[ $pid ]['g_perm_id'];
}
}
}
}
//-----------------------------------------
// Current Location, used for online list
//-----------------------------------------
$module = ipsRegistry::$request['module'] != 'ajax' ? ipsRegistry::$request['module'] : $session_data['session_location'];
$location = $session_data['session_url'];
if ( ( IPS_APP_COMPONENT ) && ipsRegistry::$request['module'] != 'ajax' )
{
$location = str_ireplace( "login=yes" , "" , ipsRegistry::$settings['query_string_safe'] );
$location = ltrim( $location , '?' );
$location = preg_replace( "!adsess=(\w){32}!" , "" , $location );
$location = preg_replace( "!&mshow=(.+?)*!i" , "" , $location );
$location = preg_replace( "!&st=(.+?)*!i" , "" , $location );
$location = preg_replace( "!&messageinabottleacp=(.+?)*!i" , "" , $location );
}
/* Compare user-agent stuff */
$session_data['_session_app_data'] = unserialize( $session_data['session_app_data'] );
if ( is_array( $session_data['_session_app_data'] ) AND $session_data['_session_app_data']['uagent_key'] )
{
if ( $session_data['_session_app_data']['uagent_raw'] != self::instance()->user_agent )
{
$session_data['_session_app_data'] = self::_processUserAgent();
$session_data['_session_app_data']['uagent_raw'] = self::instance()->user_agent;
}
}
else
{
$session_data['_session_app_data'] = self::_processUserAgent();
$session_data['_session_app_data']['uagent_raw'] = self::instance()->user_agent;
}
//-----------------------------------------
// Done...
//-----------------------------------------
$this->DB->update( 'core_sys_cp_sessions',
array( 'session_running_time' => time(),
'session_location' => $module,
'session_url' => $location,
'session_app_data' => serialize( $session_data['_session_app_data'] ),
'session_member_name' => self::$data_store['members_display_name'],
),
'session_member_id='.intval(self::$data_store['member_id'])." and session_id='".ipsRegistry::$request['adsess']."'" );
return $this->_response( 1, '', $session_data['_session_app_data'] );
}
}
/**
* Get the validation status
*
* @access public
* @return bool
*/
public function getStatus()
{
return $this->_validated;
}
/**
* Get the validation message
*
* @access public
* @return string
*/
public function getMessage()
{
return !empty($this->registry->class_localization->words[ $this->_message ]) ? $this->registry->class_localization->words[ $this->_message ] : $this->_message;
}
/**
* Grab the user agent from the DB if required
*
* @access protected
* @return array Array of user agent info from the DB
*/
protected function _processUserAgent()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$uAgent = array( 'uagent_key' => '__NONE__',
'uagent_version' => 0,
'uagent_name' => '',
'uagent_type' => '',
'uagent_bypass' => 0 );
//-----------------------------------------
// Get useragent stuff
//-----------------------------------------
if ( ! $this->registry->isClassLoaded( 'userAgentFunctions' ) )
{
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php', 'userAgentFunctions' );
$this->registry->setClass( 'userAgentFunctions', new $classToLoad( $this->registry ) );
}
$uAgent = $this->registry->getClass( 'userAgentFunctions' )->findUserAgentID( self::instance()->user_agent );
if ( $uAgent['uagent_key'] === NULL )
{
$uAgent = array( 'uagent_key' => '__NONE__',
'uagent_version' => 0,
'uagent_name' => '',
'uagent_type' => '',
'uagent_bypass' => 0 );
}
return $uAgent;
}
/**
* Set the response
*
* @access protected
* @param bool Authenticated or not
* @param string Message
* @param array Array of user agent data
* @return @e void
*/
protected function _response( $validated, $message, $userAgentData=array() )
{
$this->_validated = $validated;
$this->_message = $message;
$this->session_data = $userAgentData;
return;
}
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* Admin session handler
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* </pre>
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @since Who knows...
* @version $Revision: 10914 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class adminSessions extends ips_MemberRegistry
{
/**
* Variable for session validated
*
* @access protected
* @var array
*/
protected $session_data = array();
/**
* Timeout variable
*
* @access protected
* @var int
*/
protected $_time_out_mins = 120;
/**
* Admin session
*
* @access protected
* @var string
*/
protected $_adsess = '';
/**
* Whether they are validated or not
*
* @access protected
* @var bool
*/
protected $_validated = false;
/**
* Message to display
*
* @access protected
* @var string
*/
protected $_message = '';
/**
* Authorize
*
* @access public
* @return @e void
*/
public function __construct()
{
/* Make object */
$this->registry = ipsRegistry::instance();
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
//--------------------------------------------
// Got a cookie wookey?
//--------------------------------------------
$_adsess = ipsRegistry::$request['adsess'];
$_time_out_mins = ( defined( 'IPB_ACP_SESSION_TIME_OUT' ) ) ? IPB_ACP_SESSION_TIME_OUT : 60;
//-----------------------------------------
// If the cookie doesn't match URL... use URL?
