Version 4.3.0

This commit is contained in:
Neo committed 2025-12-19 05:47:12 -08:00
1 parent 96997ddd8e
commit fe1acf984a
1349 files changed
+116159 -67711

No files matched your search

+18 -2
View File
@@ -55,6 +55,9 @@ class _Admin extends \IPS\Dispatcher\Standard
public function init()
{
\IPS\Output::i()->sidebar['appmenu'] = '';
/* Disable sending of referrer to third party sites from AdminCP */
\IPS\Output::i()->sendHeader( "Referrer-Policy: origin-when-cross-origin" );
/* Sync stuff when in developer mode */
if ( \IPS\IN_DEV )
@@ -124,7 +127,7 @@ class _Admin extends \IPS\Dispatcher\Standard
{
/* Make sure the right protocol is used. IIS, for example, does not like protocol relative URL's in redirects. (Ref: 970629) */
$protocol = \IPS\Http\Url::PROTOCOL_HTTP;
if ( \IPS\Settings::i()->logins_over_https OR \substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' )
if ( \substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' )
{
$protocol = \IPS\Http\Url::PROTOCOL_HTTPS;
}
@@ -170,7 +173,20 @@ class _Admin extends \IPS\Dispatcher\Standard
}
/* Permission Check */
if ( ( $this->module->key !== 'system' or !in_array( $this->controller, array( 'login', 'language', 'theme', 'livesearch', 'editor', 'ajax' ) ) ) and ( $this->module->key !== 'members' or $this->controller !== 'members' or !in_array( \IPS\Request::i()->do, array( 'adminDetails', 'adminEmail', 'adminPassword' ) ) ) and !\IPS\Member::loggedIn()->hasAcpRestriction( $this->application, $this->module ) )
if (
(
$this->module->key !== 'system' or
!in_array( $this->controller, array( 'login', 'language', 'theme', 'livesearch', 'editor', 'ajax' ) )
) and
(
$this->module->key !== 'members' or
$this->controller !== 'members' or
!in_array( \IPS\Request::i()->do, array( 'adminDetails', 'adminEmail', 'adminPassword' ) )
) and
/* This is slightly hacky, but the upgrader was moved to the system module, however the ACP restriction is still set to overview.
To avoid unintentionally removing restrictions via an upgrade by moving the restriction, we reference the overview module for the restriction check instead */
!\IPS\Member::loggedIn()->hasAcpRestriction( $this->application, ( $this->application->directory === 'core' and $this->module->key === 'system' and $this->controller === 'upgrade' ) ? \IPS\Application\Module::get( 'core', 'overview', 'admin' ) : $this->module )
)
{
\IPS\Output::i()->error( 'no_module_permission', '2S107/1', 403, '' );
}