@@ -14,8 +14,9 @@ discard block |
||
| 14 | 14 | * @version 2.1 Beta 4 |
| 15 | 15 | */ |
| 16 | 16 | |
| 17 | -if (!defined('SMF')) |
|
| 17 | +if (!defined('SMF')) { |
|
| 18 | 18 | die('No direct access...'); |
| 19 | +} |
|
| 19 | 20 | |
| 20 | 21 | /** |
| 21 | 22 | * Check if the user is who he/she says he is |
@@ -42,12 +43,14 @@ discard block |
||
| 42 | 43 | $refreshTime = isset($_GET['xml']) ? 4200 : 3600; |
| 43 | 44 | |
| 44 | 45 | // Is the security option off? |
| 45 | - if (!empty($modSettings['securityDisable' . ($type != 'admin' ? '_' . $type : '')])) |
|
| 46 | - return; |
|
| 46 | + if (!empty($modSettings['securityDisable' . ($type != 'admin' ? '_' . $type : '')])) { |
|
| 47 | + return; |
|
| 48 | + } |
|
| 47 | 49 | |
| 48 | 50 | // Or are they already logged in?, Moderator or admin session is need for this area |
| 49 | - if ((!empty($_SESSION[$type . '_time']) && $_SESSION[$type . '_time'] + $refreshTime >= time()) || (!empty($_SESSION['admin_time']) && $_SESSION['admin_time'] + $refreshTime >= time())) |
|
| 50 | - return; |
|
| 51 | + if ((!empty($_SESSION[$type . '_time']) && $_SESSION[$type . '_time'] + $refreshTime >= time()) || (!empty($_SESSION['admin_time']) && $_SESSION['admin_time'] + $refreshTime >= time())) { |
|
| 52 | + return; |
|
| 53 | + } |
|
| 51 | 54 | |
| 52 | 55 | require_once($sourcedir . '/Subs-Auth.php'); |
| 53 | 56 | |
@@ -55,8 +58,9 @@ discard block |
||
| 55 | 58 | if (isset($_POST[$type . '_pass'])) |
| 56 | 59 | { |
| 57 | 60 | // Check to ensure we're forcing SSL for authentication |
| 58 | - if (!empty($modSettings['force_ssl']) && empty($maintenance) && !httpsOn()) |
|
| 59 | - fatal_lang_error('login_ssl_required'); |
|
| 61 | + if (!empty($modSettings['force_ssl']) && empty($maintenance) && !httpsOn()) { |
|
| 62 | + fatal_lang_error('login_ssl_required'); |
|
| 63 | + } |
|
| 60 | 64 | |
| 61 | 65 | checkSession(); |
| 62 | 66 | |
@@ -72,17 +76,19 @@ discard block |
||
| 72 | 76 | } |
| 73 | 77 | |
| 74 | 78 | // Better be sure to remember the real referer |
| 75 | - if (empty($_SESSION['request_referer'])) |
|
| 76 | - $_SESSION['request_referer'] = isset($_SERVER['HTTP_REFERER']) ? @parse_url($_SERVER['HTTP_REFERER']) : array(); |
|
| 77 | - elseif (empty($_POST)) |
|
| 78 | - unset($_SESSION['request_referer']); |
|
| 79 | + if (empty($_SESSION['request_referer'])) { |
|
| 80 | + $_SESSION['request_referer'] = isset($_SERVER['HTTP_REFERER']) ? @parse_url($_SERVER['HTTP_REFERER']) : array(); |
|
| 81 | + } elseif (empty($_POST)) { |
|
| 82 | + unset($_SESSION['request_referer']); |
|
| 83 | + } |
|
| 79 | 84 | |
| 80 | 85 | // Need to type in a password for that, man. |
| 81 | - if (!isset($_GET['xml'])) |
|
| 82 | - adminLogin($type); |
|
| 83 | - else |
|
| 84 | - return 'session_verify_fail'; |
|
| 85 | -} |
|
| 86 | + if (!isset($_GET['xml'])) { |
|
| 87 | + adminLogin($type); |
|
| 88 | + } else { |
|
| 89 | + return 'session_verify_fail'; |
|
| 90 | + } |
|
| 91 | + } |
|
| 86 | 92 | |
| 87 | 93 | /** |
| 88 | 94 | * Require a user who is logged in. (not a guest.) |
@@ -96,25 +102,30 @@ discard block |
||
| 96 | 102 | global $user_info, $txt, $context, $scripturl, $modSettings; |
| 97 | 103 | |
| 98 | 104 | // Luckily, this person isn't a guest. |
| 99 | - if (!$user_info['is_guest']) |
|
| 100 | - return; |
|
| 105 | + if (!$user_info['is_guest']) { |
|
| 106 | + return; |
|
| 107 | + } |
|
| 101 | 108 | |
| 102 | 109 | // Log what they were trying to do didn't work) |
| 103 | - if (!empty($modSettings['who_enabled'])) |
|
| 104 | - $_GET['error'] = 'guest_login'; |
|
| 110 | + if (!empty($modSettings['who_enabled'])) { |
|
| 111 | + $_GET['error'] = 'guest_login'; |
|
| 112 | + } |
|
| 105 | 113 | writeLog(true); |
| 106 | 114 | |
| 107 | 115 | // Just die. |
| 108 | - if (isset($_REQUEST['xml'])) |
|
| 109 | - obExit(false); |
|
| 116 | + if (isset($_REQUEST['xml'])) { |
|
| 117 | + obExit(false); |
|
| 118 | + } |
|
| 110 | 119 | |
| 111 | 120 | // Attempt to detect if they came from dlattach. |
| 112 | - if (SMF != 'SSI' && empty($context['theme_loaded'])) |
|
| 113 | - loadTheme(); |
|
| 121 | + if (SMF != 'SSI' && empty($context['theme_loaded'])) { |
|
| 122 | + loadTheme(); |
|
| 123 | + } |
|
| 114 | 124 | |
| 115 | 125 | // Never redirect to an attachment |
| 116 | - if (strpos($_SERVER['REQUEST_URL'], 'dlattach') === false) |
|
| 117 | - $_SESSION['login_url'] = $_SERVER['REQUEST_URL']; |
|
| 126 | + if (strpos($_SERVER['REQUEST_URL'], 'dlattach') === false) { |
|
| 127 | + $_SESSION['login_url'] = $_SERVER['REQUEST_URL']; |
|
| 128 | + } |
|
| 118 | 129 | |
| 119 | 130 | // Load the Login template and language file. |
| 120 | 131 | loadLanguage('Login'); |
@@ -124,8 +135,7 @@ discard block |
||
| 124 | 135 | { |
| 125 | 136 | $_SESSION['login_url'] = $scripturl . '?' . $_SERVER['QUERY_STRING']; |
| 126 | 137 | redirectexit('action=login'); |
| 127 | - } |
|
| 128 | - else |
|
| 138 | + } else |
|
| 129 | 139 | { |
| 130 | 140 | loadTemplate('Login'); |
| 131 | 141 | $context['sub_template'] = 'kick_guest'; |
@@ -155,8 +165,9 @@ discard block |
||
| 155 | 165 | global $sourcedir, $cookiename, $user_settings, $smcFunc; |
| 156 | 166 | |
| 157 | 167 | // You cannot be banned if you are an admin - doesn't help if you log out. |
| 158 | - if ($user_info['is_admin']) |
|
| 159 | - return; |
|
| 168 | + if ($user_info['is_admin']) { |
|
| 169 | + return; |
|
| 170 | + } |
|
| 160 | 171 | |
| 161 | 172 | // Only check the ban every so often. (to reduce load.) |
| 162 | 173 | if ($forceCheck || !isset($_SESSION['ban']) || empty($modSettings['banLastUpdated']) || ($_SESSION['ban']['last_checked'] < $modSettings['banLastUpdated']) || $_SESSION['ban']['id_member'] != $user_info['id'] || $_SESSION['ban']['ip'] != $user_info['ip'] || $_SESSION['ban']['ip2'] != $user_info['ip2'] || (isset($user_info['email'], $_SESSION['ban']['email']) && $_SESSION['ban']['email'] != $user_info['email'])) |