//-----------------------------------------
if ( $_adsess )
{
$this->session_type = 'url';
ipsRegistry::$request['adsess'] = $_adsess;
}
//--------------------------------------------
// Continue...
//--------------------------------------------
if ( ! ipsRegistry::$request['adsess'] )
{
//--------------------------------------------
// No URL adsess found, lets log in.
//--------------------------------------------
return $this->_response( 0, '' );
}
else
{
//--------------------------------------------
// We have a URL adsess, lets verify...
//--------------------------------------------
$this->DB->build( array( 'select' => '*',
'from' => 'core_sys_cp_sessions',
'where' => "session_id='" . IPSText::md5clean( ipsRegistry::$request['adsess'] ) . "'" ) );
$this->DB->execute();
$session_data = $this->DB->fetch();
$_tab_data = unserialize( $session_data['session_app_data'] );
$_tab_data = ( is_array( $_tab_data ) ) ? $_tab_data : array();
if ( $session_data['session_id'] == "" )
{
//--------------------------------------------
// Fail-safe, no DB record found, lets log in..
//--------------------------------------------
return $this->_response( 0, '' );
}
else if ($session_data['session_member_id'] == "")
{
//--------------------------------------------
// No member ID is stored, log in!
//--------------------------------------------
return $this->_response( 0, 'session_nomemberid' );
}
else
{
//--------------------------------------------
// Key is good, check the member details
//--------------------------------------------
$this->DB->build( array(
'select' => 'm.*',
'from' => array( 'members' => 'm' ),
'where' => "member_id=".intval($session_data['session_member_id']),
'add_join' => array( 0 => array( 'select' => 'g.*',
'from' => array( 'groups' => 'g' ),
'where' => 'm.member_group_id=g.g_id',
'type' => 'left'
),
1 => array( 'select' => 's.*',
'from' => array( 'core_sys_login' => 's' ),
'where' => 's.sys_login_id = m.member_id',
'type' => 'left'
)
)
) );
$this->DB->execute();
self::$data_store = $this->DB->fetch();
self::$data_store = self::instance()->setUpSecondaryGroups( self::$data_store );
//--------------------------------------------
// Get perms
//--------------------------------------------
if ( self::$data_store['member_id'] == "" )
{
//--------------------------------------------
// Ut-oh, no such member, log in!
//--------------------------------------------
return $this->_response( 0, 'session_invalidmid' );
}
else
{
//--------------------------------------------
// Member found, check passy
//--------------------------------------------
//if ( $session_data['session_member_login_key'] != self::$data_store['member_login_key'] )
//{
// //--------------------------------------------
// // Passys don't match..
// //--------------------------------------------
//
// return $this->_response( 0, 'Session member password mismatch' );
//}
//else
//{
//--------------------------------------------
// Do we have admin access?
//--------------------------------------------
if (self::$data_store['g_access_cp'] != 1)
{
return $this->_response( 0, 'session_noaccess' );
}
else
{
$this->_validated = TRUE;
}
//}
}
}
}
//--------------------------------------------
// If we're here, we're valid...
//--------------------------------------------
if ( $this->_validated === TRUE )
{
if ( $session_data['session_running_time'] < ( time() - $_time_out_mins * 60 ) )
{
self::$data_store = array();
self::setMember( 0 );
$this->_validated = FALSE;
return $this->_response( 0, 'session_timeout' );
}
//------------------------------
// Are we checking IP's?
//------------------------------
else if ( IPB_ACP_IP_MATCH )
{
if (
$session_data['session_ip_address'] != self::instance()->ip_address
or
( !IPSLib::validateIPv4( $session_data['session_ip_address'] ) and !IPSLib::validateIPv6( $session_data['session_ip_address'] ) )
or
( !IPSLib::validateIPv4( self::instance()->ip_address ) and !IPSLib::validateIPv6( self::instance()->ip_address ) )
)
{
self::$data_store = array();
self::setMember( 0 );
$this->_validated = FALSE;
return $this->_response( 0, 'session_mismatchip' );
}
}
self::setMember( self::$data_store['member_id'] );
//-----------------------------------------
// Fix up secondary groups
//-----------------------------------------
if ( self::$data_store['mgroup_others'] )
{
$groups_id = explode( ',', self::$data_store['mgroup_others'] );
$masks = array();
$cache = ipsRegistry::cache()->getCache('group_cache');
if ( count( $groups_id ) )
{
foreach( $groups_id as $pid )
{
if ( empty($cache[ $pid ]['g_id']) )
{
continue;
}
//-----------------------------------------
// Got masks?
