diff --git a/Credits.txt b/Credits.txt index c8081d33..c2e972b8 100644 --- a/Credits.txt +++ b/Credits.txt @@ -6,7 +6,7 @@ has been used throughout Invision Community to add style, flair and functionalit to our product. NULLING - Last Updated: 25 July 2017 + Last Updated: 18 April 2018 Author: IPBMafia.ru AES implementation in PHP @@ -22,17 +22,10 @@ BMDoHyeon font package Website: http://font.woowahan.com/dohyeon/ License: Open Font License -Buzz.js - Description: HTML5 audio support for notifications - Location: applications/core/interface/buzz - Included version: 1.2 - Website: http://buzz.jaysalvat.com/ - License: http://opensource.org/licenses/MIT - CKEditor Description: Provides the editor functionality for submitting content. Location: In development: applications/core/dev/ckeditor (custom build with additional plugins and some code changes) - Included version: 4.7.1 + Included version: 4.9 Website: http://ckeditor.com License: http://www.gnu.org/copyleft/lesser.html @@ -56,6 +49,13 @@ Devices Icon Pack Website: https://www.iconfinder.com/iconsets/devices-42 License: Free for commercial use +EmojiOne + Description: Emoji images + Location: Served from CDN + Included version: 3.1 + Website: https://www.emojione.com + License: https://d1j8pt39hxlh3d.cloudfront.net/license-free.pdf + FontAwesome Description: General icons for UI Location: Font files in applications/core/interface/font and CSS in development in applications/core/dev/css/global/framework/fonts.css (mixed with other CSS and modified to use correct path to font files) @@ -95,7 +95,14 @@ history.js Included version: 1.8b2 Website: https://github.com/browserstate/history.js License: https://github.com/browserstate/history.js#license - + +Howler + Description: HTML5 audio api + Location: applications/core/interface/howler + Included version: 2.0.9 + Website: https://github.com/goldfire/howler.js + License: http://opensource.org/licenses/MIT + HTML5shiv Description: Provides some HTML5 compatability for IE8 Location: applications/core/interface/html5shiv/html5shiv.js @@ -106,7 +113,7 @@ HTML5shiv HTMLPurifier Description: Validates and cleans submitted HTML for content Location: system/3rd_party/HTMLPurifier - Included version: 4.9.3 + Included version: 4.10.0 Website: http://htmlpurifier.org License: http://www.gnu.org/copyleft/lesser.html @@ -307,7 +314,14 @@ success.mp3 Notification Sound by RCP Tones Location: /applications/core/interface/sounds/success.mp3 Website: http://rcptones.com/dev_tones/ License: http://creativecommons.org/licenses/by/3.0/us/ - + +Twemoji + Description: Emoji images + Location: Served from CDN + Included version: 2.3 + Website: http://twitter.github.io/twemoji/ + License: https://github.com/twitter/twemoji/blob/gh-pages/LICENSE + Underscore.js Description: General-purpose functional JS library Location: dev/js/library/underscore/ @@ -315,13 +329,6 @@ Underscore.js Website: http://underscorejs.org License: https://github.com/documentcloud/underscore/blob/master/LICENSE -Video.js - Description: HTML5 video player for Gallery - Location: applications/interface/videojs - Included version: 5.19.2 - Website: http://www.videojs.com/ - License: https://github.com/videojs/video.js/blob/master/LICENSE - Whoops Description: Provides error handling for development mode Location: dev/Whoops @@ -341,4 +348,11 @@ XRegExp (with addons) Location: In development: dev/js/library/xregexp/xregexp-all.js Included Version: 3.2.0 Website: http://xregexp.com + License: http://mit-license.org + +Hammer.js + Description: Provides touch and gesture javascript event support + Location: dev/js/library/hammer + Included Version: 2.0.8 + Website: http://hammerjs.github.io License: http://mit-license.org \ No newline at end of file diff --git a/admin/convertutf8/init.php b/admin/convertutf8/init.php index e8dfe29e..f39a5028 100644 --- a/admin/convertutf8/init.php +++ b/admin/convertutf8/init.php @@ -95,7 +95,8 @@ class IPSUtf8 */ public static function errorHandler( $errno, $errstr, $errfile, $errline, $trace=NULL ) { - if ( in_array( $errno, array( E_NOTICE ) ) ) + /* We don't care about these in production */ + if ( in_array( $errno, array( E_WARNING, E_NOTICE, E_STRICT, E_DEPRECATED ) ) ) { return; } @@ -246,4 +247,11 @@ class IPSUtf8 /* Init */ IPSUtf8::init(); - +/* Custom mb_ucfirst() function - eval'd so we can put into global namespace */ +eval( ' +function mb_ucfirst() +{ + $text = func_get_arg( 0 ); + return mb_strtoupper( mb_substr( $text, 0, 1 ) ) . mb_substr( $text, 1 ); +} +'); \ No newline at end of file diff --git a/admin/convertutf8/system/Convert/Convert.php b/admin/convertutf8/system/Convert/Convert.php index 5040904d..00ea8aaa 100644 --- a/admin/convertutf8/system/Convert/Convert.php +++ b/admin/convertutf8/system/Convert/Convert.php @@ -995,7 +995,7 @@ class Convert { foreach( $tableData['definition']['indexes'] as $key => $index ) { - if ( $index['type'] === 'unique' ) + if ( $index['type'] === 'unique' OR $index['type'] === 'primary' ) { /* Make sure none of the columns in this index are auto_increment */ foreach( $index['columns'] AS $k => $idxcol ) @@ -1030,7 +1030,9 @@ class Convert /* Did not work - try the long way */ static::$utf->query( "RENAME TABLE `" . static::$db->prefix . $name . "` TO `" . static::$db->prefix . $name . "_temp`" ); static::log( $name . " has Unique Index - temp table created from main." ); - static::$utf->query( "CREATE TABLE `" . static::$db->prefix . $name . "` LIKE `" . static::$db->prefix . $name . "_temp`" ); + /* Previously we used a raw create table query to create a copy, however this does not check index lengths. Leaving this for reference. */ + //static::$utf->query( "CREATE TABLE `" . static::$db->prefix . $name . "` LIKE `" . static::$db->prefix . $name . "_temp`" ); + static::$db->createTable( $this->checkTable( $tableData['definition'] ) ); static::$utf->query( "ALTER TABLE `" . static::$db->prefix . $name . "` CONVERT TO CHARACTER SET " . $charset . " COLLATE " . $collation ); static::$utf->query( "ALTER TABLE `" . static::$db->prefix . $name . "` DEFAULT CHARACTER SET " . $charset . " COLLATE " . $collation ); static::log( $name . " created from temp table." ); @@ -1280,7 +1282,7 @@ class Convert /* MB4? */ $sessionData = \IPSUtf8\Session::i()->json; $length = 0; - $multiplier = ( ! empty( $sessionData['use_utf8mb4'] ) ) ? 