@@ -177,8 +188,9 @@ discard block |
||
| 177 | 188 | // Check both IP addresses. |
| 178 | 189 | foreach (array('ip', 'ip2') as $ip_number) |
| 179 | 190 | { |
| 180 | - if ($ip_number == 'ip2' && $user_info['ip2'] == $user_info['ip']) |
|
| 181 | - continue; |
|
| 191 | + if ($ip_number == 'ip2' && $user_info['ip2'] == $user_info['ip']) { |
|
| 192 | + continue; |
|
| 193 | + } |
|
| 182 | 194 | $ban_query[] = ' {inet:' . $ip_number . '} BETWEEN bi.ip_low and bi.ip_high'; |
| 183 | 195 | $ban_query_vars[$ip_number] = $user_info[$ip_number]; |
| 184 | 196 | // IP was valid, maybe there's also a hostname... |
@@ -228,24 +240,28 @@ discard block |
||
| 228 | 240 | // Store every type of ban that applies to you in your session. |
| 229 | 241 | while ($row = $smcFunc['db_fetch_assoc']($request)) |
| 230 | 242 | { |
| 231 | - foreach ($restrictions as $restriction) |
|
| 232 | - if (!empty($row[$restriction])) |
|
| 243 | + foreach ($restrictions as $restriction) { |
|
| 244 | + if (!empty($row[$restriction])) |
|
| 233 | 245 | { |
| 234 | 246 | $_SESSION['ban'][$restriction]['reason'] = $row['reason']; |
| 247 | + } |
|
| 235 | 248 | $_SESSION['ban'][$restriction]['ids'][] = $row['id_ban']; |
| 236 | - if (!isset($_SESSION['ban']['expire_time']) || ($_SESSION['ban']['expire_time'] != 0 && ($row['expire_time'] == 0 || $row['expire_time'] > $_SESSION['ban']['expire_time']))) |
|
| 237 | - $_SESSION['ban']['expire_time'] = $row['expire_time']; |
|
| 249 | + if (!isset($_SESSION['ban']['expire_time']) || ($_SESSION['ban']['expire_time'] != 0 && ($row['expire_time'] == 0 || $row['expire_time'] > $_SESSION['ban']['expire_time']))) { |
|
| 250 | + $_SESSION['ban']['expire_time'] = $row['expire_time']; |
|
| 251 | + } |
|
| 238 | 252 | |
| 239 | - if (!$user_info['is_guest'] && $restriction == 'cannot_access' && ($row['id_member'] == $user_info['id'] || $row['email_address'] == $user_info['email'])) |
|
| 240 | - $flag_is_activated = true; |
|
| 253 | + if (!$user_info['is_guest'] && $restriction == 'cannot_access' && ($row['id_member'] == $user_info['id'] || $row['email_address'] == $user_info['email'])) { |
|
| 254 | + $flag_is_activated = true; |
|
| 255 | + } |
|
| 241 | 256 | } |
| 242 | 257 | } |
| 243 | 258 | $smcFunc['db_free_result']($request); |
| 244 | 259 | } |
| 245 | 260 | |
| 246 | 261 | // Mark the cannot_access and cannot_post bans as being 'hit'. |
| 247 | - if (isset($_SESSION['ban']['cannot_access']) || isset($_SESSION['ban']['cannot_post']) || isset($_SESSION['ban']['cannot_login'])) |
|
| 248 | - log_ban(array_merge(isset($_SESSION['ban']['cannot_access']) ? $_SESSION['ban']['cannot_access']['ids'] : array(), isset($_SESSION['ban']['cannot_post']) ? $_SESSION['ban']['cannot_post']['ids'] : array(), isset($_SESSION['ban']['cannot_login']) ? $_SESSION['ban']['cannot_login']['ids'] : array())); |
|
| 262 | + if (isset($_SESSION['ban']['cannot_access']) || isset($_SESSION['ban']['cannot_post']) || isset($_SESSION['ban']['cannot_login'])) { |
|
| 263 | + log_ban(array_merge(isset($_SESSION['ban']['cannot_access']) ? $_SESSION['ban']['cannot_access']['ids'] : array(), isset($_SESSION['ban']['cannot_post']) ? $_SESSION['ban']['cannot_post']['ids'] : array(), isset($_SESSION['ban']['cannot_login']) ? $_SESSION['ban']['cannot_login']['ids'] : array())); |
|
| 264 | + } |
|
| 249 | 265 | |
| 250 | 266 | // If for whatever reason the is_activated flag seems wrong, do a little work to clear it up. |
| 251 | 267 | if ($user_info['id'] && (($user_settings['is_activated'] >= 10 && !$flag_is_activated) |
@@ -260,8 +276,9 @@ discard block |
||
| 260 | 276 | if (!isset($_SESSION['ban']['cannot_access']) && !empty($_COOKIE[$cookiename . '_'])) |
| 261 | 277 | { |
| 262 | 278 | $bans = explode(',', $_COOKIE[$cookiename . '_']); |
| 263 | - foreach ($bans as $key => $value) |
|
| 264 | - $bans[$key] = (int) $value; |
|
| 279 | + foreach ($bans as $key => $value) { |
|
| 280 | + $bans[$key] = (int) $value; |
|
| 281 | + } |
|
| 265 | 282 | $request = $smcFunc['db_query']('', ' |
| 266 | 283 | SELECT bi.id_ban, bg.reason, COALESCE(bg.expire_time, 0) AS expire_time |
| 267 | 284 | FROM {db_prefix}ban_items AS bi |
@@ -298,14 +315,15 @@ discard block |
||
| 298 | 315 | if (isset($_SESSION['ban']['cannot_access'])) |
| 299 | 316 | { |
| 300 | 317 | // We don't wanna see you! |
| 301 | - if (!$user_info['is_guest']) |
|
| 302 | - $smcFunc['db_query']('', ' |
|
| 318 | + if (!$user_info['is_guest']) { |
|
| 319 | + $smcFunc['db_query']('', ' |
|
| 303 | 320 | DELETE FROM {db_prefix}log_online |
| 304 | 321 | WHERE id_member = {int:current_member}', |
| 305 | 322 | array( |
| 306 | 323 | 'current_member' => $user_info['id'], |
| 307 | 324 | ) |
| 308 | 325 | ); |
| 326 | + } |
|
| 309 | 327 | |
| 310 | 328 | // 'Log' the user out. Can't have any funny business... (save the name!) |
| 311 | 329 | $old_name = isset($user_info['name']) && $user_info['name'] != '' ? $user_info['name'] : $txt['guest_title']; |
@@ -391,9 +409,10 @@ discard block |
||
| 391 | 409 | } |
| 392 | 410 | |
| 393 | 411 | // Fix up the banning permissions. |
| 394 | - if (isset($user_info['permissions'])) |
|
| 395 | - banPermissions(); |
|
| 396 | -} |
|
| 412 | + if (isset($user_info['permissions'])) { |
|
| 413 | + banPermissions(); |
|
| 414 | + } |
|
| 415 | + } |
|
| 397 | 416 | |
| 398 | 417 | /** |
| 399 | 418 | * Fix permissions according to ban status. |
@@ -404,8 +423,9 @@ discard block |
||
| 404 | 423 | global $user_info, $sourcedir, $modSettings, $context; |
| 405 | 424 | |
| 406 | 425 | // Somehow they got here, at least take away all permissions... |
| 407 | - if (isset($_SESSION['ban']['cannot_access'])) |