//-----------------------------------------
if ( $cache[ $pid ]['g_perm_id'] )
{
self::$data_store['g_perm_id'] .= ',' . $cache[ $pid ]['g_perm_id'];
}
}
}
}
//-----------------------------------------
// Current Location, used for online list
//-----------------------------------------
$module = ipsRegistry::$request['module'] != 'ajax' ? ipsRegistry::$request['module'] : $session_data['session_location'];
$location = $session_data['session_url'];
if ( ( IPS_APP_COMPONENT ) && ipsRegistry::$request['module'] != 'ajax' )
{
$location = str_ireplace( "login=yes" , "" , ipsRegistry::$settings['query_string_safe'] );
$location = ltrim( $location , '?' );
$location = preg_replace( "!adsess=(\w){32}!" , "" , $location );
$location = preg_replace( "!&mshow=(.+?)*!i" , "" , $location );
$location = preg_replace( "!&st=(.+?)*!i" , "" , $location );
$location = preg_replace( "!&messageinabottleacp=(.+?)*!i" , "" , $location );
}
/* Compare user-agent stuff */
$session_data['_session_app_data'] = unserialize( $session_data['session_app_data'] );
if ( is_array( $session_data['_session_app_data'] ) AND $session_data['_session_app_data']['uagent_key'] )
{
if ( $session_data['_session_app_data']['uagent_raw'] != self::instance()->user_agent )
{
$session_data['_session_app_data'] = self::_processUserAgent();
$session_data['_session_app_data']['uagent_raw'] = self::instance()->user_agent;
}
}
else
{
$session_data['_session_app_data'] = self::_processUserAgent();
$session_data['_session_app_data']['uagent_raw'] = self::instance()->user_agent;
}
//-----------------------------------------
// Done...
//-----------------------------------------
$this->DB->update( 'core_sys_cp_sessions',
array( 'session_running_time' => time(),
'session_location' => $module,
'session_url' => $location,
'session_app_data' => serialize( $session_data['_session_app_data'] ),
'session_member_name' => self::$data_store['members_display_name'],
),
'session_member_id='.intval(self::$data_store['member_id'])." and session_id='".ipsRegistry::$request['adsess']."'" );
return $this->_response( 1, '', $session_data['_session_app_data'] );
}
}
/**
* Get the validation status
*
* @access public
* @return bool
*/
public function getStatus()
{
return $this->_validated;
}
/**
* Get the validation message
*
* @access public
* @return string
*/
public function getMessage()
{
return !empty($this->registry->class_localization->words[ $this->_message ]) ? $this->registry->class_localization->words[ $this->_message ] : $this->_message;
}
/**
* Grab the user agent from the DB if required
*
* @access protected
* @return array Array of user agent info from the DB
*/
protected function _processUserAgent()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$uAgent = array( 'uagent_key' => '__NONE__',
'uagent_version' => 0,
'uagent_name' => '',
'uagent_type' => '',
'uagent_bypass' => 0 );
//-----------------------------------------
// Get useragent stuff
//-----------------------------------------
if ( ! $this->registry->isClassLoaded( 'userAgentFunctions' ) )
{
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/useragents/userAgentFunctions.php', 'userAgentFunctions' );
$this->registry->setClass( 'userAgentFunctions', new $classToLoad( $this->registry ) );
}
$uAgent = $this->registry->getClass( 'userAgentFunctions' )->findUserAgentID( self::instance()->user_agent );
if ( $uAgent['uagent_key'] === NULL )
{
$uAgent = array( 'uagent_key' => '__NONE__',
'uagent_version' => 0,
'uagent_name' => '',
'uagent_type' => '',
'uagent_bypass' => 0 );
}
return $uAgent;
}
/**
* Set the response
*
* @access protected
* @param bool Authenticated or not
* @param string Message
* @param array Array of user agent data
* @return @e void
*/
protected function _response( $validated, $message, $userAgentData=array() )
{
$this->_validated = $validated;
$this->_message = $message;
$this->session_data = $userAgentData;
return;
}
}
+416 -262
View File
@@ -1,263 +1,417 @@
<?php
/**
* @file api.php Provides global methods to retrieve active users from the sessions table
*~TERABYTE_DOC_READY~
* $Copyright: (c) 2001 - 2011 Invision Power Services, Inc.$
* $License: This is NULLED!
