Version 4.3.0
This commit is contained in:
1 parent
96997ddd8e
commit
fe1acf984a
1349 files changed
+116159
-67711
No files matched your search
@@ -34,24 +34,47 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal('') );
|
||||
}
|
||||
|
||||
/* Force HTTPs? */
|
||||
if ( mb_strtolower( $_SERVER['REQUEST_METHOD'] ) == 'get' and \IPS\Settings::i()->logins_over_https and \IPS\Request::i()->url()->data['scheme'] !== 'https' )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login', NULL, \IPS\Settings::i()->logins_over_https ) );
|
||||
}
|
||||
|
||||
/* Init login class */
|
||||
$login = new \IPS\Login( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login', NULL, \IPS\Settings::i()->logins_over_https ) );
|
||||
|
||||
/* Init login class */
|
||||
$login = new \IPS\Login( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' ) );
|
||||
|
||||
/* What's our referrer? */
|
||||
$ref = \IPS\Request::i()->ref;
|
||||
|
||||
/* Process */
|
||||
$error = isset( \IPS\Request::i()->_err ) && \IPS\Member::loggedIn()->language()->checkKeyExists( \IPS\Request::i()->_err ) ? \IPS\Request::i()->_err : NULL;
|
||||
$error = NULL;
|
||||
try
|
||||
{
|
||||
$member = $login->authenticate();
|
||||
if ( $member !== NULL )
|
||||
if ( $success = $login->authenticate() )
|
||||
{
|
||||
$this->_doLogin( $member, $login->flags['signin_anonymous'], $login->flags['remember_me'], \IPS\Login::getDestination(), FALSE, $login->usedHandler );
|
||||
if ( $ref and $ref = @base64_decode( $ref ) )
|
||||
{
|
||||
try
|
||||
{
|
||||
$ref = \IPS\Http\Url::createFromString( $ref );
|
||||
if ( !( $ref instanceof \IPS\Http\Url\Internal ) or $ref->base !== 'front' )
|
||||
{
|
||||
throw new \Exception;
|
||||
}
|
||||
}
|
||||
catch ( \Exception $e )
|
||||
{
|
||||
$ref = \IPS\Http\Url::internal('');
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$ref = \IPS\Http\Url::internal('');
|
||||
}
|
||||
|
||||
if ( $success->mfa() )
|
||||
{
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $success->member->member_id, 'anonymous' => $success->anonymous, 'remember' => $success->rememberMe, 'destination' => (string) $ref, 'handler' => $success->handler->id );
|
||||
\IPS\Output::i()->redirect( $ref->setQueryString( '_mfaLogin', 1 ) );
|
||||
}
|
||||
$success->process();
|
||||
|
||||
\IPS\Output::i()->redirect( $ref->setQueryString( '_fromLogin', 1 ) );
|
||||
}
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
@@ -59,91 +82,33 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
if ( $e->getCode() === \IPS\Login\Exception::MERGE_SOCIAL_ACCOUNT )
|
||||
{
|
||||
$e->member = $e->member->member_id;
|
||||
$e->handler = $e->handler->id;
|
||||
$_SESSION['linkAccounts'] = json_encode( $e );
|
||||
|
||||
$linkUrl = \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=link', 'front', 'login' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
{
|
||||
$linkUrl = $linkUrl->setQueryString( 'ref', \IPS\Request::i()->ref );
|
||||
}
|
||||
\IPS\Output::i()->redirect( $linkUrl );
|
||||
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=link', 'front', 'login' )->setQueryString( 'ref', $ref ), '', 303 );
|
||||
}
|
||||
|
||||
$error = $e->getMessage();
|
||||
}
|
||||
|
||||
if ( \IPS\Request::i()->isAjax() && $error )
|
||||
{
|
||||
\IPS\Output::i()->json( array( 'status' => 'error', 'error' => $error ), 401 );
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Display Login Form */
|
||||
\IPS\Output::i()->allowDefaultWidgets = FALSE;
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('login');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->login( $login->forms(), $error );
|
||||
}
|
||||
/* Display Login Form */
|
||||
\IPS\Output::i()->allowDefaultWidgets = FALSE;
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('login');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->login( $login, $ref, $error );
|
||||
|
||||
/* Set Session Location */
|
||||
\IPS\Session::i()->setLocation( \IPS\Http\Url::internal( 'app=core&module=system&controller=login', NULL, 'login' ), array(), 'loc_logging_in' );
|
||||
}
|
||||
|
||||
/**
|
||||
* Process the login
|
||||
*
|
||||
* @param \IPS\Member $member The member
|
||||
