Version 4.3.0
This commit is contained in:
1 parent
96997ddd8e
commit
fe1acf984a
1349 files changed
+116159
-67711
No files matched your search
+61
-60
@@ -74,41 +74,12 @@ class _Front extends \IPS\Session
|
||||
*/
|
||||
public function read( $sessionId )
|
||||
{
|
||||
$session = NULL;
|
||||
$this->sessionId = $sessionId;
|
||||
|
||||
/* Get user agent info */
|
||||
$this->userAgent = \IPS\Http\Useragent::parse();
|
||||
|
||||
/* Get from the database */
|
||||
try
|
||||
{
|
||||
/* If it looks like we're logged in, join the member row to save a query later */
|
||||
if ( static::loggedIn() )
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ), NULL, NULL, NULL, NULL, \IPS\Db::SELECT_MULTIDIMENSIONAL_JOINS )->join( 'core_members', 'core_members.member_id=core_sessions.member_id' )->first();
|
||||
if ( $session['core_members']['member_id'] )
|
||||
{
|
||||
\IPS\Member::constructFromData( $session['core_members'], FALSE );
|
||||
}
|
||||
$session = $session['core_sessions'];
|
||||
}
|
||||
/* If we're not logged in, just look at the session */
|
||||
else
|
||||
{
|
||||
/* Spiders match by IP and useragent */
|
||||
if ( $this->userAgent->spider )
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=? OR ( ip_address=? AND browser=? )', $sessionId, \IPS\Request::i()->ipAddress(), $_SERVER['HTTP_USER_AGENT'] ) )->first();
|
||||
$sessionId = $session['id'];
|
||||
}
|
||||
/* Normal users don't */
|
||||
else
|
||||
{
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sessions', array( 'id=?', $sessionId ) )->first();
|
||||
}
|
||||
}
|
||||
}
|
||||
catch ( \UnderflowException $e ) { }
|
||||
$session = \IPS\Session\Store::i()->loadSession( $this->sessionId );
|
||||
|
||||
/* Only use sessions with matching IP address */
|
||||
if( \IPS\Settings::i()->match_ipaddress and $session['ip_address'] != \IPS\Request::i()->ipAddress() )
|
||||
@@ -150,7 +121,7 @@ class _Front extends \IPS\Session
|
||||
{
|
||||
/* Get the member we're trying to authenticate against - do not process cookie-based login if the account is locked */
|
||||
$member = \IPS\Member::load( (int) \IPS\Request::i()->cookie['member_id'] );
|
||||
if ( $member->member_id and \IPS\Login::accountUnlockTime( $member ) === FALSE )
|
||||
if ( $member->member_id and $member->unlockTime() === FALSE )
|
||||
{
|
||||
/* Load and authenticate device device data */
|
||||
try
|
||||
@@ -212,7 +183,7 @@ class _Front extends \IPS\Session
|
||||
|
||||
/* Set data */
|
||||
$this->data = array(
|
||||
'id' => $sessionId,
|
||||
'id' => $this->sessionId,
|
||||
'member_name' => $this->member->member_id ? $this->member->name : '',
|
||||
'seo_name' => $this->member->member_id ? ( $this->member->members_seo_name ?: '' ) : '',
|
||||
'member_id' => $this->member->member_id ?: 0,
|
||||
@@ -238,6 +209,8 @@ class _Front extends \IPS\Session
|
||||
'location_data' => $session ? $session['location_data'] : NULL,
|
||||
'location_permissions' => $session ? $session['location_permissions'] : NULL,
|
||||
'theme_id' => $session ? $session['theme_id'] : 0,
|
||||
'in_editor' => ( \IPS\Request::i()->isAjax() ) ? ( $session ? $session['in_editor'] : 0 ) : 0,
|
||||
|
||||
);
|
||||
|
||||
/* Is this a spider? */
|
||||
@@ -294,6 +267,12 @@ class _Front extends \IPS\Session
|
||||
$this->save = FALSE;
|
||||
}
|
||||
|
||||
/* Don't update if we're an interface file showing database filesystem images, or custom field images, etc as this wipes location data */
|
||||
if ( isset( $_SERVER['SCRIPT_FILENAME'] ) and preg_match( '#/applications/(\w+?)/interface/#', $_SERVER['SCRIPT_FILENAME'] ) )
|
||||
{
|
||||
$this->save = FALSE;
|
||||
}
|
||||
|
||||
$this->data['member_name'] = $this->member->member_id ? $this->member->name : '';
|
||||
$this->data['member_id'] = $this->member->member_id ?: NULL;
|
||||
$this->data['data'] = $data;
|
||||
@@ -301,12 +280,29 @@ class _Front extends \IPS\Session
|
||||
|
||||
if ( $this->save === TRUE and ( !empty( \IPS\Request::i()->cookie ) or $this->userAgent->spider or $this->member->member_id ) ) // If a guest and cookies are disabled we do not write to database to prevent duplicate sessions unless it's a search engine, which we deal with separately
|
||||
{
|
||||
\IPS\Db::i()->replace( 'core_sessions', $this->data, TRUE );
|
||||
\IPS\Session\Store::i()->updateSession( $this->data );