|
| 408 | - $user_info['permissions'] = array(); |
|
| 426 | + if (isset($_SESSION['ban']['cannot_access'])) { |
|
| 427 | + $user_info['permissions'] = array(); |
|
| 428 | + } |
|
| 409 | 429 | // Okay, well, you can watch, but don't touch a thing. |
| 410 | 430 | elseif (isset($_SESSION['ban']['cannot_post']) || (!empty($modSettings['warning_mute']) && $modSettings['warning_mute'] <= $user_info['warning'])) |
| 411 | 431 | { |
@@ -447,19 +467,20 @@ discard block |
||
| 447 | 467 | call_integration_hook('integrate_warn_permissions', array(&$permission_change)); |
| 448 | 468 | foreach ($permission_change as $old => $new) |
| 449 | 469 | { |
| 450 | - if (!in_array($old, $user_info['permissions'])) |
|
| 451 | - unset($permission_change[$old]); |
|
| 452 | - else |
|
| 453 | - $user_info['permissions'][] = $new; |
|
| 470 | + if (!in_array($old, $user_info['permissions'])) { |
|
| 471 | + unset($permission_change[$old]); |
|
| 472 | + } else { |
|
| 473 | + $user_info['permissions'][] = $new; |
|
| 474 | + } |
|
| 454 | 475 | } |
| 455 | 476 | $user_info['permissions'] = array_diff($user_info['permissions'], array_keys($permission_change)); |
| 456 | 477 | } |
| 457 | 478 | |
| 458 | 479 | // @todo Find a better place to call this? Needs to be after permissions loaded! |
| 459 | 480 | // Finally, some bits we cache in the session because it saves queries. |
| 460 | - if (isset($_SESSION['mc']) && $_SESSION['mc']['time'] > $modSettings['settings_updated'] && $_SESSION['mc']['id'] == $user_info['id']) |
|
| 461 | - $user_info['mod_cache'] = $_SESSION['mc']; |
|
| 462 | - else |
|
| 481 | + if (isset($_SESSION['mc']) && $_SESSION['mc']['time'] > $modSettings['settings_updated'] && $_SESSION['mc']['id'] == $user_info['id']) { |
|
| 482 | + $user_info['mod_cache'] = $_SESSION['mc']; |
|
| 483 | + } else |
|
| 463 | 484 | { |
| 464 | 485 | require_once($sourcedir . '/Subs-Auth.php'); |
| 465 | 486 | rebuildModCache(); |
@@ -470,14 +491,12 @@ discard block |
||
| 470 | 491 | { |
| 471 | 492 | $context['open_mod_reports'] = $_SESSION['rc']['reports']; |
| 472 | 493 | $context['open_member_reports'] = $_SESSION['rc']['member_reports']; |
| 473 | - } |
|
| 474 | - elseif ($_SESSION['mc']['bq'] != '0=1') |
|
| 494 | + } elseif ($_SESSION['mc']['bq'] != '0=1') |
|
| 475 | 495 | { |
| 476 | 496 | require_once($sourcedir . '/Subs-ReportedContent.php'); |
| 477 | 497 | $context['open_mod_reports'] = recountOpenReports('posts'); |
| 478 | 498 | $context['open_member_reports'] = recountOpenReports('members'); |
| 479 | - } |
|
| 480 | - else |
|
| 499 | + } else |
|
| 481 | 500 | { |
| 482 | 501 | $context['open_mod_reports'] = 0; |
| 483 | 502 | $context['open_member_reports'] = 0; |
@@ -497,8 +516,9 @@ discard block |
||
| 497 | 516 | global $user_info, $smcFunc; |
| 498 | 517 | |
| 499 | 518 | // Don't log web accelerators, it's very confusing... |
| 500 | - if (isset($_SERVER['HTTP_X_MOZ']) && $_SERVER['HTTP_X_MOZ'] == 'prefetch') |
|
| 501 | - return; |
|
| 519 | + if (isset($_SERVER['HTTP_X_MOZ']) && $_SERVER['HTTP_X_MOZ'] == 'prefetch') { |
|
| 520 | + return; |
|
| 521 | + } |
|
| 502 | 522 | |
| 503 | 523 | $smcFunc['db_insert']('', |
| 504 | 524 | '{db_prefix}log_banned', |
@@ -508,8 +528,8 @@ discard block |
||
| 508 | 528 | ); |
| 509 | 529 | |
| 510 | 530 | // One extra point for these bans. |
| 511 | - if (!empty($ban_ids)) |
|
| 512 | - $smcFunc['db_query']('', ' |
|
| 531 | + if (!empty($ban_ids)) { |
|
| 532 | + $smcFunc['db_query']('', ' |
|
| 513 | 533 | UPDATE {db_prefix}ban_items |
| 514 | 534 | SET hits = hits + 1 |
| 515 | 535 | WHERE id_ban IN ({array_int:ban_ids})', |
@@ -517,7 +537,8 @@ discard block |
||
| 517 | 537 | 'ban_ids' => $ban_ids, |
| 518 | 538 | ) |
| 519 | 539 | ); |
| 520 | -} |
|
| 540 | + } |
|
| 541 | + } |
|
| 521 | 542 | |
| 522 | 543 | /** |
| 523 | 544 | * Checks if a given email address might be banned. |
@@ -533,8 +554,9 @@ discard block |
||
| 533 | 554 | global $txt, $smcFunc; |
| 534 | 555 | |
| 535 | 556 | // Can't ban an empty email |
| 536 | - if (empty($email) || trim($email) == '') |
|
| 537 | - return; |
|
| 557 | + if (empty($email) || trim($email) == '') { |
|
| 558 | + return; |
|
| 559 | + } |
|
| 538 | 560 | |
| 539 | 561 | // Let's start with the bans based on your IP/hostname/memberID... |
| 540 | 562 | $ban_ids = isset($_SESSION['ban'][$restriction]) ? $_SESSION['ban'][$restriction]['ids'] : array(); |
@@ -607,16 +629,18 @@ discard block |
||
| 607 | 629 | if ($type == 'post') |
| 608 | 630 | { |
| 609 | 631 | $check = isset($_POST[$_SESSION['session_var']]) ? $_POST[$_SESSION['session_var']] : (empty($modSettings['strictSessionCheck']) && isset($_POST['sc']) ? $_POST['sc'] : null); |
| 610 | - if ($check !== $sc) |
|
| 611 | - $error = 'session_timeout'; |
|
| 632 | + if ($check !== $sc) { |
|
| 633 | + $error = 'session_timeout'; |
|
| 634 | + } |
|
| 612 | 635 | } |
| 613 | 636 | |
| 614 | 637 | // How about $_GET['sesc']? |
| 615 | 638 | elseif ($type == 'get') |
| 616 | 639 | { |
| 617 | 640 | $check = isset($_GET[$_SESSION['session_var']]) ? $_GET[$_SESSION['session_var']] : (empty($modSettings['strictSessionCheck']) && isset($_GET['sesc']) ? $_GET['sesc'] : null); |
| 618 | - if ($check !== $sc) |
|
| 619 | - $error = 'session_verify_fail'; |
|
| 641 | + if ($check !== $sc) { |
|
| 642 | + $error = 'session_verify_fail'; |
|
| 643 | + } |
|
| 620 | 644 | } |
| 621 | 645 | |
| 622 | 646 | // Or can it be in either? |
@@ -624,13 +648,15 @@ discard block |
||
| 624 | 648 | { |
| 625 | 649 | $check = isset($_GET[$_SESSION['session_var']]) ? $_GET[$_SESSION['session_var']] : (empty($modSettings['strictSessionCheck']) && isset($_GET['sesc']) ? $_GET['sesc'] : (isset($_POST[$_SESSION['session_var']]) ? $_POST[$_SESSION['session_var']] : (empty($modSettings['strictSessionCheck']) && isset($_POST['sc']) ? $_POST['sc'] : null))); |