4 : 3; + $multiplier = 4; $needsFixing = array(); $maxLen = 1000; @@ -1293,30 +1295,44 @@ class Convert { foreach( $definition['indexes'] as $key => $index ) { + $thisLength = null; + $hasText = false; + foreach( $index['columns'] as $i => $column ) { - if ( isset( $definition['columns'][ $column ] ) and ( ( ! empty( $definition['columns'][ $column ]['length'] ) or in_array( mb_strtolower( $definition['columns'][ $column ]['type'] ), array( 'longtext', 'mediumtext', 'text' ) ) ) ) ) + $thisLength = ( isset( $index['length'][ $i ] ) ) ? $index['length'][ $i ] : ( ( (int) $definition['columns'][ $column ]['length'] or empty( $definition['columns'][ $column ]['length'] ) ) ? $definition['columns'][ $column ]['length'] : 250 ); + + $isText = in_array( mb_strtolower( $definition['columns'][ $column ]['type'] ), array( 'mediumtext', 'text' ) ); + + if ( $hasText === false and $isText === true ) { - $length += (int) ( $definition['columns'][ $column ]['length'] ) ? $definition['columns'][ $column ]['length'] : 250; + $hasText = true; + } + + if ( isset( $definition['columns'][ $column ] ) and ( ( ! empty( $thisLength ) or $isText ) ) ) + { + $length += $thisLength; } } - - if ( $length * $multiplier > $maxLen ) + + if ( ( $length * $multiplier > $maxLen ) or $hasText ) { foreach( $index['columns'] as $i => $column ) { - if ( isset( $definition['columns'][ $column ] ) and ( ( ! empty( $definition['columns'][ $column ]['length'] ) or in_array( mb_strtolower( $definition['columns'][ $column ]['type'] ), array( 'longtext', 'mediumtext', 'text' ) ) ) ) ) + $thisLength = ( isset( $index['length'][ $i ] ) ) ? $index['length'][ $i ] : ( (int) $definition['columns'][ $column ]['length'] ? $definition['columns'][ $column ]['length'] : 250 ); + + if ( isset( $definition['columns'][ $column ] ) and ( ( ! empty( $thisLength ) or in_array( mb_strtolower( $definition['columns'][ $column ]['type'] ), array( 'mediumtext', 'text' ) ) ) ) ) { /* Column name, column length, column type */ - $needsFixing[ $key ][ $i ] = array( $column, ( (int) $definition['columns'][ $column ]['length'] ) ? $definition['columns'][ $column ]['length'] : 250, $definition['columns'][ $column ]['type'] ); + $needsFixing[ $key ][ $i ] = array( $column, $thisLength, $definition['columns'][ $column ]['type'] ); } } } - + $length = 0; } } - + if ( count( $needsFixing ) ) { foreach( $needsFixing as $key => $i ) @@ -1334,21 +1350,23 @@ class Convert /* Check each column can be reduced by the amount we need reducing */ $debt = 0; - $reduceEachBy = ( ( 100 / $totalLength ) * $maxChars ) / 100; - + $reduceEachBy = ( ( 100 / $totalLength ) * $maxChars) / 100; + /* Apply debt if we have any. We do not reduce integers */ foreach( $i as $x => $vals ) { - if ( array_key_exists( mb_strtolower( $vals[2] ), static::$numericCols ) AND static::$numericCols[ mb_strtolower( $vals[2] ) ] !== NULL ) + if ( in_array( mb_strtoupper( $vals[2] ), array_keys( static::$numericCols ) ) ) { - /* Don't go by "display" space, go by storage space, which is static regardless of supplied value ... an INT(4) still uses 11 chars */ - $debt += static::$numericCols[ mb_strtolower( $vals[2] ) ]; + $debt += $vals[1]; } } /* Recalculate value to multiply index sub lengths with (subtracting debt) */ - $reduceEachBy = ( ( 100 / ( $totalLength - $debt ) ) * ( $maxChars - $debt ) ) / 100; - + if ( $debt < $totalLength ) + { + $reduceEachBy = ( ( 100 / ($totalLength - $debt) ) * ( $maxChars - $debt ) ) / 100; + } + foreach( $i as $x => $vals ) { /* No length? */ @@ -1357,9 +1375,16 @@ class Convert $vals[1] = 250; } - if ( array_key_exists( mb_strtolower( $vals[2] ), static::$numericCols ) AND static::$numericCols[ mb_strtolower( $vals[2] ) ] !== NULL ) + if ( in_array( mb_strtoupper( $vals[2] ), array_keys( static::$numericCols ) ) ) { - /* Preserve col len */ + /* Preserve col len where possible but if the column length is greater than subpart allowed, NULL the length + otherwise MySQL will complain as you cannot use subpart on non-string column. */ + if ( $vals[1] > floor( $maxLen / $multiplier ) ) + { + $vals[1] = NULL; + $i[ $x ] = $vals; + } + continue; } @@ -1370,9 +1395,13 @@ class Convert foreach( $i as $x => $vals ) { - if ( $definition['columns'][ $definition['indexes'][ $key ]['columns'][ $x ] ]['length'] != $vals[1] ) + if ( in_array( mb_strtolower( $vals[2] ), static::$convertCols ) AND $definition['columns'][ $definition['indexes'][ $key ]['columns'][ $x ] ]['length'] != $vals[1] ) { - $definition['indexes'][ $key ]['length'][ $x ] = $vals[1]; + $definition['indexes'][ $key ]['length'][ $x ] = intval( $vals[1] ); + } + else + { + $definition['indexes'][ $key ]['length'][ $x ] = NULL; } } } diff --git a/admin/convertutf8/system/Text/Charset.php b/admin/convertutf8/system/Text/Charset.php index 703a0459..08eef5b0 100644 --- a/admin/convertutf8/system/Text/Charset.php +++ b/admin/convertutf8/system/Text/Charset.php @@ -74,7 +74,7 @@ abstract class Charset } } - self::$method = ucfirst( self::$method ); + self::$method = mb_ucfirst( self::$method ); if ( ! isset( static::$multitons[ self::$method ] ) ) { diff --git a/admin/index.php b/admin/index.php index 5e72b753..54f65fa5 100644 --- a/admin/index.php +++ b/admin/index.php @@ -9,5 +9,6 @@ */ define('READ_WRITE_SEPARATION', FALSE); +define('REPORT_EXCEPTIONS', TRUE); require_once '../init.php'; \IPS\Dispatcher\Admin::i()->run(); \ No newline at end of file diff --git a/admin/install/emoticons/data.json b/admin/install/emoticons/data.json index de3cb73f..080014c0 100644 --- a/admin/install/emoticons/data.json +++ b/admin/install/emoticons/data.json @@ -1,85 +1,85 @@ { - ">:(": { + ":classic_angry:": { "image": "angry.png", "image_2x": "angry@2x.png" }, - ":D": { + ":classic_biggrin:": { "image": "biggrin.png", "image_2x": "biggrin@2x.png" }, - "O.o": { + ":classic_blink:": { "image": "blink.png", "image_2x": "blink@2x.png" }, - ":$": { + ":classic_blush:": { "image": "blush.png", "image_2x": "blush@2x.png" }, - "B|": { + ":classic_cool:": { "image": "cool.png", "image_2x": "cool@2x.png" }, - "¬¬": { + ":classic_dry:": { "image": "dry.png", "image_2x": "dry@2x.png" }, - "^_^": { + ":classic_happy:": { "image": "happy.png", "image_2x": "happy@2x.png" }, - "o.O": { + ":classic_huh:": { "image": "huh.png", "image_2x": "huh@2x.png" }, - "xD": { + ":classic_laugh:": { "image": "laugh.png", "image_2x": "laugh@2x.png" }, - ":|": { + ":classic_mellow:": { "image": "mellow.png", "image_2x": "mellow@2x.png" }, - ":o": { + ":classic_ohmy:": { "image": "ohmy.png", "image_2x": "ohmy@2x.png" }, - ":ph34r:": { + ":classic_ninja:": { "image": "ph34r.png", "image_2x": "ph34r@2x.png" }, - "9_9": { + ":classic_rolleyes:": { "image": "rolleyes.gif", "image_2x": "rolleyes@2x.png" }, - ":(": { + ":classic_sad:": { "image": "sad.png", "image_2x": "sad@2x.png" }, - "-_-": { + ":classic_sleep:": { "image": "sleep.png", "image_2x": "sleep@2x.png" }, - ":)": { + ":classic_smile:": { "image": "smile.png", "image_2x": "smile@2x.png" }, - ":P": { + ":classic_tongue:": { "image": "tongue.png", "image_2x": "tongue@2x.png" }, - ":/": { + ":classic_unsure:": { "image": "unsure.png", "image_2x": "unsure@2x.png" }, - ":S": { + ":classic_wacko:": { "image": "wacko.png", "image_2x": "wacko@2x.png" }, - ";)": { + ":classic_wink:": { "image": "wink.png", "image_2x": "wink@2x.png" }, - ":x": { + ":classic_love:": { "image": "wub.png", "image_2x": "wub@2x.png" } diff --git a/admin/install/emoticons/rolleyes.gif b/admin/install/emoticons/rolleyes.gif index def8a49d..73368922 100644 Binary files a/admin/install/emoticons/rolleyes.gif and b/admin/install/emoticons/rolleyes.gif differ diff --git a/admin/install/emoticons/sleep.png b/admin/install/emoticons/sleep.png index c9b00808..599ab3a7 100644 Binary files a/admin/install/emoticons/sleep.png and b/admin/install/emoticons/sleep.png differ diff --git a/admin/install/eula.txt b/admin/install/eula.txt index 4755f467..1e3fd974 100644 --- a/admin/install/eula.txt +++ b/admin/install/eula.txt @@ -1 +1 @@ -=============================[NOTE]============================= This software is Nulled! Nulled by IPBMafia.ru Buy license at https://www.invisionpower.com/buy/self-hosted ================================================================ IPS 4.2.0 Release (102002) =============================[NOTE]============================= Invision Community End User License Agreement 1. Acceptance This software license agreement (the “Agreement”) is between you (either an individual or entity, hereinafter referred to as “You” or “Your”) and Invision Power Services, Inc. (“IPS”, “We”, “Our” or “Us”) and pertains to the Invision Community software, its components, features, enhancements, updates and modifications (collectively the “Software” or “Suite”) and any related services (“Services”) provided by IPS under this Agreement. By purchasing, downloading, accessing, installing, facilitating the installation or using the Software or Services (or allowing or authorizing any other person to do so) you are warranting that you have the authority provided by your state, country or jurisdiction to enter into a legally binding contract and that you have read and agree to be bound by the terms of this Agreement. You understand and acknowledge that this Agreement comprises the entire agreement between You and IPS. This Agreement supersedes any prior agreements, promises, representations or descriptions. If you do not agree with the terms and conditions set forth hereinafter, you may not purchase, download, access, install or use the Software or Services. This Agreement may only be modified in writing, signed by an officer of IPS and You. 2. License Scope and Grant In consideration for payment of all applicable license fees and subject to the terms and conditions of this Agreement, IPS grants you a revocable, limited and non-exclusive license to install and use the Software and Services on a single installation, accessible via one URL. Access to services, components, software updates and technical support require an active license. All rights in and to the Software and Services are reserved to the use and benefit of IPS and/or its licensors, successors and assigners. (a) Test Installation. You may install and test one additional instance of the Software for the purpose of development and testing. This installation must be and remain isolated and inaccessible to the general public at all times. 3. Restrictions Your license to use the Software and Services is subject to the following terms, conditions and restrictions on use: (a) You may alter and modify the Software’s source code for Your use, subject to this Agreement, however, you may not distribute, publish, resell, or otherwise share the Software or derivative works based on the Software without prior express written consent from IPS. (b) You may not utilize the Software or Services to engage in, facilitate, or otherwise allow others to engage in any activity that violates any law or regulation or the terms and conditions within this Agreement. (c) You are solely responsible for complying with all governmental regulations and policies. You agree to indemnify Us from any loss, action or damage arising from Your failure to use the Software in a manner inconsistent with applicable legislation. (d) You may not remove any copyright or proprietary notices on or within the software’s source code at any time. A copyright removal license may be purchased to remove the public display of the Software’s publicly displayed copyright notice. 4. Intellectual Property We have the sole and exclusive right to the Software which is being licensed, not sold, to you by IPS under the terms and conditions of this agreement. The Software is protected by copyright, trademark and other intellectual property laws. IPS reserves any rights not expressly granted herein. 5. Assignment You may not rent, lease, sell, share or authorize or temporarily assign your rights to the license or this Agreement to another individual or entity except as expressly permitted herein. (a) You may, after six months from the original purchase date, permanently transfer your licensing rights and interest in this Agreement to a third party, provided the license is active and in good standing. Any transfer and reassignment must occur via the mechanisms provided within the invisioncommunity.com client area and all applicable fees must be paid for the reassignment to be considered valid. (b) You agree to provide this Agreement in its entirety to the assignee prior to reassignment and the assignee must agree to be bound to the terms of this Agreement. (c) You acknowledge that account and non license specific materials and purchases, including, but not limited to: account credits and third party (“marketplace”) add-ons and purchases are non-transferrable under any circumstances. (d) We reserve the right to refuse or reject reassignment at our sole discretion. 6. Termination This Agreement shall remain in effect until terminated. Your rights under this Agreement will automatically terminate without notice from Us in the event you fail to comply with any term or condition within this Agreement. Upon termination of this Agreement, you shall immediately cease all use of the Software and destroy all copies, full or partial, of the Software that may be in your possession or otherwise under your control. 7. Modification We reserve the right to amend or modify the terms of this Agreement at any time, and to change, discontinue or impose conditions on any aspect of the Software or related Service and to provide notification solely by posting an updated version of the Agreement on the invisioncommunity.com website. You acknowledge that you are solely responsible for regularly reviewing this Agreement and our policies. Continued use of the Software after modification to the Agreement constitutes your binding consent to such changes. 