* $Author: ips_terabyte $
* @since Friday 12th November 2010 16:58
* $LastChangedDate: 2011-08-26 11:38:16 -0400 (Fri, 26 Aug 2011) $
* @version v3.2.3
* $Revision: 9420 $
*/
/**
*
* @class session_api
* @brief Provides global methods to retrieve active users from the sessions table
*
*/
class session_api
{
/**
* Registry Object Shortcuts
*
* @var $registry
* @var $DB
* @var $settings
* @var $request
* @var $lang
* @var $member
* @var $memberData
* @var $cache
* @var $caches
*/
protected $registry;
protected $DB;
protected $settings;
protected $request;
protected $lang;
protected $member;
protected $memberData;
protected $cache;
protected $caches;
/**
* Constructor
*
* @param object $registry Registry object
* @return @e void
*/
public function __construct( ipsRegistry $registry )
{
/* Make object */
$this->registry = $registry;
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->lang = $this->registry->getClass('class_localization');
$this->member = $this->registry->member();
$this->memberData =& $this->registry->member()->fetchMemberData();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
}
/**
* Returns a list (with buildProfilePhoto set) of users in an application
*
* @param string $app Application folder/key
* @param array $options Array of options to add/override checks for the query
* @return @e array Array of found sessions (members, guests, bots, anons)
*
* <b>Filters:</b>
* - cutoff: Specify a different cutoff time rather than using the default setting
* - addJoins: Add more joins for the query
* - addWhere: Add more checks for the 'where' part of the query (everything is joined with ' AND ')
* - overrideWhere: Specify manually the 'where' part of the query, the query must be already compiled
*
* <b>Example Usage:</b>
* @code
* $onlineUsers = $this->getUsersIn( 'forums', array( 'cutoff' => 90 ) );
* $onlineUsers = $this->getUsersIn( 'forums', array( 'cutoff' => 90, 'addJoins' => array( ... ), 'addWhere' => array( ... ) ) );
* $onlineUsers = $this->getUsersIn( 'forums', array( 'overrideWhere' => "s.current_appcomponent='forums' AND (s.running_time > TIME_A OR s.running_time < TIME_B)" ) );
* @endcode
*/
public function getUsersIn( $app, $options=array() )
{
/* Init vars and check options */
$return = array( 'stats' => array( 'total' => 0,
'members' => 0,
'guests' => 0,
'bots' => 0,
'anon' => 0 ),
'rows' => array( 'members' => array(),
'bots' => array(),
'guests' => array(),
'anon' => array() ),
'names' => array()
);
$cutoff = empty($options['cutoff']) ? $this->settings['au_cutoff'] : $options['cutoff'];
$limit = time() - ( $cutoff * 60 );
$rows = array();
$NOWJIM = IPS_UNIX_TIME_NOW;
$cached = array();
/* Sort joins */
$_joins = array( array( 'select' => 'm.*',
'from' => array( 'members' => 'm' ),
'where' => 'm.member_id=s.member_id',
'type' => 'left' ) );
if ( isset($options['addJoins']) && is_array($options['addJoins']) && count($options['addJoins']) )
{
$where = array_merge( $_joins, $options['addJoins'] );
}
/* Sort where.. override? */
if ( !empty($options['overrideWhere']) && is_string($options['overrideWhere']) )
{
$where = $options['overrideWhere'];
}
else
{
/* Normal where */
$where = array( "s.current_appcomponent='" . $app . "'", "s.running_time > " . $limit );
if ( isset($options['addWhere']) && is_array($options['addWhere']) && count($options['addWhere']) )
{
$where = array_merge( $where, $options['addWhere'] );
}
$where = implode( ' AND ', $where );
}
/* We're a member too? */
if ( $this->memberData['member_id'] )
{
$rows[ $NOWJIM . '.' . $this->memberData['member_id'] ] = array_merge( $this->memberData,
array( 'id' => $this->member->session_id,
'login_type' => substr($this->memberData['login_anonymous'],0, 1),
'running_time' => $NOWJIM,
'member_name' => $this->memberData['members_display_name'],
'member_group' => $this->memberData['member_group_id'],
'seo_name' => $this->memberData['members_seo_name'] )
);
}
/* Dee bee */
$this->DB->build( array( 'select' => 's.*, s.id as row_session_id',
'from' => array( 'sessions' => 's' ),
'where' => $where,
'add_join' => $_joins ) );
$this->DB->execute();
while( $session = $this->DB->fetch() )
{
if ( ! empty( $session['member_id'] ) AND $session['member_id'] == $this->memberData['member_id'] )
{
continue;
}
$session['id'] = $session['row_session_id'];
$rows[ $session['running_time'] . '.' . $session['id'] ] = $session;
}
/* No rows? */
if ( ! count( $rows ) )
{
return $return;
}
krsort( $rows );
/* Process them */
$filename = IPSLib::getAppDir( $app ) . '/extensions/coreExtensions.php';