| 626 | 650 | |
| 627 | - if ($check !== $sc) |
|
| 628 | - $error = 'session_verify_fail'; |
|
| 651 | + if ($check !== $sc) { |
|
| 652 | + $error = 'session_verify_fail'; |
|
| 653 | + } |
|
| 629 | 654 | } |
| 630 | 655 | |
| 631 | 656 | // Verify that they aren't changing user agents on us - that could be bad. |
| 632 | - if ((!isset($_SESSION['USER_AGENT']) || $_SESSION['USER_AGENT'] != $_SERVER['HTTP_USER_AGENT']) && empty($modSettings['disableCheckUA'])) |
|
| 633 | - $error = 'session_verify_fail'; |
|
| 657 | + if ((!isset($_SESSION['USER_AGENT']) || $_SESSION['USER_AGENT'] != $_SERVER['HTTP_USER_AGENT']) && empty($modSettings['disableCheckUA'])) { |
|
| 658 | + $error = 'session_verify_fail'; |
|
| 659 | + } |
|
| 634 | 660 | |
| 635 | 661 | // Make sure a page with session check requirement is not being prefetched. |
| 636 | 662 | if (isset($_SERVER['HTTP_X_MOZ']) && $_SERVER['HTTP_X_MOZ'] == 'prefetch') |
@@ -641,30 +667,35 @@ discard block |
||
| 641 | 667 | } |
| 642 | 668 | |
| 643 | 669 | // Check the referring site - it should be the same server at least! |
| 644 | - if (isset($_SESSION['request_referer'])) |
|
| 645 | - $referrer = $_SESSION['request_referer']; |
|
| 646 | - else |
|
| 647 | - $referrer = isset($_SERVER['HTTP_REFERER']) ? @parse_url($_SERVER['HTTP_REFERER']) : array(); |
|
| 670 | + if (isset($_SESSION['request_referer'])) { |
|
| 671 | + $referrer = $_SESSION['request_referer']; |
|
| 672 | + } else { |
|
| 673 | + $referrer = isset($_SERVER['HTTP_REFERER']) ? @parse_url($_SERVER['HTTP_REFERER']) : array(); |
|
| 674 | + } |
|
| 648 | 675 | if (!empty($referrer['host'])) |
| 649 | 676 | { |
| 650 | - if (strpos($_SERVER['HTTP_HOST'], ':') !== false) |
|
| 651 | - $real_host = substr($_SERVER['HTTP_HOST'], 0, strpos($_SERVER['HTTP_HOST'], ':')); |
|
| 652 | - else |
|
| 653 | - $real_host = $_SERVER['HTTP_HOST']; |
|
| 677 | + if (strpos($_SERVER['HTTP_HOST'], ':') !== false) { |
|
| 678 | + $real_host = substr($_SERVER['HTTP_HOST'], 0, strpos($_SERVER['HTTP_HOST'], ':')); |
|
| 679 | + } else { |
|
| 680 | + $real_host = $_SERVER['HTTP_HOST']; |
|
| 681 | + } |
|
| 654 | 682 | |
| 655 | 683 | $parsed_url = parse_url($boardurl); |
| 656 | 684 | |
| 657 | 685 | // Are global cookies on? If so, let's check them ;). |
| 658 | 686 | if (!empty($modSettings['globalCookies'])) |
| 659 | 687 | { |
| 660 | - if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $parsed_url['host'], $parts) == 1) |
|
| 661 | - $parsed_url['host'] = $parts[1]; |
|
| 688 | + if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $parsed_url['host'], $parts) == 1) { |
|
| 689 | + $parsed_url['host'] = $parts[1]; |
|
| 690 | + } |
|
| 662 | 691 | |
| 663 | - if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $referrer['host'], $parts) == 1) |
|
| 664 | - $referrer['host'] = $parts[1]; |
|
| 692 | + if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $referrer['host'], $parts) == 1) { |
|
| 693 | + $referrer['host'] = $parts[1]; |
|
| 694 | + } |
|
| 665 | 695 | |
| 666 | - if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $real_host, $parts) == 1) |
|
| 667 | - $real_host = $parts[1]; |
|
| 696 | + if (preg_match('~(?:[^\.]+\.)?([^\.]{3,}\..+)\z~i', $real_host, $parts) == 1) { |
|
| 697 | + $real_host = $parts[1]; |
|
| 698 | + } |
|
| 668 | 699 | } |
| 669 | 700 | |
| 670 | 701 | // Okay: referrer must either match parsed_url or real_host. |
@@ -682,12 +713,14 @@ discard block |
||
| 682 | 713 | $log_error = true; |
| 683 | 714 | } |
| 684 | 715 | |
| 685 | - if (strtolower($_SERVER['HTTP_USER_AGENT']) == 'hacker') |
|
| 686 | - fatal_error('Sound the alarm! It\'s a hacker! Close the castle gates!!', false); |
|
| 716 | + if (strtolower($_SERVER['HTTP_USER_AGENT']) == 'hacker') { |
|
| 717 | + fatal_error('Sound the alarm! It\'s a hacker! Close the castle gates!!', false); |
|
| 718 | + } |
|
| 687 | 719 | |
| 688 | 720 | // Everything is ok, return an empty string. |
| 689 | - if (!isset($error)) |
|
| 690 | - return ''; |
|
| 721 | + if (!isset($error)) { |
|
| 722 | + return ''; |
|
| 723 | + } |
|
| 691 | 724 | // A session error occurred, show the error. |
| 692 | 725 | elseif ($is_fatal) |
| 693 | 726 | { |
@@ -696,13 +729,14 @@ discard block |
||
| 696 | 729 | ob_end_clean(); |
| 697 | 730 | header('HTTP/1.1 403 Forbidden - Session timeout'); |
| 698 | 731 | die; |
| 732 | + } else { |
|
| 733 | + fatal_lang_error($error, isset($log_error) ? 'user' : false); |
|
| 699 | 734 | } |
| 700 | - else |
|
| 701 | - fatal_lang_error($error, isset($log_error) ? 'user' : false); |
|
| 702 | 735 | } |
| 703 | 736 | // A session error occurred, return the error to the calling function. |
| 704 | - else |
|
| 705 | - return $error; |
|
| 737 | + else { |
|
| 738 | + return $error; |
|
| 739 | + } |
|
| 706 | 740 | |
| 707 | 741 | // We really should never fall through here, for very important reasons. Let's make sure. |
| 708 | 742 | trigger_error('Hacking attempt...', E_USER_ERROR); |
@@ -718,10 +752,9 @@ discard block |
||
| 718 | 752 | { |
| 719 | 753 | global $modSettings; |
| 720 | 754 | |
| 721 | - if (isset($_GET['confirm']) && isset($_SESSION['confirm_' . $action]) && md5($_GET['confirm'] . $_SERVER['HTTP_USER_AGENT']) == $_SESSION['confirm_' . $action]) |
|
| 722 | - return true; |
|
| 723 | - |
|
| 724 | - else |
|
| 755 | + if (isset($_GET['confirm']) && isset($_SESSION['confirm_' . $action]) && md5($_GET['confirm'] . $_SERVER['HTTP_USER_AGENT']) == $_SESSION['confirm_' . $action]) { |
|
| 756 | + return true; |
|
| 757 | + } else |
|
| 725 | 758 | { |
| 726 | 759 | $token = md5(mt_rand() . session_id() . (string) microtime() . $modSettings['rand_seed']); |