8. Disclaimer of Warranty THE SOFTWARE IS PROVIDED “AS-IS” AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE DISCLAIM ALL OTHER WARRANTIES, CONDITIONS, REPRESENTATIONS OR TERMS, EXPRESS OR IMPLIED, BY STATUTE, COMMON LAW, USAGE OR OTHERWISE, REGARDING THE SOFTWARE AND ANY RELATED SERVICES, INCLUDING THEIR FITNESS FOR A PARTICULAR PURPOSE, THEIR QUALITY, THEIR MERCHANTABILITY, OR THEIR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SOFTWARE OR ANY RELATED SERVICES IS SECURE, OR IS FREE FROM BUGS, VIRUSES, ERRORS, OR OTHER PROGRAM LIMITATIONS, OR THAT DEFECTS WILL BE CORRECTED. SOME JURISDICTIONS DO NOT ALLOW EXCLUSION OF IMPLIED WARRANTIES, SO THE ABOVE EXCLUSIONS MAY NOT APPLY TO YOU. THE ENTIRE RISK AS TO THE RESULTS, QUALITY AND PERFORMANCE OF THE SOFTWARE IS WITH YOU. NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED BY YOU FROM US OR OUR EMPLOYEES, REPRESENTATIVE OR AGENTS OR THROUGH OR FROM THE SOFTWARE OR OUR WEBSITE SHALL CREATE ANY WARRANTY NOT EXPRESSLY STATED WITHIN. THIS SECTION WILL SURVIVE THE TERMINATION OF THIS AGREEMENT. 9. Limitation of Liability TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL WE, OUR SUBSIDIARIES, OFFICERS, DIRECTORS, SHAREHOLDERS, PARTNERS, EMPLOYEES, AGENTS, CONTRACTORS OR OUR SUCCESSORS BE LIABLE FOR ANY DAMAGES WHATSOEVER, INCLUDING, BUT NOT LIMITED TO PERSONAL INJURY OR ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, PUNITIVE, COVER, CONSEQUENTIAL OR OTHER DAMAGES, INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, LOSS OF DATA, LOSS OF USE, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, BUSINESS INTERRUPTION, LOSS OF GOODWILL OR ANY OTHER COMMERCIAL DAMAGES OR LOSSES, ARISING OUT OF OR RELATED TO THE USE OF, OR INABILITY TO USE, THE SOFTWARE OR ANY RELATED SERVICES OR CONTENT, HOWEVER CAUSED, REGARDLESS OF THE THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, TORT (INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE. WITHOUT LIMITING THE FOREGOING, IN NO EVENT SHALL OUR TOTAL LIABILITY TO YOU FOR ACTUAL DAMAGES FOR ANY CAUSE WHATSOEVER EXCEED THE AMOUNT PAID BY YOU TO LICENSE THE SOFTWARE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THE FOREGOING LIMITATION OR EXCLUSION MAY NOT APPLY TO YOU. THESE LIMITATIONS WILL SURVIVE THE TERMINATION OF THIS AGREEMENT. 10. Indemnification You agree to fully indemnify and hold us, our successors, officers, directors, shareholders, partners, employees, agents, contracts and our successors harmless from and against any claim, suit, hearing, action, expense or demand, including without limitation to: all claims for damages, fees or costs (including attorneys’ fees), arising out of or related to the use of the Software and/or any related Services by you, your agents or representatives, anyone under your control, or by any third party using your equipment or accounts to use the Software or Services (for purposes of this section, collectively, “you”); the violation by you of any provision of this Agreement; the violation by you and any laws or regulations; or the infringement or misappropriation by you any copyright, trademark or any other intellectual property right, proprietary right, property right or any other right of ours or any third party. We reserve the right to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you will cooperate with us in asserting any available defenses and, as set forth above, be fully responsible for our attorneys’ fees. 11. Governing Law The license and this Agreement are governed by and construed in accordance with the laws of the State of Virginia, United States of America. You hereby consent to exclusive jurisdiction and venue in the County of Bedford and State of Virginia. By agreeing to the terms of this Agreement, you are waiving any claims that you might otherwise have against IPS based on the laws of other jurisdictions. 12. Severability If, for any reason, a court of competent jurisdiction deems any provision or part of this Agreement to be unlawful or unenforceable, the remainder of the Agreement shall remain in full force and effect. \ No newline at end of file +=============================[NOTE]============================= This software is Nulled! Nulled by IPBMafia.ru Buy license at https://www.invisionpower.com/buy/self-hosted ================================================================ IPS 4.3.0 Release (103005) =============================[NOTE]============================= Invision Community End User License Agreement 1. Acceptance This software license agreement (the “Agreement”) is between you (either an individual or entity, hereinafter referred to as “You” or “Your”) and Invision Power Services, Inc. (“IPS”, “We”, “Our” or “Us”) and pertains to the Invision Community software, its components, features, enhancements, updates and modifications (collectively the “Software” or “Suite”) and any related services (“Services”) provided by IPS under this Agreement. By purchasing, downloading, accessing, installing, facilitating the installation or using the Software or Services (or allowing or authorizing any other person to do so) you are warranting that you have the authority provided by your state, country or jurisdiction to enter into a legally binding contract and that you have read and agree to be bound by the terms of this Agreement. You understand and acknowledge that this Agreement comprises the entire agreement between You and IPS. This Agreement supersedes any prior agreements, promises, representations or descriptions. If you do not agree with the terms and conditions set forth hereinafter, you may not purchase, download, access, install or use the Software or Services. This Agreement may only be modified in writing, signed by an officer of IPS and You. 2. License Scope and Grant In consideration for payment of all applicable license fees and subject to the terms and conditions of this Agreement, IPS grants you a revocable, limited and non-exclusive license to install and use the Software and Services on a single installation, accessible via one URL. Access to services, components, software updates and technical support require an active license. All rights in and to the Software and Services are reserved to the use and benefit of IPS and/or its licensors, successors and assigners. (a) Test Installation. You may install and test one additional instance of the Software for the purpose of development and testing. This installation must be and remain isolated and inaccessible to the general public at all times. 