if ( is_file( $filename ) )
{
$classToLoad = IPSLib::loadLibrary( $filename, 'publicSessions__' . $app, $app );
$loader = new $classToLoad();
if ( method_exists( $loader, 'parseOnlineEntries' ) )
{
$rows = $loader->parseOnlineEntries( $rows );
}
}
/* No rows? */
if ( ! count( $rows ) )
{
return $return;
}
/* Sort through */
foreach( $rows as $id => $result )
{
$last_date = $this->registry->getClass('class_localization')->getTime( $result['running_time'] );
/* ROBOT - or DODOT! */
if ( strstr( $result['id'], '_session' ) )
{
$botname = preg_replace( '/^(.+?)=/', "\\1", $result['id'] );
if ( ! $cached[ $result['member_name'] ] )
{
$result = IPSMember::buildProfilePhoto( $result );
$result['parsedMemberName'] = $result['member_name'];
$return['rows']['bots'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
$cached[ $result['member_name'] ] = 1;
}
$return['stats']['bots']++;
}
/* Guest */
else if ( ! $result['member_id'] )
{
$result = IPSMember::buildProfilePhoto( 0 );
$result['parsedMemberName'] = $this->lang->words['global_guestname'];
$return['rows']['guests'][ $result['id'] ] = $result;
$return['stats']['guests']++;
}
/* Member */
else
{
if ( empty( $cached[ $result['member_id'] ] ) )
{
$cached[ $result['member_id'] ] = 1;
$result = IPSMember::buildProfilePhoto( $result );
$result['parsedMemberName'] = IPSMember::makeNameFormatted( $result['member_name'], $result['member_group'] );
if ( $result['login_type'] )
{
if ( $this->memberData['g_access_cp'] )
{
$result['parsedMemberName'] = IPSMember::makeProfileLink( $result['parsedMemberName'], $result['member_id'], $result['seo_name'] );
$return['rows']['anon'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
}
$return['stats']['anon']++;
}
else
{
$result['parsedMemberName'] = IPSMember::makeProfileLink( $result['parsedMemberName'], $result['member_id'], $result['seo_name'] );
$return['rows']['members'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
$return['stats']['members']++;
}
}
}
}
$return['stats']['total'] = intval( $return['stats']['bots'] ) + intval( $return['stats']['guests'] ) + intval( $return['stats']['anon'] ) + intval( $return['stats']['members'] );
return $return;
}
<?php
/**
* @file api.php Provides global methods to retrieve active users from the sessions table
*~TERABYTE_DOC_READY~
* $Copyright: (c) 2001 - 2011 Invision Power Services, Inc.$
* $License: http://www.invisionpower.com/company/standards.php#license$
* $Author: bfarber $
* @since Friday 12th November 2010 16:58
* $LastChangedDate: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* @version v3.3.4
* $Revision: 10914 $
*/
/**
*
* @class session_api
* @brief Provides global methods to retrieve active users from the sessions table
*
*/
class session_api
{
/**
* Registry Object Shortcuts
*
* @var $registry
* @var $DB
* @var $settings
* @var $request
* @var $lang
* @var $member
* @var $memberData
* @var $cache
* @var $caches
*/
protected $registry;
protected $DB;
protected $settings;
protected $request;
protected $lang;
protected $member;
protected $memberData;
protected $cache;
protected $caches;
private $_sClass = null;
const NO_AUTO_SESSION_PARSING = true;
/**
* Constructor
*
* @param object $registry Registry object
* @return @e void
*/
public function __construct( ipsRegistry $registry )
{
/* Make object */
$this->registry = $registry;
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->lang = $this->registry->getClass('class_localization');
$this->member = $this->registry->member();
$this->memberData =& $this->registry->member()->fetchMemberData();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
}
/**
* Returns a list (with buildProfilePhoto set) of users in an application
*
* @param string $app Application folder/key
* @param array $options Array of options to add/override checks for the query
* @return @e array Array of found sessions (members, guests, bots, anons)
*
* <b>Filters:</b>
* - cutoff: Specify a different cutoff time rather than using the default setting
* - addJoins: Add more joins for the query
* - addWhere: Add more checks for the 'where' part of the query (everything is joined with ' AND ')
* - overrideWhere: Specify manually the 'where' part of the query, the query must be already compiled
* - overrideGroup: if set to true the check against the 'gbw_view_online_lists' group setting is skipped
* - skipParsing: If set to true the parseOnlineEntries from coreExtensions is NOT executed
* - includeErrors: If set to true the in_error=1 lines are loaded as well from the table