|
||||
}
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* @brief Stored engine
|
||||
*/
|
||||
protected static $engine = NULL;
|
||||
|
||||
/**
|
||||
* Clear sessions - abstracted so it can be called externally without initiating a session
|
||||
*
|
||||
* @param int $timeout Sessions older than the number of seconds provided will be deleted
|
||||
* @return void
|
||||
*/
|
||||
public static function clearSessions( $timeout )
|
||||
{
|
||||
/* Cannot change this from a static method as it is called on garbage collection */
|
||||
\IPS\Session\Store::i()->clearSessions( $timeout );
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the search start
|
||||
*
|
||||
@@ -379,7 +375,17 @@ class _Front extends \IPS\Session
|
||||
$this->data['current_controller'] = \IPS\Dispatcher::i()->controller;
|
||||
$this->data['current_id'] = intval( \IPS\Request::i()->id );
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Set user as editing
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function setUsingEditor()
|
||||
{
|
||||
$this->data['in_editor'] = time();
|
||||
}
|
||||
|
||||
/**
|
||||
* Set the session location
|
||||
*
|
||||
@@ -427,6 +433,8 @@ class _Front extends \IPS\Session
|
||||
}
|
||||
|
||||
$this->data['location_permissions'] = ( $groupIds !== NULL ) ? ( is_string( $groupIds ) ? $groupIds : implode( ',', $groupIds ) ) : NULL;
|
||||
|
||||
$this->save = TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -444,24 +452,28 @@ class _Front extends \IPS\Session
|
||||
return $location;
|
||||
}
|
||||
|
||||
if ( $row['location_permissions'] === NULL or $row['location_permissions'] === '*' or \IPS\Member::loggedIn()->inGroup( explode( ',', $row['location_permissions'] ), TRUE ) )
|
||||
try
|
||||
{
|
||||
$sprintf = array();
|
||||
$data = json_decode( $row['location_data'], TRUE );
|
||||
if ( $row['location_permissions'] === NULL or $row['location_permissions'] === '*' or \IPS\Member::loggedIn()->inGroup( explode( ',', $row['location_permissions'] ), TRUE ) )
|
||||
{
|
||||
$sprintf = array();
|
||||
$data = json_decode( $row['location_data'], TRUE );
|
||||
|
||||
if ( !empty( $data ) )
|
||||
{
|
||||
foreach ( $data as $key => $parse )
|
||||
if ( !empty( $data ) )
|
||||
{
|
||||
$value = htmlspecialchars( $parse ? \IPS\Member::loggedIn()->language()->get( $key ) : $key, \IPS\HTMLENTITIES, 'UTF-8', FALSE );
|
||||
$sprintf[] = $value;
|
||||
foreach ( $data as $key => $parse )
|
||||
{
|
||||
$value = htmlspecialchars( $parse ? \IPS\Member::loggedIn()->language()->get( $key ) : $key, ENT_DISALLOWED, 'UTF-8', FALSE );
|
||||
$sprintf[] = $value;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$location = \IPS\Member::loggedIn()->language()->addToStack( htmlspecialchars( $row['location_lang'], \IPS\HTMLENTITIES, 'UTF-8', FALSE ), FALSE, array( 'htmlsprintf' => $sprintf ) );
|
||||
|
||||
$location = "<a href='" . htmlspecialchars( $row['location_url'], \IPS\HTMLENTITIES, 'UTF-8', FALSE ) . "'>" . $location . "</a>";
|
||||
$location = \IPS\Member::loggedIn()->language()->addToStack( htmlspecialchars( $row['location_lang'], ENT_DISALLOWED, 'UTF-8', FALSE ), FALSE, array( 'htmlsprintf' => $sprintf ) );
|
||||
|
||||
$location = "<a href='" . htmlspecialchars( $row['location_url'], ENT_DISALLOWED, 'UTF-8', FALSE ) . "'>" . $location . "</a>";
|
||||
}
|
||||
}
|
||||
catch ( \UnderflowException $e ){ }
|
||||
|
||||
return $location;
|
||||
}
|
||||
@@ -533,7 +545,7 @@ class _Front extends \IPS\Session
|
||||
unset( \IPS\Data\Store::i()->$dataKey );
|
||||
}
|
||||
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'id=?', $sessionId ) );
|
||||
\IPS\Session\Store::i()->deleteSession( $sessionId );
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
@@ -548,15 +560,4 @@ class _Front extends \IPS\Session
|
||||
static::clearSessions( $lifetime );
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Clear sessions - abstracted so it can be called externally without initiating a session
|
||||
*
|
||||
* @param int $timeout Sessions older than the number of seconds provided will be deleted
|
||||
* @return void
|
||||
*/
|
||||
public static function clearSessions( $timeout )
|
||||
{
|
||||
\IPS\Db::i()->delete( 'core_sessions', array( 'running_time<?', ( time() - $timeout ) ) );
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user