3. Restrictions Your license to use the Software and Services is subject to the following terms, conditions and restrictions on use: (a) You may alter and modify the Software’s source code for Your use, subject to this Agreement, however, you may not distribute, publish, resell, or otherwise share the Software or derivative works based on the Software without prior express written consent from IPS. (b) You may not utilize the Software or Services to engage in, facilitate, or otherwise allow others to engage in any activity that violates any law or regulation or the terms and conditions within this Agreement. (c) You are solely responsible for complying with all governmental regulations and policies. You agree to indemnify Us from any loss, action or damage arising from Your failure to use the Software in a manner inconsistent with applicable legislation. (d) You may not remove any copyright or proprietary notices on or within the software’s source code at any time. A copyright removal license may be purchased to remove the public display of the Software’s publicly displayed copyright notice. 4. Intellectual Property We have the sole and exclusive right to the Software which is being licensed, not sold, to you by IPS under the terms and conditions of this agreement. The Software is protected by copyright, trademark and other intellectual property laws. IPS reserves any rights not expressly granted herein. 5. Assignment You may not rent, lease, sell, share or authorize or temporarily assign your rights to the license or this Agreement to another individual or entity except as expressly permitted herein. (a) You may, after six months from the original purchase date, permanently transfer your licensing rights and interest in this Agreement to a third party, provided the license is active and in good standing. Any transfer and reassignment must occur via the mechanisms provided within the invisioncommunity.com client area and all applicable fees must be paid for the reassignment to be considered valid. (b) You agree to provide this Agreement in its entirety to the assignee prior to reassignment and the assignee must agree to be bound to the terms of this Agreement. (c) You acknowledge that account and non license specific materials and purchases, including, but not limited to: account credits and third party (“marketplace”) add-ons and purchases are non-transferrable under any circumstances. (d) We reserve the right to refuse or reject reassignment at our sole discretion. 6. Termination This Agreement shall remain in effect until terminated. Your rights under this Agreement will automatically terminate without notice from Us in the event you fail to comply with any term or condition within this Agreement. Upon termination of this Agreement, you shall immediately cease all use of the Software and destroy all copies, full or partial, of the Software that may be in your possession or otherwise under your control. 7. Modification We reserve the right to amend or modify the terms of this Agreement at any time, and to change, discontinue or impose conditions on any aspect of the Software or related Service and to provide notification solely by posting an updated version of the Agreement on the invisioncommunity.com website. You acknowledge that you are solely responsible for regularly reviewing this Agreement and our policies. Continued use of the Software after modification to the Agreement constitutes your binding consent to such changes. 8. Disclaimer of Warranty THE SOFTWARE IS PROVIDED “AS-IS” AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE DISCLAIM ALL OTHER WARRANTIES, CONDITIONS, REPRESENTATIONS OR TERMS, EXPRESS OR IMPLIED, BY STATUTE, COMMON LAW, USAGE OR OTHERWISE, REGARDING THE SOFTWARE AND ANY RELATED SERVICES, INCLUDING THEIR FITNESS FOR A PARTICULAR PURPOSE, THEIR QUALITY, THEIR MERCHANTABILITY, OR THEIR NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SOFTWARE OR ANY RELATED SERVICES IS SECURE, OR IS FREE FROM BUGS, VIRUSES, ERRORS, OR OTHER PROGRAM LIMITATIONS, OR THAT DEFECTS WILL BE CORRECTED. SOME JURISDICTIONS DO NOT ALLOW EXCLUSION OF IMPLIED WARRANTIES, SO THE ABOVE EXCLUSIONS MAY NOT APPLY TO YOU. THE ENTIRE RISK AS TO THE RESULTS, QUALITY AND PERFORMANCE OF THE SOFTWARE IS WITH YOU. NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED BY YOU FROM US OR OUR EMPLOYEES, REPRESENTATIVE OR AGENTS OR THROUGH OR FROM THE SOFTWARE OR OUR WEBSITE SHALL CREATE ANY WARRANTY NOT EXPRESSLY STATED WITHIN. THIS SECTION WILL SURVIVE THE TERMINATION OF THIS AGREEMENT. 9. Limitation of Liability TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL WE, OUR SUBSIDIARIES, OFFICERS, DIRECTORS, SHAREHOLDERS, PARTNERS, EMPLOYEES, AGENTS, CONTRACTORS OR OUR SUCCESSORS BE LIABLE FOR ANY DAMAGES WHATSOEVER, INCLUDING, BUT NOT LIMITED TO PERSONAL INJURY OR ANY DIRECT, INDIRECT, SPECIAL, INCIDENTAL, EXEMPLARY, PUNITIVE, COVER, CONSEQUENTIAL OR OTHER DAMAGES, INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, LOSS OF DATA, LOSS OF USE, COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, BUSINESS INTERRUPTION, LOSS OF GOODWILL OR ANY OTHER COMMERCIAL DAMAGES OR LOSSES, ARISING OUT OF OR RELATED TO THE USE OF, OR INABILITY TO USE, THE SOFTWARE OR ANY RELATED SERVICES OR CONTENT, HOWEVER CAUSED, REGARDLESS OF THE THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, TORT (INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE. WITHOUT LIMITING THE FOREGOING, IN NO EVENT SHALL OUR TOTAL LIABILITY TO YOU FOR ACTUAL DAMAGES FOR ANY CAUSE WHATSOEVER EXCEED THE AMOUNT PAID BY YOU TO LICENSE THE SOFTWARE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THE FOREGOING LIMITATION OR EXCLUSION MAY NOT APPLY TO YOU. THESE LIMITATIONS WILL SURVIVE THE TERMINATION OF THIS AGREEMENT. 10. Indemnification You agree to fully indemnify and hold us, our successors, officers, directors, shareholders, partners, employees, agents, contracts and our successors harmless from and against any claim, suit, hearing, action, expense or demand, including without limitation to: all claims for damages, fees or costs (including attorneys’ fees), arising out of or related to the use of the Software and/or any related Services by you, your agents or representatives, anyone under your control, or by any third party using your equipment or accounts to use the Software or Services (for purposes of this section, collectively, “you”); the violation by you of any provision of this Agreement; the violation by you and any laws or regulations; or the infringement or misappropriation by you any copyright, trademark or any other intellectual property right, proprietary right, property right or any other right of ours or any third party. We reserve the right to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you will cooperate with us in asserting any available defenses and, as set forth above, be fully responsible for our attorneys’ fees. 11. Governing Law The license and this Agreement are governed by and construed in accordance with the laws of the State of Virginia, United States of America. You hereby consent to exclusive jurisdiction and venue in the County of Bedford and State of Virginia. By agreeing to the terms of this Agreement, you are waiving any claims that you might otherwise have against IPS based on the laws of other jurisdictions. 