* @param bool $anonymous If the login is anonymous
|
||||
* @param bool $rememberMe If the "remember me" checkbox was checked
|
||||
* @param \IPS\Http\Url $destination Where to redirect to
|
||||
* @param bool $bypass2FA If true, will not perform 2FA check
|
||||
* @param string $loginHandler Which login handler processed the login
|
||||
* @return void
|
||||
*/
|
||||
protected function _doLogin( $member, $anonymous=FALSE, $rememberMe=TRUE, $destination=NULL, $bypass2FA=FALSE, $loginHandler=NULL )
|
||||
{
|
||||
/* Get destination */
|
||||
if ( !$destination )
|
||||
{
|
||||
$destination = \IPS\Http\Url::internal( '' );
|
||||
}
|
||||
|
||||
/* Is this a known device? */
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member );
|
||||
|
||||
/* Do we need to do 2FA? */
|
||||
if ( !$bypass2FA and $output = \IPS\MFA\MFAHandler::accessToArea( 'core', $device->known ? 'AuthenticateFrontKnown' : 'AuthenticateFront', \IPS\Http\Url::internal( '' ), $member ) )
|
||||
{
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $member->member_id, 'anonymous' => $anonymous, 'remember' => $rememberMe, 'destination' => (string) $destination, 'handler' => $loginHandler );
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_mfaLogin', 1 ) );
|
||||
}
|
||||
|
||||
/* Log in */
|
||||
\IPS\Session::i()->setMember( $member );
|
||||
if ( $anonymous and !\IPS\Settings::i()->disable_anonymous )
|
||||
{
|
||||
\IPS\Session::i()->setAnon();
|
||||
}
|
||||
|
||||
/* Log device */
|
||||
$device->anonymous = $anonymous and !\IPS\Settings::i()->disable_anonymous;
|
||||
$device->updateAfterAuthentication( $rememberMe, $loginHandler );
|
||||
|
||||
/* Member sync */
|
||||
$member->memberSync( 'onLogin', array( \IPS\Login::getDestination() ) );
|
||||
|
||||
/* Redirect */
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_fromLogin', 1 ), '', 303 );
|
||||
}
|
||||
|
||||
/**
|
||||
* MFA
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
protected function mfa()
|
||||
{
|
||||
{
|
||||
/* Have we logged in? */
|
||||
$member = NULL;
|
||||
if ( isset( $_SESSION['processing2FA'] ) )
|
||||
@@ -156,7 +121,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
|
||||
/* Where do we want to go? */
|
||||
$destination = NULL;
|
||||
$destination = \IPS\Http\Url::internal( '' );
|
||||
try
|
||||
{
|
||||
$destination = \IPS\Http\Url::createFromString( $_SESSION['processing2FA']['destination'] );
|
||||
@@ -167,8 +132,9 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
$device = \IPS\Member\Device::loadOrCreate( $member );
|
||||
$output = \IPS\MFA\MFAHandler::accessToArea( 'core', $device->known ? 'AuthenticateFrontKnown' : 'AuthenticateFront', \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=mfa', 'front', 'login' ), $member );
|
||||
if ( !$output )
|
||||
{
|
||||
$this->_doLogin( $member, $_SESSION['processing2FA']['anonymous'], $_SESSION['processing2FA']['remember'], $destination, TRUE, $_SESSION['processing2FA']['handler'] );
|
||||
{
|
||||
( new \IPS\Login\Success( $member, \IPS\Login\Handler::load( $_SESSION['processing2FA']['handler'] ), $_SESSION['processing2FA']['remember'], $_SESSION['processing2FA']['anonymous'] ) )->process();
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_fromLogin', 1 ), '', 303 );
|
||||
}
|
||||
|
||||
/* Nope, just send us where we want to go not logged in */
|
||||
@@ -199,35 +165,36 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
*/
|
||||
protected function link()
|
||||
{
|
||||
/* Get the member we're linking with */
|
||||
if ( !isset( $_SESSION['linkAccounts'] ) )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=login', 'front', 'login' ) );
|
||||
}
|
||||
$details = json_decode( $_SESSION['linkAccounts'], TRUE );
|
||||
|
||||
$member = \IPS\Member::load( $details['member'] );
|
||||
if ( !$member->member_id )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( 'app=core&module=system&controller=login', 'front', 'login' ) );
|
||||
}
|
||||
|
||||
$form = new \IPS\Helpers\Form( 'link_accounts', 'login' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
/* And then handler to link with */
|
||||
$handler = \IPS\Login\Handler::load( $details['handler'] );
|
||||
|
||||
/* Init reauthentication */