| 727 | 760 | $_SESSION['confirm_' . $action] = md5($token . $_SERVER['HTTP_USER_AGENT']); |
@@ -772,9 +805,9 @@ discard block |
||
| 772 | 805 | $return = $_SESSION['token'][$type . '-' . $action][3]; |
| 773 | 806 | unset($_SESSION['token'][$type . '-' . $action]); |
| 774 | 807 | return $return; |
| 808 | + } else { |
|
| 809 | + return ''; |
|
| 775 | 810 | } |
| 776 | - else |
|
| 777 | - return ''; |
|
| 778 | 811 | } |
| 779 | 812 | |
| 780 | 813 | // This nasty piece of code validates a token. |
@@ -805,12 +838,14 @@ discard block |
||
| 805 | 838 | fatal_lang_error('token_verify_fail', false); |
| 806 | 839 | } |
| 807 | 840 | // Remove this token as its useless |
| 808 | - else |
|
| 809 | - unset($_SESSION['token'][$type . '-' . $action]); |
|
| 841 | + else { |
|
| 842 | + unset($_SESSION['token'][$type . '-' . $action]); |
|
| 843 | + } |
|
| 810 | 844 | |
| 811 | 845 | // Randomly check if we should remove some older tokens. |
| 812 | - if (mt_rand(0, 138) == 23) |
|
| 813 | - cleanTokens(); |
|
| 846 | + if (mt_rand(0, 138) == 23) { |
|
| 847 | + cleanTokens(); |
|
| 848 | + } |
|
| 814 | 849 | |
| 815 | 850 | return false; |
| 816 | 851 | } |
@@ -825,14 +860,16 @@ discard block |
||
| 825 | 860 | function cleanTokens($complete = false) |
| 826 | 861 | { |
| 827 | 862 | // We appreciate cleaning up after yourselves. |
| 828 | - if (!isset($_SESSION['token'])) |
|
| 829 | - return; |
|
| 863 | + if (!isset($_SESSION['token'])) { |
|
| 864 | + return; |
|
| 865 | + } |
|
| 830 | 866 | |
| 831 | 867 | // Clean up tokens, trying to give enough time still. |
| 832 | - foreach ($_SESSION['token'] as $key => $data) |
|
| 833 | - if ($data[2] + 10800 < time() || $complete) |
|
| 868 | + foreach ($_SESSION['token'] as $key => $data) { |
|
| 869 | + if ($data[2] + 10800 < time() || $complete) |
|
| 834 | 870 | unset($_SESSION['token'][$key]); |
| 835 | -} |
|
| 871 | + } |
|
| 872 | + } |
|
| 836 | 873 | |
| 837 | 874 | /** |
| 838 | 875 | * Check whether a form has been submitted twice. |
@@ -850,37 +887,40 @@ discard block |
||
| 850 | 887 | { |
| 851 | 888 | global $context; |
| 852 | 889 | |
| 853 | - if (!isset($_SESSION['forms'])) |
|
| 854 | - $_SESSION['forms'] = array(); |
|
| 890 | + if (!isset($_SESSION['forms'])) { |
|
| 891 | + $_SESSION['forms'] = array(); |
|
| 892 | + } |
|
| 855 | 893 | |
| 856 | 894 | // Register a form number and store it in the session stack. (use this on the page that has the form.) |
| 857 | 895 | if ($action == 'register') |
| 858 | 896 | { |
| 859 | 897 | $context['form_sequence_number'] = 0; |
| 860 | - while (empty($context['form_sequence_number']) || in_array($context['form_sequence_number'], $_SESSION['forms'])) |
|
| 861 | - $context['form_sequence_number'] = mt_rand(1, 16000000); |
|
| 898 | + while (empty($context['form_sequence_number']) || in_array($context['form_sequence_number'], $_SESSION['forms'])) { |
|
| 899 | + $context['form_sequence_number'] = mt_rand(1, 16000000); |
|
| 900 | + } |
|
| 862 | 901 | } |
| 863 | 902 | // Check whether the submitted number can be found in the session. |
| 864 | 903 | elseif ($action == 'check') |
| 865 | 904 | { |
| 866 | - if (!isset($_REQUEST['seqnum'])) |
|
| 867 | - return true; |
|
| 868 | - elseif (!in_array($_REQUEST['seqnum'], $_SESSION['forms'])) |
|
| 905 | + if (!isset($_REQUEST['seqnum'])) { |
|
| 906 | + return true; |
|
| 907 | + } elseif (!in_array($_REQUEST['seqnum'], $_SESSION['forms'])) |
|
| 869 | 908 | { |
| 870 | 909 | $_SESSION['forms'][] = (int) $_REQUEST['seqnum']; |
| 871 | 910 | return true; |
| 911 | + } elseif ($is_fatal) { |
|
| 912 | + fatal_lang_error('error_form_already_submitted', false); |
|
| 913 | + } else { |
|
| 914 | + return false; |
|
| 872 | 915 | } |
| 873 | - elseif ($is_fatal) |
|
| 874 | - fatal_lang_error('error_form_already_submitted', false); |
|
| 875 | - else |
|
| 876 | - return false; |
|
| 877 | 916 | } |
| 878 | 917 | // Don't check, just free the stack number. |
| 879 | - elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms'])) |
|
| 880 | - $_SESSION['forms'] = array_diff($_SESSION['forms'], array($_REQUEST['seqnum'])); |
|
| 881 | - elseif ($action != 'free') |
|
| 882 | - trigger_error('checkSubmitOnce(): Invalid action \'' . $action . '\'', E_USER_WARNING); |
|
| 883 | -} |
|
| 918 | + elseif ($action == 'free' && isset($_REQUEST['seqnum']) && in_array($_REQUEST['seqnum'], $_SESSION['forms'])) { |
|
| 919 | + $_SESSION['forms'] = array_diff($_SESSION['forms'], array($_REQUEST['seqnum'])); |
|
| 920 | + } elseif ($action != 'free') { |
|
| 921 | + trigger_error('checkSubmitOnce(): Invalid action \'' . $action . '\'', E_USER_WARNING); |
|
| 922 | + } |
|
| 923 | + } |
|
| 884 | 924 | |
| 885 | 925 | /** |
| 886 | 926 | * Check the user's permissions. |
@@ -899,16 +939,19 @@ discard block |
||
| 899 | 939 | global $user_info, $smcFunc; |
| 900 | 940 | |
| 901 | 941 | // You're always allowed to do nothing. (unless you're a working man, MR. LAZY :P!) |
| 902 | - if (empty($permission)) |
|
| 903 | - return true; |
|
| 942 | + if (empty($permission)) { |
|
| 943 | + return true; |
|
| 944 | + } |
|
| 904 | 945 | |
| 905 | 946 | // You're never allowed to do something if your data hasn't been loaded yet! |
| 906 | - if (empty($user_info)) |
|
| 907 | - return false; |
|
| 947 | + if (empty($user_info)) { |
|
| 948 | + return false; |
|
| 949 | + } |
|
| 908 | 950 | |
| 909 | 951 | // Administrators are supermen :P. |
| 910 | - if ($user_info['is_admin']) |
|
| 911 | - return true; |
|
| 952 | + if ($user_info['is_admin']) { |
|
| 953 | + return true; |
|
| 954 | + } |
|
| 912 | 955 | |
| 913 | 956 | // Let's ensure this is an array. |
| 914 | 957 | $permission = (array) $permission; |
@@ -916,14 +959,16 @@ discard block |
||
| 916 | 959 | // Are we checking the _current_ board, or some other boards? |