12. Severability If, for any reason, a court of competent jurisdiction deems any provision or part of this Agreement to be unlawful or unenforceable, the remainder of the Agreement shall remain in full force and effect. \ No newline at end of file diff --git a/admin/install/html/forms/template.phtml b/admin/install/html/forms/template.phtml index d5fd3652..70aa331f 100644 --- a/admin/install/html/forms/template.phtml +++ b/admin/install/html/forms/template.phtml @@ -12,7 +12,7 @@ {{endforeach}} {{if $uploadField}} - + {{endif}} {{if $error}}
{lang='sign_in_connect'}
-{lang="hc_files_fail"}
+{lang="hc_files_fail3"}
+{$exception->query}
+ {{if $exception->query}}{$exception->query}{{else}}{$trace[0]['args'][0]}{{endif}}
{{else}}
{$trace[1]['file']}::{$trace[1]['line']}{$exception->query}
+ {{if $exception->query}}{$exception->query}{{else}}{$trace[0]['args'][0]}{{endif}}
{{endif}}
{{else}}
diff --git a/admin/upgrade/index.php b/admin/upgrade/index.php
index 620ad094..ed5dd881 100644
--- a/admin/upgrade/index.php
+++ b/admin/upgrade/index.php
@@ -9,6 +9,7 @@
*/
define('READ_WRITE_SEPARATION', FALSE);
+define('REPORT_EXCEPTIONS', TRUE);
/* Prevent hooks from running during the upgrade */
define('RECOVERY_MODE', TRUE);
diff --git a/admin/upgrade/lang.php b/admin/upgrade/lang.php
index e06386d2..871b9914 100644
--- a/admin/upgrade/lang.php
+++ b/admin/upgrade/lang.php
@@ -37,6 +37,7 @@ $lang = array(
'create_conf_global' => "Please create a %s directory and make it writeable. If you are not sure how to do this, contact your hosting provider.",
'session_no_good' => "We were unable to start a PHP session. You will need to contact your host to adjust your PHP configuration before you can continue. The error reported was: %s",
'upgrade_group_not_exist' => "You do not have permission to run the upgrader because your group does not exist.",
+ 'help' => "Help",
'sign_in_short' => "Sign In",
'auth' => "Display Name or Email Address",
@@ -46,7 +47,7 @@ $lang = array(
'username' => "Display Name",
'email_address' => "Email Address",
'username_or_email' => "Username or Email Address",
- 'login_err_no_account' => "The %s you entered does not belong to any account. Make sure that it is typed correctly.",
+ 'login_err_no_account' => "The email address you entered does not belong to any account. Make sure that it is typed correctly.",
'login_err_bad_password' => "The password you entered is incorrect. Please try again (make sure your caps lock is off).",
'login_err_locked_unlock' => "Your account has been locked. Try again in {# [1:minute][?:minutes]}.",
'login_err_locked_nounlock' => "Your account has been locked. Try again later.",
@@ -106,6 +107,8 @@ $lang = array(
'requirements_mysql_utf8_info' => "%s is %s",
'requirements_file_system' => "File System",
'requirements_file_writable' => "%s is writable",
+ 'requirements_mysql_timeout' => "Your MySQL %s system variable is currently set to an extremely low value (%s). The default MySQL value is 28800. It is recommended to increase this MySQL system variable to at least 20 in order to prevent potential problems with queries timing out.",
+ 'dir_not_provided' => "No directory provided. Please check file storage configurations.",
'dir_does_not_exist' => "%s does not exist.",
'dir_is_not_writable' => "%s cannot be written to. Please adjust the permissions on it or contact your hosting provider for assistance.",
'file_storage_test_error_amazon' => "There appears to be a problem with your Amazon (%s) file storage settings which can cause problems with uploads.This is a comment.
") - * @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time - * @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request + * @reqapiparam string content The comment content as HTML (e.g. "This is a comment.
"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type. + * @apiparam datetime date The date/time that should be used for the comment date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member + * @apiparam string ip_address The IP address that should be stored for the comment. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member * @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator) * @throws 2B301/2 INVALID_ID The comment ID does not exist * @throws 1B301/3 NO_AUTHOR The author ID does not exist * @throws 1B301/4 NO_CONTENT No content was supplied + * @throws 2B301/8 NO_PERMISSION The authorized user does not have permission to comment on that blog entry * @return \IPS\blog\Entry\Comment */ public function POSTindex() { - /* Get topic */ + /* Get entry */ try { $entry = \IPS\blog\Entry::load( \IPS\Request::i()->entry ); @@ -108,18 +125,29 @@ class _comments extends \IPS\Content\Api\CommentController } /* Get author */ - if ( \IPS\Request::i()->author ) + if ( $this->member ) { - $author = \IPS\Member::load( \IPS\Request::i()->author ); - if ( !$author->member_id ) + if ( !$entry->canComment( $this->member ) ) { - throw new \IPS\Api\Exception( 'NO_AUTHOR', '1B301/3', 404 ); + throw new \IPS\Api\Exception( 'NO_PERMISSION', '2B301/8', 403 ); } + $author = $this->member; } else { - $author = new \IPS\Member; - $author->name = \IPS\Request::i()->author_name; + if ( \IPS\Request::i()->author ) + { + $author = \IPS\Member::load( \IPS\Request::i()->author ); + if ( !$author->member_id ) + { + throw new \IPS\Api\Exception( 'NO_AUTHOR', '1B301/3', 404 ); + } + } + else + { + $author = new \IPS\Member; + $author->name = \IPS\Request::i()->author_name; + } } /* Check we have a post */ @@ -136,13 +164,15 @@ class _comments extends \IPS\Content\Api\CommentController * POST /blog/comments/{id} * Edit a comment * + * @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, hidden will only be honoured if the authentictaed user has permission to hide content). * @param int $id ID Number - * @apiparam int author The ID number of the member making the comment (0 for guest) + * @apiparam int author The ID number of the member making the comment (0 for guest). Ignored for requests using an OAuth Access Token for a particular member. * @apiparam string author_name If author is 0, the guest name that should be used - * @apiparam string content The comment content as HTML (e.g. "This is a comment.