* - excludeViewer: If set to true skips loading the row for the current session_id, it is required to load the current member viewing the page as sessions table is not updated at this point yet but only on destruct
*
* <b>Example Usage:</b>
* @code
* $onlineUsers = $this->getUsersIn( 'forums', array( 'cutoff' => 90 ) );
* $onlineUsers = $this->getUsersIn( 'forums', array( 'cutoff' => 90, 'addJoins' => array( ... ), 'addWhere' => array( ... ) ) );
* $onlineUsers = $this->getUsersIn( 'forums', array( 'overrideWhere' => "s.current_appcomponent='forums' AND (s.running_time > TIME_A OR s.running_time < TIME_B)" ) );
* @endcode
*/
public function getUsersIn( $app, $options=array() )
{
/* App we're checking is not even installed? */
if ( ! IPSLib::appIsInstalled( $app, false ) )
{
return array();
}
/* Can't view online lists? */
if ( empty($options['overrideGroup']) && ! $this->memberData['gbw_view_online_lists'] )
{
return array();
}
/* Init vars and check options */
$return = array( 'stats' => array( 'total' => 0,
'members' => 0,
'guests' => 0,
'bots' => 0,
'anon' => 0 ),
'rows' => array( 'members' => array(),
'bots' => array(),
'guests' => array(),
'anon' => array() ),
'names' => array()
);
$cutoff = empty($options['cutoff']) ? $this->settings['au_cutoff'] : $options['cutoff'];
$limit = time() - ( $cutoff * 60 );
$rows = array();
$NOWJIM = IPS_UNIX_TIME_NOW;
$cached = array();
/* Sort joins */
$_joins = array( array( 'select' => 'm.*',
'from' => array( 'members' => 'm' ),
'where' => 'm.member_id=s.member_id',
'type' => 'left' ) );
if ( isset($options['addJoins']) && is_array($options['addJoins']) && count($options['addJoins']) )
{
$_joins = array_merge( $_joins, $options['addJoins'] );
}
/* Sort where.. override? */
if ( !empty($options['overrideWhere']) && is_string($options['overrideWhere']) )
{
$where = $options['overrideWhere'];
}
else
{
/* Normal where */
$where = array( "s.current_appcomponent='" . $this->DB->addSlashes( $app ) . "'", 's.running_time > ' . $limit );
/* Load error rows? */
if ( empty($options['includeErrors']) )
{
$where[] = 's.in_error=0';
}
/* Add more where parts */
if ( isset($options['addWhere']) && is_array($options['addWhere']) && count($options['addWhere']) )
{
$where = array_merge( $where, $options['addWhere'] );
}
$where = implode( ' AND ', $where );
}
/* We're a viewer too? Get our session separately */
$_extraWhere = empty($options['excludeViewer']) ? "s.id='{$this->member->session_id}' OR " : '';
/* Dee bee */
$this->DB->build( array( 'select' => 's.*, s.id as row_session_id',
'from' => array( 'sessions' => 's' ),
'where' => "{$_extraWhere}({$where})",
'add_join' => $_joins ) );
$this->DB->execute();
while( $session = $this->DB->fetch() )
{
/* Reset for possible bad joins */
$session['id'] = $session['row_session_id'];
/* Update our own session properly? */
if ( $session['id'] == $this->member->session_id )
{
$session = array_merge( $session, $this->member->sessionClass()->returnCurrentSession() );
}
$rows[ $session['running_time'] . '.' . $session['id'] ] = $session;
}
/* No rows? */
if ( ! count( $rows ) )
{
return $return;
}
krsort( $rows );
/* Are we parsing online entries or want only the names */
if ( empty( $options['skipParsing'] ) )
{
/* Process them */
$filename = IPSLib::getAppDir( $app ) . '/extensions/coreExtensions.php';
if ( is_file( $filename ) )
{
$classToLoad = IPSLib::loadLibrary( $filename, 'publicSessions__' . $app, $app );
$loader = new $classToLoad();
if ( method_exists( $loader, 'parseOnlineEntries' ) )
{
$rows = $loader->parseOnlineEntries( $rows );
}
}
/* No rows? */
if ( ! count( $rows ) )
{
return $return;
}
}
/* Sort through */
foreach( $rows as $id => $result )
{
$last_date = $this->registry->getClass('class_localization')->getTime( $result['running_time'] );
/* ROBOT - or DODOT! */
if ( strstr( $result['id'], '_session' ) )
{
$botname = preg_replace( '/^(.+?)=/', "\\1", $result['id'] );
if ( ! $cached[ 'srch_' . $result['member_name'] ] )
{
$result = IPSMember::buildProfilePhoto( $result );
$result['parsedMemberName'] = $result['member_name'];
$return['rows']['bots'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
$cached[ 'srch_' . $result['member_name'] ]['count'] = 1;
}
else
{
$cached[ 'srch_' . $result['member_name'] ]['count']++;
}
$return['stats']['bots']++;
}
/* Guest */
else if ( ! $result['member_id'] )
{
$result = IPSMember::buildProfilePhoto( 0 );
$result['parsedMemberName'] = $this->lang->words['global_guestname'];