| 917 | 960 | if ($boards === null) |
| 918 | 961 | { |
| 919 | - if (count(array_intersect($permission, $user_info['permissions'])) != 0) |
|
| 920 | - return true; |
|
| 962 | + if (count(array_intersect($permission, $user_info['permissions'])) != 0) { |
|
| 963 | + return true; |
|
| 964 | + } |
|
| 921 | 965 | // You aren't allowed, by default. |
| 922 | - else |
|
| 923 | - return false; |
|
| 966 | + else { |
|
| 967 | + return false; |
|
| 968 | + } |
|
| 969 | + } elseif (!is_array($boards)) { |
|
| 970 | + $boards = array($boards); |
|
| 924 | 971 | } |
| 925 | - elseif (!is_array($boards)) |
|
| 926 | - $boards = array($boards); |
|
| 927 | 972 | |
| 928 | 973 | $request = $smcFunc['db_query']('', ' |
| 929 | 974 | SELECT MIN(bp.add_deny) AS add_deny |
@@ -951,20 +996,23 @@ discard block |
||
| 951 | 996 | while ($row = $smcFunc['db_fetch_assoc']($request)) |
| 952 | 997 | { |
| 953 | 998 | $result = !empty($row['add_deny']); |
| 954 | - if ($result == true) |
|
| 955 | - break; |
|
| 999 | + if ($result == true) { |
|
| 1000 | + break; |
|
| 1001 | + } |
|
| 956 | 1002 | } |
| 957 | 1003 | $smcFunc['db_free_result']($request); |
| 958 | 1004 | return $result; |
| 959 | 1005 | } |
| 960 | 1006 | |
| 961 | 1007 | // Make sure they can do it on all of the boards. |
| 962 | - if ($smcFunc['db_num_rows']($request) != count($boards)) |
|
| 963 | - return false; |
|
| 1008 | + if ($smcFunc['db_num_rows']($request) != count($boards)) { |
|
| 1009 | + return false; |
|
| 1010 | + } |
|
| 964 | 1011 | |
| 965 | 1012 | $result = true; |
| 966 | - while ($row = $smcFunc['db_fetch_assoc']($request)) |
|
| 967 | - $result &= !empty($row['add_deny']); |
|
| 1013 | + while ($row = $smcFunc['db_fetch_assoc']($request)) { |
|
| 1014 | + $result &= !empty($row['add_deny']); |
|
| 1015 | + } |
|
| 968 | 1016 | $smcFunc['db_free_result']($request); |
| 969 | 1017 | |
| 970 | 1018 | // If the query returned 1, they can do it... otherwise, they can't. |
@@ -1031,9 +1079,10 @@ discard block |
||
| 1031 | 1079 | |
| 1032 | 1080 | // If you're doing something on behalf of some "heavy" permissions, validate your session. |
| 1033 | 1081 | // (take out the heavy permissions, and if you can't do anything but those, you need a validated session.) |
| 1034 | - if (!allowedTo(array_diff($permission, $heavy_permissions), $boards)) |
|
| 1035 | - validateSession(); |
|
| 1036 | -} |
|
| 1082 | + if (!allowedTo(array_diff($permission, $heavy_permissions), $boards)) { |
|
| 1083 | + validateSession(); |
|
| 1084 | + } |
|
| 1085 | + } |
|
| 1037 | 1086 | |
| 1038 | 1087 | /** |
| 1039 | 1088 | * Return the boards a user has a certain (board) permission on. (array(0) if all.) |
@@ -1052,8 +1101,9 @@ discard block |
||
| 1052 | 1101 | global $user_info, $smcFunc; |
| 1053 | 1102 | |
| 1054 | 1103 | // Arrays are nice, most of the time. |
| 1055 | - if (!is_array($permissions)) |
|
| 1056 | - $permissions = array($permissions); |
|
| 1104 | + if (!is_array($permissions)) { |
|
| 1105 | + $permissions = array($permissions); |
|
| 1106 | + } |
|
| 1057 | 1107 | |
| 1058 | 1108 | /* |
| 1059 | 1109 | * Set $simple to true to use this function as it were in SMF 2.0.x. |
@@ -1065,13 +1115,14 @@ discard block |
||
| 1065 | 1115 | // Administrators are all powerful, sorry. |
| 1066 | 1116 | if ($user_info['is_admin']) |
| 1067 | 1117 | { |
| 1068 | - if ($simple) |
|
| 1069 | - return array(0); |
|
| 1070 | - else |
|
| 1118 | + if ($simple) { |
|
| 1119 | + return array(0); |
|
| 1120 | + } else |
|
| 1071 | 1121 | { |
| 1072 | 1122 | $boards = array(); |
| 1073 | - foreach ($permissions as $permission) |
|
| 1074 | - $boards[$permission] = array(0); |
|
| 1123 | + foreach ($permissions as $permission) { |
|
| 1124 | + $boards[$permission] = array(0); |
|
| 1125 | + } |
|
| 1075 | 1126 | |
| 1076 | 1127 | return $boards; |
| 1077 | 1128 | } |
@@ -1103,31 +1154,32 @@ discard block |
||
| 1103 | 1154 | { |
| 1104 | 1155 | if ($simple) |
| 1105 | 1156 | { |
| 1106 | - if (empty($row['add_deny'])) |
|
| 1107 | - $deny_boards[] = $row['id_board']; |
|
| 1108 | - else |
|
| 1109 | - $boards[] = $row['id_board']; |
|
| 1110 | - } |
|
| 1111 | - else |
|
| 1157 | + if (empty($row['add_deny'])) { |
|
| 1158 | + $deny_boards[] = $row['id_board']; |
|
| 1159 | + } else { |
|
| 1160 | + $boards[] = $row['id_board']; |
|
| 1161 | + } |
|
| 1162 | + } else |
|
| 1112 | 1163 | { |
| 1113 | - if (empty($row['add_deny'])) |
|
| 1114 | - $deny_boards[$row['permission']][] = $row['id_board']; |
|
| 1115 | - else |
|
| 1116 | - $boards[$row['permission']][] = $row['id_board']; |
|
| 1164 | + if (empty($row['add_deny'])) { |
|
| 1165 | + $deny_boards[$row['permission']][] = $row['id_board']; |
|
| 1166 | + } else { |
|
| 1167 | + $boards[$row['permission']][] = $row['id_board']; |
|
| 1168 | + } |
|
| 1117 | 1169 | } |
| 1118 | 1170 | } |
| 1119 | 1171 | $smcFunc['db_free_result']($request); |
| 1120 | 1172 | |
| 1121 | - if ($simple) |
|
| 1122 | - $boards = array_unique(array_values(array_diff($boards, $deny_boards))); |
|
| 1123 | - else |
|
| 1173 | + if ($simple) { |
|
| 1174 | + $boards = array_unique(array_values(array_diff($boards, $deny_boards))); |
|
| 1175 | + } else |
|
| 1124 | 1176 | { |
| 1125 | 1177 | foreach ($permissions as $permission) |
| 1126 | 1178 | { |
| 1127 | 1179 | // never had it to start with |
| 1128 | - if (empty($boards[$permission])) |
|
| 1129 | - $boards[$permission] = array(); |
|
| 1130 | - else |
|
| 1180 | + if (empty($boards[$permission])) { |
|
| 1181 | + $boards[$permission] = array(); |
|
| 1182 | + } else |
|
| 1131 | 1183 | { |
| 1132 | 1184 | // Or it may have been removed |
| 1133 | 1185 | $deny_boards[$permission] = isset($deny_boards[$permission]) ? $deny_boards[$permission] : array(); |