") + * @apiparam string content The comment content as HTML (e.g. "This is a comment.
"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type. * @apiparam int hidden 1/0 indicating if the topic should be hidden - * @throws 2B301/5 INVALID_ID The comment ID does not exist + * @throws 2B301/5 INVALID_ID The comment ID does not exist or the authorized user does not have permission to view it * @throws 1B301/6 NO_AUTHOR The author ID does not exist + * @throws 2B301/9 NO_PERMISSION The authorized user does not have permission to edit the comment * @return \IPS\blog\Entry\Comment */ public function POSTitem( $id ) @@ -151,6 +181,14 @@ class _comments extends \IPS\Content\Api\CommentController { /* Load */ $comment = \IPS\blog\Entry\Comment::load( $id ); + if ( $this->member and !$comment->canView( $this->member ) ) + { + throw new \OutOfRangeException; + } + if ( $this->member and !$comment->canEdit( $this->member ) ) + { + throw new \IPS\Api\Exception( 'NO_PERMISSION', '2B301/9', 403 ); + } /* Do it */ try @@ -173,14 +211,21 @@ class _comments extends \IPS\Content\Api\CommentController * Deletes a comment * * @param int $id ID Number - * @throws 2B301/7 INVALID_ID The comment ID does not exist + * @throws 2B301/7 INVALID_ID The comment ID does not exist + * @throws 2B301/A NO_PERMISSION The authorized user does not have permission to delete the comment * @return void */ public function DELETEitem( $id ) { try { - \IPS\blog\Entry\Comment::load( $id )->delete(); + $class = $this->class; + $object = $class::load( $id ); + if ( $this->member and !$object->canDelete( $this->member ) ) + { + throw new \IPS\Api\Exception( 'NO_PERMISSION', '2B301/A', 403 ); + } + $object->delete(); return new \IPS\Api\Response( 200, NULL ); } diff --git a/applications/blog/api/entries.php b/applications/blog/api/entries.php index 9df60dba..1339b30d 100644 --- a/applications/blog/api/entries.php +++ b/applications/blog/api/entries.php @@ -32,6 +32,7 @@ class _entries extends \IPS\Content\Api\ItemController * GET /blog/entries * Get list of entries * + * @note For requests using an OAuth Access Token for a particular member, only entries that are published and in blogs that are not disabled and not belonging to a particular club or social group will be included * @apiparam string blogs Comma-delimited list of blog IDs * @apiparam string authors Comma-delimited list of member IDs - if provided, only entries started by those members are returned * @apiparam int locked If 1, only entries which are locked are returned, if 0 only unlocked @@ -42,6 +43,7 @@ class _entries extends \IPS\Content\Api\ItemController * @apiparam string sortBy What to sort by. Can be 'date' for creation date, 'title' or leave unspecified for ID * @apiparam string sortDir Sort direction. Can be 'asc' or 'desc' - defaults to 'asc' * @apiparam int page Page number + * @apiparam int perPage Number of results per page - defaults to 25 * @return \IPS\Api\PaginatedResponseThis is a blog entry.
") + * @reqapiparam string entry The entry content as HTML (e.g. "This is a blog entry.
"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type. * @apiparam bool draft If this is a draft * @apiparam string prefix Prefix tag * @apiparam string tags Comma-separated list of tags (do not include prefix) - * @apiparam datetime date The date/time that should be used for the entry date. If not provided, will use the current date/time - * @apiparam string ip_address The IP address that should be stored for the entry/post. If not provided, will use the IP address from the API request + * @apiparam datetime date The date/time that should be used for the entry date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member + * @apiparam string ip_address The IP address that should be stored for the entry/post. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member * @apiparam int locked 1/0 indicating if the entry should be locked * @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator) * @apiparam int pinned 1/0 indicating if the entry should be pinned @@ -121,6 +129,7 @@ class _entries extends \IPS\Content\Api\ItemController * @throws 1B300/3 NO_AUTHOR The author ID does not exist * @throws 1B300/4 NO_TITLE No title was supplied * @throws 1B300/5 NO_CONTENT No content was supplied + * @throws 1B300/A NO_PERMISSION The authorized user does not have permission to create an entry in that blog * @return \IPS\blog\Entry */ public function POSTindex() @@ -136,17 +145,28 @@ class _entries extends \IPS\Content\Api\ItemController } /* Get author */ - if ( \IPS\Request::i()->author ) + if ( $this->member ) { - $author = \IPS\Member::load( \IPS\Request::i()->author ); - if ( !$author->member_id ) + if ( !$blog->can( 'add', $this->member ) ) { - throw new \IPS\Api\Exception( 'NO_AUTHOR', '1B300/3', 400 ); + throw new \IPS\Api\Exception( 'NO_PERMISSION', '1B300/A', 403 ); } + $author = $this->member; } else { - $author = new \IPS\Member; + if ( \IPS\Request::i()->author ) + { + $author = \IPS\Member::load( \IPS\Request::i()->author ); + if ( !$author->member_id ) + { + throw new \IPS\Api\Exception( 'NO_AUTHOR', '1B300/3', 400 ); + } + } + else + { + $author = new \IPS\Member; + } } /* Check we have a title and a description */ @@ -160,29 +180,31 @@ class _entries extends \IPS\Content\Api\ItemController } /* Do it */ - return new \IPS\Api\Response( 201, $this->_create( $blog, $author )->apiOutput() ); + return new \IPS\Api\Response( 201, $this->_create( $blog, $author )->apiOutput( $this->member ) ); } /** * POST /blog/entries/{id} * Edit a blog entry * + * @note For requests using an OAuth Access Token for a particular member, any parameters the user doesn't have permission to use are ignored (for example, locked will only be honoured if the authentictaed user has permission to lock topics). * @reqapiparam int blog The ID number of the blog the entry should be created in - * @reqapiparam int author The ID number of the member creating the entry (0 for guest) + * @reqapiparam int author The ID number of the member creating the entry (0 for guest). Ignored for requests using an OAuth Access Token for a particular member. * @reqapiparam string title The entry title - * @reqapiparam string entry The entry content as HTML (e.g. "This is a blog entry.
") + * @reqapiparam string entry The entry content as HTML (e.g. "This is a blog entry.