$return['rows']['guests'][ $result['id'] ] = $result;
$return['stats']['guests']++;
}
/* Member */
else
{
if ( empty( $cached[ $result['member_id'] ] ) )
{
$cached[ $result['member_id'] ] = 1;
$result = IPSMember::buildProfilePhoto( $result );
$result['parsedMemberName'] = IPSMember::makeNameFormatted( $result['member_name'], $result['member_group'] );
/* Reset login type in case the board/group setting got changed */
$result['login_type'] = IPSMember::isLoggedInAnon( array( 'login_anonymous' => $result['login_type'] ), $result['member_group_id'] );
if ( $result['login_type'] )
{
if ( $this->memberData['g_access_cp'] || ( $this->memberData['member_id'] == $result['member_id'] ) )
{
$result['parsedMemberName'] = IPSMember::makeProfileLink( $result['parsedMemberName'], $result['member_id'], $result['seo_name'] );
$result['parsedMemberName'] .= '*'; # Add anonymous asterisk
$return['rows']['anon'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
}
$return['stats']['anon']++;
}
else
{
$result['parsedMemberName'] = IPSMember::makeProfileLink( $result['parsedMemberName'], $result['member_id'], $result['seo_name'] );
$return['rows']['members'][ $result['id'] ] = $result;
$return['names'][ $result['id'] ] = $result['parsedMemberName'];
$return['stats']['members']++;
}
}
}
}
/* Process bots */
foreach( $cached as $name => $val )
{
if ( $val['count'] && substr( $name, 0, 5 ) == 'srch_' )
{
foreach( $return['rows']['bots'] as $row )
{
if ( $row['parsedMemberName'] == substr( $name, 5 ) )
{
$return['rows']['bots'][ $row['id'] ]['parsedMemberName'] .= ' (' . $val['count'] . ')';
$return['rows']['bots'][ $row['id'] ]['member_name'] = $return['rows']['bots'][ $row['id'] ]['parsedMemberName'];
$return['names'][ $row['id'] ] = $return['rows']['bots'][ $row['id'] ]['parsedMemberName'];
break;
}
}
}
}
$return['stats']['total'] = intval( $return['stats']['bots'] ) + intval( $return['stats']['guests'] ) + intval( $return['stats']['anon'] ) + intval( $return['stats']['members'] );
return $return;
}
/**
* Fetch session by member id
* @param int Member Id
* @return array session data
*/
public function getSessionByMemberId( $memberId )
{
$_session = $this->DB->buildAndFetch( array( 'select' => '*',
'from' => 'sessions',
'where' => "member_id=" . intval( $memberId ) ) );
if ( $_session['id'] )
{
/* Test for browser.... */
if ( $this->settings['match_browser'])
{
if ( $_session['browser'] != substr( $this->member->user_agent, 0, 200 ) )
{
return false;
}
}
/* Test for IP Address... */
if ( $this->settings['match_ipaddress'] )
{
if ( $_session['ip_address'] != $this->member->ip_address )
{
return false;
}
}
return $_session;
}
return false;
}
/**
* Log user in remotely.
* @param array Array of member data (member_id, etc) or Id
*/
public function logGuestInAsMember( $member )
{
if ( is_numeric( $member ) )
{
$member = IPSMember::load( $member );
}
/* Check for existing session */
$ip = ipsRegistry::member()->ip_address;
$_session = $this->DB->buildAndFetch( array( 'select' => '*',
'from' => 'sessions',
'where' => "ip_address='{$ip}'" ) );
if ( !$_session['id'] or !$_session['member_id'] )
{
$this->_getSessionClass()->convertGuestToMember( $member, $member );
}
}
/**
* Load session class if not loaded
*/
protected function _getSessionClass()
{
if ( ! is_object( $this->_sClass ) )
{
$classToLoad = IPSLib::loadLibrary( IPS_ROOT_PATH . 'sources/classes/session/publicSessions.php', 'publicSessions' );
/**
* Support for extending the session class
*/
if ( is_file( IPS_ROOT_PATH . "sources/classes/session/ssoPublicSessions.php" ) )
{
$classToLoadA = IPSLib::loadLibrary( IPS_ROOT_PATH . "sources/classes/session/ssoPublicSessions.php", 'ssoPublicSessions' );
/**
* Does the ssoPublicSessions class exist?
*/
if( class_exists( $classToLoadA ) )
{
$parent = get_parent_class( $classToLoadA );
/**
* Is it a child of publicSessions
*/
if ( $parent == $classToLoad )
{
$this->_sClass = new $classToLoadA( self::NO_AUTO_SESSION_PARSING );
}
else
{
$this->_sClass = new $classToLoad( self::NO_AUTO_SESSION_PARSING );
}
}
}
else
{
$this->_sClass = new $classToLoad( self::NO_AUTO_SESSION_PARSING );
}
}
return $this->_sClass;
}
}
@@ -1,75 +1,75 @@
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.2.3
* This class overrides parent publicSessions to prevent construct being called
* It doesn't do anything else...
* Last Updated: $Date: 2011-05-05 07:03:47 -0400 (Thu, 05 May 2011) $
* </pre>
*
* @author $Author: ips_terabyte $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license This is NULLED!