@@ -1163,10 +1215,11 @@ discard block |
||
| 1163 | 1215 | |
| 1164 | 1216 | |
| 1165 | 1217 | // Moderators are free... |
| 1166 | - if (!allowedTo('moderate_board')) |
|
| 1167 | - $timeLimit = isset($timeOverrides[$error_type]) ? $timeOverrides[$error_type] : $modSettings['spamWaitTime']; |
|
| 1168 | - else |
|
| 1169 | - $timeLimit = 2; |
|
| 1218 | + if (!allowedTo('moderate_board')) { |
|
| 1219 | + $timeLimit = isset($timeOverrides[$error_type]) ? $timeOverrides[$error_type] : $modSettings['spamWaitTime']; |
|
| 1220 | + } else { |
|
| 1221 | + $timeLimit = 2; |
|
| 1222 | + } |
|
| 1170 | 1223 | |
| 1171 | 1224 | call_integration_hook('integrate_spam_protection', array(&$timeOverrides, &$timeLimit)); |
| 1172 | 1225 | |
@@ -1193,8 +1246,9 @@ discard block |
||
| 1193 | 1246 | if ($smcFunc['db_affected_rows']() != 1) |
| 1194 | 1247 | { |
| 1195 | 1248 | // Spammer! You only have to wait a *few* seconds! |
| 1196 | - if (!$only_return_result) |
|
| 1197 | - fatal_lang_error($error_type . '_WaitTime_broken', false, array($timeLimit)); |
|
| 1249 | + if (!$only_return_result) { |
|
| 1250 | + fatal_lang_error($error_type . '_WaitTime_broken', false, array($timeLimit)); |
|
| 1251 | + } |
|
| 1198 | 1252 | |
| 1199 | 1253 | return true; |
| 1200 | 1254 | } |
@@ -1212,11 +1266,13 @@ discard block |
||
| 1212 | 1266 | */ |
| 1213 | 1267 | function secureDirectory($path, $attachments = false) |
| 1214 | 1268 | { |
| 1215 | - if (empty($path)) |
|
| 1216 | - return 'empty_path'; |
|
| 1269 | + if (empty($path)) { |
|
| 1270 | + return 'empty_path'; |
|
| 1271 | + } |
|
| 1217 | 1272 | |
| 1218 | - if (!is_writable($path)) |
|
| 1219 | - return 'path_not_writable'; |
|
| 1273 | + if (!is_writable($path)) { |
|
| 1274 | + return 'path_not_writable'; |
|
| 1275 | + } |
|
| 1220 | 1276 | |
| 1221 | 1277 | $directoryname = basename($path); |
| 1222 | 1278 | |
@@ -1228,9 +1284,9 @@ discard block |
||
| 1228 | 1284 | |
| 1229 | 1285 | RemoveHandler .php .php3 .phtml .cgi .fcgi .pl .fpl .shtml'; |
| 1230 | 1286 | |
| 1231 | - if (file_exists($path . '/.htaccess')) |
|
| 1232 | - $errors[] = 'htaccess_exists'; |
|
| 1233 | - else |
|
| 1287 | + if (file_exists($path . '/.htaccess')) { |
|
| 1288 | + $errors[] = 'htaccess_exists'; |
|
| 1289 | + } else |
|
| 1234 | 1290 | { |
| 1235 | 1291 | $fh = @fopen($path . '/.htaccess', 'w'); |
| 1236 | 1292 | if ($fh) |
@@ -1243,9 +1299,9 @@ discard block |
||
| 1243 | 1299 | $errors[] = 'htaccess_cannot_create_file'; |
| 1244 | 1300 | } |
| 1245 | 1301 | |
| 1246 | - if (file_exists($path . '/index.php')) |
|
| 1247 | - $errors[] = 'index-php_exists'; |
|
| 1248 | - else |
|
| 1302 | + if (file_exists($path . '/index.php')) { |
|
| 1303 | + $errors[] = 'index-php_exists'; |
|
| 1304 | + } else |
|
| 1249 | 1305 | { |
| 1250 | 1306 | $fh = @fopen($path . '/index.php', 'w'); |
| 1251 | 1307 | if ($fh) |
@@ -1273,11 +1329,12 @@ discard block |
||
| 1273 | 1329 | $errors[] = 'index-php_cannot_create_file'; |
| 1274 | 1330 | } |
| 1275 | 1331 | |
| 1276 | - if (!empty($errors)) |
|
| 1277 | - return $errors; |
|
| 1278 | - else |
|
| 1279 | - return true; |
|
| 1280 | -} |
|
| 1332 | + if (!empty($errors)) { |
|
| 1333 | + return $errors; |
|
| 1334 | + } else { |
|
| 1335 | + return true; |
|
| 1336 | + } |
|
| 1337 | + } |
|
| 1281 | 1338 | |
| 1282 | 1339 | /** |
| 1283 | 1340 | * This sets the X-Frame-Options header. |
@@ -1290,14 +1347,16 @@ discard block |
||
| 1290 | 1347 | global $modSettings; |
| 1291 | 1348 | |
| 1292 | 1349 | $option = 'SAMEORIGIN'; |
| 1293 | - if (is_null($override) && !empty($modSettings['frame_security'])) |
|
| 1294 | - $option = $modSettings['frame_security']; |
|
| 1295 | - elseif (in_array($override, array('SAMEORIGIN', 'DENY'))) |
|
| 1296 | - $option = $override; |
|
| 1350 | + if (is_null($override) && !empty($modSettings['frame_security'])) { |
|
| 1351 | + $option = $modSettings['frame_security']; |
|
| 1352 | + } elseif (in_array($override, array('SAMEORIGIN', 'DENY'))) { |
|
| 1353 | + $option = $override; |
|
| 1354 | + } |
|
| 1297 | 1355 | |
| 1298 | 1356 | // Don't bother setting the header if we have disabled it. |
| 1299 | - if ($option == 'DISABLE') |
|
| 1300 | - return; |
|
| 1357 | + if ($option == 'DISABLE') { |
|
| 1358 | + return; |
|
| 1359 | + } |
|
| 1301 | 1360 | |
| 1302 | 1361 | // Finally set it. |
| 1303 | 1362 | header('x-frame-options: ' . $option); |
@@ -14,8 +14,9 @@ discard block |
||
| 14 | 14 | * @version 2.1 Beta 4 |
| 15 | 15 | */ |
| 16 | 16 | |
| 17 | -if (!defined('SMF')) |
|
| 17 | +if (!defined('SMF')) { |
|
| 18 | 18 | die('No direct access...'); |
| 19 | +} |
|
| 19 | 20 | |
| 20 | 21 | /** |
| 21 | 22 | * Ban center. The main entrance point for all ban center functions. |
@@ -120,10 +121,11 @@ discard block |
||
| 120 | 121 | } |
| 121 | 122 | |
| 122 | 123 | // Create a date string so we don't overload them with date info. |
| 123 | - if (preg_match('~%[AaBbCcDdeGghjmuYy](?:[^%]*%[AaBbCcDdeGghjmuYy])*~', $user_info['time_format'], $matches) == 0 || empty($matches[0])) |
|
| 124 | - $context['ban_time_format'] = $user_info['time_format']; |
|
| 125 | - else |
|
| 126 | - $context['ban_time_format'] = $matches[0]; |
|
| 124 | + if (preg_match('~%[AaBbCcDdeGghjmuYy](?:[^%]*%[AaBbCcDdeGghjmuYy])*~', $user_info['time_format'], $matches) == 0 || empty($matches[0])) { |
|
| 125 | + $context['ban_time_format'] = $user_info['time_format']; |
|
| 126 | + } else { |
|
| 127 | + $context['ban_time_format'] = $matches[0]; |
|
| 128 | + } |
|
| 127 | 129 | |
| 128 | 130 | $listOptions = array( |
| 129 | 131 | 'id' => 'ban_list', |
@@ -201,16 +203,19 @@ discard block |
||
| 201 | 203 | 'function' => function($rowData) use ($txt) |
| 202 | 204 | { |
| 203 | 205 | // This ban never expires...whahaha. |