"). Will be sanatized for requests using an OAuth Access Token for a particular member; will be saved unaltered for requests made using an API Key or the Client Credentials Grant Type. * @apiparam bool draft If this is a draft * @apiparam string prefix Prefix tag * @apiparam string tags Comma-separated list of tags (do not include prefix) - * @apiparam datetime date The date/time that should be used for the entry date. If not provided, will use the current date/time - * @apiparam string ip_address The IP address that should be stored for the entry/post. If not provided, will use the IP address from the API request + * @apiparam datetime date The date/time that should be used for the entry date. If not provided, will use the current date/time. Ignored for requests using an OAuth Access Token for a particular member. + * @apiparam string ip_address The IP address that should be stored for the entry/post. If not provided, will use the IP address from the API request. Ignored for requests using an OAuth Access Token for a particular member. * @apiparam int locked 1/0 indicating if the entry should be locked * @apiparam int hidden 0 = unhidden; 1 = hidden, pending moderator approval; -1 = hidden (as if hidden by a moderator) * @apiparam int pinned 1/0 indicating if the entry should be pinned * @apiparam int featured 1/0 indicating if the entry should be featured - * @throws 2B300/6 INVALID_ID The entry ID is invalid - * @throws 1B300/7 NO_BLOG The blog ID does not exist + * @throws 2B300/6 INVALID_ID The entry ID is invalid or the authorized user does not have permission to view it + * @throws 1B300/7 NO_BLOG The blog ID does not exist or the authorized user does not have permission to post in it * @throws 1B300/8 NO_AUTHOR The author ID does not exist + * @throws 1B300/B NO_PERMISSION The authorized user does not have permission to edit that blog entry * @return \IPS\blog\Entry */ public function POSTitem( $id ) @@ -190,13 +212,26 @@ class _entries extends \IPS\Content\Api\ItemController try { $entry = \IPS\blog\Entry::load( $id ); + if ( $this->member and !$entry->can( 'read', $this->member ) ) + { + throw new \OutOfRangeException; + } + if ( $this->member and !$entry->canEdit( $this->member ) ) + { + throw new \IPS\Api\Exception( 'NO_PERMISSION', '1B300/B', 403 ); + } /* New blog */ - if ( isset( \IPS\Request::i()->blog ) and \IPS\Request::i()->blog != $entry->forum_id ) + if ( isset( \IPS\Request::i()->blog ) and \IPS\Request::i()->blog != $entry->blog_id and ( !$this->member or $entry->canMove( $this->member ) ) ) { try { $newBlog = \IPS\blog\Blog::load( \IPS\Request::i()->blog ); + if ( $this->member and !$newBlog->can( 'add', $this->member ) ) + { + throw new \OutOfRangeException; + } + $entry->move( $newBlog ); } catch ( \OutOfRangeException $e ) @@ -206,7 +241,7 @@ class _entries extends \IPS\Content\Api\ItemController } /* New author */ - if ( isset( \IPS\Request::i()->author ) ) + if ( !$this->member and isset( \IPS\Request::i()->author ) ) { try { @@ -225,11 +260,11 @@ class _entries extends \IPS\Content\Api\ItemController } /* Everything else */ - $this->_createOrUpdate( $entry ); + $this->_createOrUpdate( $entry, 'edit' ); /* Save and return */ $entry->save(); - return new \IPS\Api\Response( 200, $entry->apiOutput() ); + return new \IPS\Api\Response( 200, $entry->apiOutput( $this->member ) ); } catch ( \OutOfRangeException $e ) { @@ -241,9 +276,10 @@ class _entries extends \IPS\Content\Api\ItemController * Create or update entry * * @param \IPS\Content\Item $item The item + * @param string $type add or edit * @return \IPS\Content\Item */ - protected function _createOrUpdate( \IPS\Content\Item $item ) + protected function _createOrUpdate( \IPS\Content\Item $item, $type='add' ) { /* Is draft */ if ( isset( \IPS\Request::i()->draft ) ) @@ -254,11 +290,16 @@ class _entries extends \IPS\Content\Api\ItemController /* Content */ if ( isset( \IPS\Request::i()->entry ) ) { - $item->content = \IPS\Request::i()->entry; + $entryContents = \IPS\Request::i()->entry; + if ( $this->member ) + { + $entryContents = \IPS\Text\Parser::parseStatic( $entryContents, TRUE, NULL, $this->member, 'blog_Entries' ); + } + $item->content = $entryContents; } /* Pass up */ - return parent::_createOrUpdate( $item ); + return parent::_createOrUpdate( $item, $type ); } /** @@ -266,14 +307,21 @@ class _entries extends \IPS\Content\Api\ItemController * Delete an entry * * @param int $id ID Number - * @throws 2B300/9 INVALID_ID The entry ID does not exist + * @throws 2B300/9 INVALID_ID The entry ID does not exist + * @throws 2B300/C NO_PERMISSION The authorized user does not have permission to delete the entry * @return void */ public function DELETEitem( $id ) { try { - \IPS\blog\Entry::load( $id )->delete(); + $item = \IPS\blog\Entry::load( $id ); + if ( $this->member and !$item->canDelete( $this->member ) ) + { + throw new \IPS\Api\Exception( 'NO_PERMISSION', '2B300/C', 404 ); + } + + $item->delete(); return new \IPS\Api\Response( 200, NULL ); } diff --git a/applications/blog/data/emails.xml b/applications/blog/data/emails.xml index cd2e6b5e..e5e51e70 100644 --- a/applications/blog/data/emails.xml +++ b/applications/blog/data/emails.xml @@ -26,7 +26,7 @@ ]]>{lang="byline_nodate" htmlsprintf="$entry->author()->link()"} {datetime="$entry->mapped('date')"}
-{lang="byline_nodate" htmlsprintf="$entry->author()->link()"} {datetime="$entry->mapped('date')"}
+{lang="no_entries_yet"}
++ {datetime="$entry->date"} +
+{{if $entry->container()->owner() instanceof \IPS\Member}} {lang="blog_by" htmlsprintf="$entry->container()->owner()->link()"} - {{elseif !$entry->container()->club()}} + {{elseif $club = $blog->club()}} + {lang="club_blog_for" sprintf="$club->name"} + {{else}} {lang="group_blog_by" sprintf="\IPS\Member::loggedIn()->language()->addToStack( 'blogs_groupblog_name_' . $entry->container()->id )"} {{endif}}
@@ -324,7 +470,7 @@ ]]> - {template="embedHeader" group="embed" app="core" params="$entry, \IPS\Member::loggedIn()->language()->addToStack( 'x_created_entry_in', FALSE, array( 'sprintf' => array( $entry->author()->name, $entry->container()->_title ) ) ), $entry->mapped('date')"} + {template="embedHeader" group="embed" app="core" params="$entry, \IPS\Member::loggedIn()->language()->addToStack( 'x_created_entry_in', FALSE, array( 'sprintf' => array( $entry->author()->name, $entry->container()->_title ) ) ), $entry->mapped('date'), $url"} {{if $blog->coverPhoto() && $blog->coverPhoto()->file}} {{$photo = $blog->coverPhoto()->file;}}