|
||||
$login = new \IPS\Login( \IPS\Http\Url::internal( 'app=core&module=system&controller=login&do=link', 'front', 'login' )->setQueryString( 'ref', isset( \IPS\Request::i()->ref ) ? \IPS\Request::i()->ref : NULL ), \IPS\Login::LOGIN_REAUTHENTICATE );
|
||||
$login->reauthenticateAs = $member;
|
||||
$error = NULL;
|
||||
|
||||
/* If successful (or if there's no way to reauthenticate which would only happen if a login handler has been deleted)) complete the link... */
|
||||
try
|
||||
{
|
||||
$form->hiddenValues['ref'] = \IPS\Request::i()->ref;
|
||||
}
|
||||
$form->addDummy( 'email_address', htmlspecialchars( isset( $details['email'] ) ? $details['email'] : $member->email, \IPS\HTMLENTITIES, 'UTF-8', FALSE ) );
|
||||
$form->add( new \IPS\Helpers\Form\Password( 'password', NULL, TRUE, array( 'validateFor' => $member ) ) );
|
||||
if ( $values = $form->values() )
|
||||
{
|
||||
try
|
||||
{
|
||||
$class = 'IPS\Login\\' . ucfirst( $details['handler'] );
|
||||
$class::link( $member, $details['details'] );
|
||||
if ( $success = $login->authenticate() or ( !count( $login->usernamePasswordMethods() ) and !count( $login->buttonMethods() ) ) )
|
||||
{
|
||||
$handler->completeLink( $member, $details['details'] );
|
||||
|
||||
unset( $_SESSION['linkAccounts'] );
|
||||
|
||||
$destination = NULL;
|
||||
$destination = \IPS\Http\Url::internal( '' );
|
||||
if ( isset( \IPS\Request::i()->ref ) )
|
||||
{
|
||||
try
|
||||
@@ -240,18 +207,27 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
}
|
||||
catch ( \Exception $e ) { }
|
||||
}
|
||||
$this->_doLogin( $member, FALSE, TRUE, $destination, FALSE, $details['handler'] );
|
||||
|
||||
$success = new \IPS\Login\Success( $member, $handler );
|
||||
if ( $success->mfa() )
|
||||
{
|
||||
$_SESSION['processing2FA'] = array( 'memberId' => $success->member->member_id, 'anonymous' => $success->anonymous, 'remember' => $success->rememberMe, 'destination' => (string) $destination, 'handler' => $success->handler->id );
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_mfaLogin', 1 ) );
|
||||
}
|
||||
$success->process();
|
||||
\IPS\Output::i()->redirect( $destination->setQueryString( '_fromLogin', 1 ) );
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
{
|
||||
$form->error = $e->getMessage();
|
||||
}
|
||||
}
|
||||
catch ( \IPS\Login\Exception $e )
|
||||
{
|
||||
$error = $e->getMessage();
|
||||
}
|
||||
|
||||
/* Otherwise show the reauthenticate form */
|
||||
\IPS\Output::i()->bodyClasses[] = 'ipsLayout_minimal';
|
||||
\IPS\Output::i()->sidebar['enabled'] = FALSE;
|
||||
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('login');
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->mergeSocialAccount( $details['handler'], $member, $form );
|
||||
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate( 'system' )->mergeSocialAccount( $handler, $member, $login, $error );
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -309,16 +285,6 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
setcookie( session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"] );
|
||||
session_destroy();
|
||||
|
||||
/* Login handler callback */
|
||||
foreach ( \IPS\Login::handlers( TRUE ) as $k => $handler )
|
||||
{
|
||||
try
|
||||
{
|
||||
$handler->logoutAccount( $member, $redirectUrl );
|
||||
}
|
||||
catch( \BadMethodCallException $e ) {}
|
||||
}
|
||||
|
||||
/* Member sync callback */
|
||||
$member->memberSync( 'onLogout', array( $redirectUrl ) );
|
||||
|
||||
@@ -345,7 +311,7 @@ class _login extends \IPS\Dispatcher\Controller
|
||||
/* Not logged in as admin? */
|
||||
if ( $admin->member_id != \IPS\Member::loggedIn()->member_id )
|
||||
{
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login', NULL, \IPS\Settings::i()->logins_over_https )->setQueryString( array( 'ref' => base64_encode( \IPS\Request::i()->url() ), '_err' => 'login_as_user_login' ) ) );
|
||||
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=system&controller=login", 'front', 'login' )->setQueryString( array( 'ref' => base64_encode( \IPS\Request::i()->url() ), '_err' => 'login_as_user_login' ) ) );
|
||||
}
|
||||
|
||||
/* Do it */
|
||||
|
||||
Reference in new issue
Block a user