Version 4.3.0
This commit is contained in:
1 parent
96997ddd8e
commit
fe1acf984a
1349 files changed
+116159
-67711
No files matched your search
@@ -55,6 +55,9 @@ class _Admin extends \IPS\Dispatcher\Standard
|
||||
public function init()
|
||||
{
|
||||
\IPS\Output::i()->sidebar['appmenu'] = '';
|
||||
|
||||
/* Disable sending of referrer to third party sites from AdminCP */
|
||||
\IPS\Output::i()->sendHeader( "Referrer-Policy: origin-when-cross-origin" );
|
||||
|
||||
/* Sync stuff when in developer mode */
|
||||
if ( \IPS\IN_DEV )
|
||||
@@ -124,7 +127,7 @@ class _Admin extends \IPS\Dispatcher\Standard
|
||||
{
|
||||
/* Make sure the right protocol is used. IIS, for example, does not like protocol relative URL's in redirects. (Ref: 970629) */
|
||||
$protocol = \IPS\Http\Url::PROTOCOL_HTTP;
|
||||
if ( \IPS\Settings::i()->logins_over_https OR \substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' )
|
||||
if ( \substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' )
|
||||
{
|
||||
$protocol = \IPS\Http\Url::PROTOCOL_HTTPS;
|
||||
}
|
||||
@@ -170,7 +173,20 @@ class _Admin extends \IPS\Dispatcher\Standard
|
||||
}
|
||||
|
||||
/* Permission Check */
|
||||
if ( ( $this->module->key !== 'system' or !in_array( $this->controller, array( 'login', 'language', 'theme', 'livesearch', 'editor', 'ajax' ) ) ) and ( $this->module->key !== 'members' or $this->controller !== 'members' or !in_array( \IPS\Request::i()->do, array( 'adminDetails', 'adminEmail', 'adminPassword' ) ) ) and !\IPS\Member::loggedIn()->hasAcpRestriction( $this->application, $this->module ) )
|
||||
if (
|
||||
(
|
||||
$this->module->key !== 'system' or
|
||||
!in_array( $this->controller, array( 'login', 'language', 'theme', 'livesearch', 'editor', 'ajax' ) )
|
||||
) and
|
||||
(
|
||||
$this->module->key !== 'members' or
|
||||
$this->controller !== 'members' or
|
||||
!in_array( \IPS\Request::i()->do, array( 'adminDetails', 'adminEmail', 'adminPassword' ) )
|
||||
) and
|
||||
/* This is slightly hacky, but the upgrader was moved to the system module, however the ACP restriction is still set to overview.
|
||||
To avoid unintentionally removing restrictions via an upgrade by moving the restriction, we reference the overview module for the restriction check instead */
|
||||
!\IPS\Member::loggedIn()->hasAcpRestriction( $this->application, ( $this->application->directory === 'core' and $this->module->key === 'system' and $this->controller === 'upgrade' ) ? \IPS\Application\Module::get( 'core', 'overview', 'admin' ) : $this->module )
|
||||
)
|
||||
{
|
||||
\IPS\Output::i()->error( 'no_module_permission', '2S107/1', 403, '' );
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user