* @package IP.Board
* @subpackage IP.Converge
* @link http://hatynka.in
* @since 22nd May 2008 11:15 AM
* @version $Revision: 8644 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class convergeSessions extends publicSessions
{
/**
* Constructor
*
* @access public
* @param object ipsRegistry reference
* @return @e void
*/
public function __construct( $registry )
{
/* Make object */
$this->registry = ipsRegistry::instance();
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
$this->_member = self::instance();
$this->_memberData =& self::instance()->fetchMemberData();
$this->_userAgent = substr( $this->_member->user_agent, 0, 200 );
//-----------------------------------------
// Fix up app / section / module
//-----------------------------------------
$this->current_appcomponent = IPS_APP_COMPONENT;
$this->current_module = IPSText::alphanumericalClean( $this->request['module'] );
$this->current_section = IPSText::alphanumericalClean( $this->request['section'] );
$this->settings['session_expiration'] = ( $this->settings['session_expiration'] ) ? $this->settings['session_expiration'] : 60;
}
/**
* Create a member session
*
* @access public
* @return string Session id
*/
public function createMemberSession()
{
parent::_createMemberSession();
return $this->session_data['id'];
}
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* This class overrides parent publicSessions to prevent construct being called
* It doesn't do anything else...
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* </pre>
*
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @subpackage IP.Converge
* @link http://www.invisionpower.com
* @since 22nd May 2008 11:15 AM
* @version $Revision: 10914 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class convergeSessions extends publicSessions
{
/**
* Constructor
*
* @access public
* @param object ipsRegistry reference
* @return @e void
*/
public function __construct( $registry )
{
/* Make object */
$this->registry = ipsRegistry::instance();
$this->DB = $this->registry->DB();
$this->settings =& $this->registry->fetchSettings();
$this->request =& $this->registry->fetchRequest();
$this->cache = $this->registry->cache();
$this->caches =& $this->registry->cache()->fetchCaches();
$this->_member = self::instance();
$this->_memberData =& self::instance()->fetchMemberData();
$this->_userAgent = substr( $this->_member->user_agent, 0, 200 );
//-----------------------------------------
// Fix up app / section / module
//-----------------------------------------
$this->current_appcomponent = IPS_APP_COMPONENT;
$this->current_module = IPSText::alphanumericalClean( $this->request['module'] );
$this->current_section = IPSText::alphanumericalClean( $this->request['section'] );
$this->settings['session_expiration'] = ( $this->settings['session_expiration'] ) ? $this->settings['session_expiration'] : 60;
}
/**
* Create a member session
*
* @access public
* @return string Session id
*/
public function createMemberSession()
{
parent::_createMemberSession();
return $this->session_data['id'];
}
}
@@ -1,10 +1,10 @@
<html>
<head><title>IP.Board - Bulletin Board System</title></head>
<body>
<h1>403: IP.Board -&gt; Forbidden</h1>
<hr>
You have reached this page in error, please use your back button to return to the forum.
<hr>
<a href="http://www.invisionpower.com">IP.Board</a>
</body>
<html>
<head><title>IP.Board - Bulletin Board System</title></head>
<body>
<h1>403: IP.Board -&gt; Forbidden</h1>
<hr>
You have reached this page in error, please use your back button to return to the forum.
<hr>
<a href="http://www.invisionpower.com">IP.Board</a>
</body>
</html>
File diff suppressed because it is too large. Load diff
@@ -3,18 +3,18 @@
/**
* <pre>
* Invision Power Services
* IP.Board v3.2.3
* IP.Board v3.3.4
* Sample SSO Class
* Last Updated: $Date: 2010-12-17 08:01:38 -0500 (Fri, 17 Dec 2010) $
* Last Updated: $Date: 2012-06-12 10:14:49 -0400 (Tue, 12 Jun 2012) $
* </pre>
*
* @author $Author: ips_terabyte $
* @author $Author: bfarber $
* @copyright (c) 2001 - 2009 Invision Power Services, Inc.
* @license This is NULLED!
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://hatynka.in
* @link http://www.invisionpower.com
* @since 22nd Septmeber 2009
* @version $Revision: 7445 $
* @version $Revision: 10914 $
*
*/
@@ -0,0 +1,65 @@
<?php
/**
* <pre>
* Invision Power Services
* IP.Board v3.3.4
* Sample Mobile App SSO Class
* Last Updated: $Date: 2012-05-10 21:10:13 +0100 (Thu, 10 May 2012) $
* </pre>
*
* @author $Author: Matt $
* @copyright (c) 2001 - 2012 Invision Power Services, Inc.
* @license http://www.invisionpower.com/company/standards.php#license
* @package IP.Board
* @link http://www.invisionpower.com
* @since 22nd Septmeber 2009
* @version $Revision: 10721 $
*
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class ssoMobileAppLogIn
{
/**
* Constructor
*
* @access public
* @param object ipsRegistry object
*/
public function __construct( ipsRegistry $registry )
{
}
/**
* authenticate
* Used to authenticate a user from the mobile app to your SSO framework
*
* @access public
* @param string $username Username sent from app
* @param string $password Password sent from app (plain text version)
*/
public function authenticate( $username, $password )
{
/*
You are expected to authenticate the user against your SSO framework.
The return value is an array:
'code' is a string of:
SUCCESS - User authenticated
FAILED - User did not authenticate
'memberId' is an INT of the IPB member ID of the user who authenticated
*/
/* Default value */
return array( 'code' => 'FAILED',
'memberId' => 0 );
}
}