| 204 | - if ($rowData['expire_time'] === null) |
|
| 205 | - return $txt['never']; |
|
| 206 | + if ($rowData['expire_time'] === null) { |
|
| 207 | + return $txt['never']; |
|
| 208 | + } |
|
| 206 | 209 | |
| 207 | 210 | // This ban has already expired. |
| 208 | - elseif ($rowData['expire_time'] < time()) |
|
| 209 | - return sprintf('<span class="red">%1$s</span>', $txt['ban_expired']); |
|
| 211 | + elseif ($rowData['expire_time'] < time()) { |
|
| 212 | + return sprintf('<span class="red">%1$s</span>', $txt['ban_expired']); |
|
| 213 | + } |
|
| 210 | 214 | |
| 211 | 215 | // Still need to wait a few days for this ban to expire. |
| 212 | - else |
|
| 213 | - return sprintf('%1$d %2$s', ceil(($rowData['expire_time'] - time()) / (60 * 60 * 24)), $txt['ban_days']); |
|
| 216 | + else { |
|
| 217 | + return sprintf('%1$d %2$s', ceil(($rowData['expire_time'] - time()) / (60 * 60 * 24)), $txt['ban_days']); |
|
| 218 | + } |
|
| 214 | 219 | }, |
| 215 | 220 | ), |
| 216 | 221 | 'sort' => array( |
@@ -320,8 +325,9 @@ discard block |
||
| 320 | 325 | ) |
| 321 | 326 | ); |
| 322 | 327 | $bans = array(); |
| 323 | - while ($row = $smcFunc['db_fetch_assoc']($request)) |
|
| 324 | - $bans[] = $row; |
|
| 328 | + while ($row = $smcFunc['db_fetch_assoc']($request)) { |
|
| 329 | + $bans[] = $row; |
|
| 330 | + } |
|
| 325 | 331 | |
| 326 | 332 | $smcFunc['db_free_result']($request); |
| 327 | 333 | |
@@ -363,8 +369,9 @@ discard block |
||
| 363 | 369 | { |
| 364 | 370 | global $txt, $modSettings, $context, $scripturl, $smcFunc, $sourcedir; |
| 365 | 371 | |
| 366 | - if ((isset($_POST['add_ban']) || isset($_POST['modify_ban']) || isset($_POST['remove_selection'])) && empty($context['ban_errors'])) |
|
| 367 | - BanEdit2(); |
|
| 372 | + if ((isset($_POST['add_ban']) || isset($_POST['modify_ban']) || isset($_POST['remove_selection'])) && empty($context['ban_errors'])) { |
|
| 373 | + BanEdit2(); |
|
| 374 | + } |
|
| 368 | 375 | |
| 369 | 376 | $ban_group_id = isset($context['ban']['id']) ? $context['ban']['id'] : (isset($_REQUEST['bg']) ? (int) $_REQUEST['bg'] : 0); |
| 370 | 377 | |
@@ -373,11 +380,10 @@ discard block |
||
| 373 | 380 | createToken('admin-bet'); |
| 374 | 381 | $context['form_url'] = $scripturl . '?action=admin;area=ban;sa=edit'; |
| 375 | 382 | |
| 376 | - if (!empty($context['ban_errors'])) |
|
| 377 | - foreach ($context['ban_errors'] as $error) |
|
| 383 | + if (!empty($context['ban_errors'])) { |
|
| 384 | + foreach ($context['ban_errors'] as $error) |
|
| 378 | 385 | $context['error_messages'][$error] = $txt[$error]; |
| 379 | - |
|
| 380 | - else |
|
| 386 | + } else |
|
| 381 | 387 | { |
| 382 | 388 | // If we're editing an existing ban, get it from the database. |
| 383 | 389 | if (!empty($ban_group_id)) |
@@ -413,12 +419,13 @@ discard block |
||
| 413 | 419 | 'data' => array( |
| 414 | 420 | 'function' => function($ban_item) use ($txt) |
| 415 | 421 | { |
| 416 | - if (in_array($ban_item['type'], array('ip', 'hostname', 'email'))) |
|
| 417 | - return '<strong>' . $txt[$ban_item['type']] . ':</strong> ' . $ban_item[$ban_item['type']]; |
|
| 418 | - elseif ($ban_item['type'] == 'user') |
|
| 419 | - return '<strong>' . $txt['username'] . ':</strong> ' . $ban_item['user']['link']; |
|
| 420 | - else |
|
| 421 | - return '<strong>' . $txt['unknown'] . ':</strong> ' . $ban_item['no_bantype_selected']; |
|
| 422 | + if (in_array($ban_item['type'], array('ip', 'hostname', 'email'))) { |
|
| 423 | + return '<strong>' . $txt[$ban_item['type']] . ':</strong> ' . $ban_item[$ban_item['type']]; |
|
| 424 | + } elseif ($ban_item['type'] == 'user') { |
|
| 425 | + return '<strong>' . $txt['username'] . ':</strong> ' . $ban_item['user']['link']; |
|
| 426 | + } else { |
|
| 427 | + return '<strong>' . $txt['unknown'] . ':</strong> ' . $ban_item['no_bantype_selected']; |
|
| 428 | + } |
|
| 422 | 429 | }, |
| 423 | 430 | 'style' => 'text-align: left;', |
| 424 | 431 | ), |
@@ -556,8 +563,9 @@ discard block |
||
| 556 | 563 | $context['ban']['from_user'] = true; |
| 557 | 564 | |
| 558 | 565 | // Would be nice if we could also ban the hostname. |
| 559 | - if ((preg_match('/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$/', $context['ban_suggestions']['main_ip']) == 1 || isValidIPv6($context['ban_suggestions']['main_ip'])) && empty($modSettings['disableHostnameLookup'])) |
|
| 560 | - $context['ban_suggestions']['hostname'] = host_from_ip($context['ban_suggestions']['main_ip']); |
|
| 566 | + if ((preg_match('/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}$/', $context['ban_suggestions']['main_ip']) == 1 || isValidIPv6($context['ban_suggestions']['main_ip'])) && empty($modSettings['disableHostnameLookup'])) { |
|
| 567 | + $context['ban_suggestions']['hostname'] = host_from_ip($context['ban_suggestions']['main_ip']); |
|
| 568 | + } |
|
| 561 | 569 | |
| 562 | 570 | $context['ban_suggestions']['other_ips'] = banLoadAdditionalIPs($context['ban_suggestions']['member']['id']); |
| 563 | 571 | } |
@@ -625,8 +633,9 @@ discard block |
||
| 625 | 633 | 'items_per_page' => $items_per_page, |
| 626 | 634 | ) |
| 627 | 635 | ); |
| 628 | - if ($smcFunc['db_num_rows']($request) == 0) |
|
| 629 | - fatal_lang_error('ban_not_found', false); |
|
| 636 | + if ($smcFunc['db_num_rows']($request) == 0) { |
|
| 637 | + fatal_lang_error('ban_not_found', false); |
|
| 638 | + } |
|
| 630 | 639 | |
| 631 | 640 | while ($row = $smcFunc['db_fetch_assoc']($request)) |
| 632 | 641 | { |
@@ -663,18 +672,15 @@ discard block |
||
| 663 | 672 | { |
| 664 | 673 | $ban_items[$row['id_ban']]['type'] = 'ip'; |
| 665 | 674 | $ban_items[$row['id_ban']]['ip'] = range2ip($row['ip_low'], $row['ip_high']); |
| 666 | - } |
|
| 667 | - elseif (!empty($row['hostname'])) |
|
| 675 | + } elseif (!empty($row['hostname'])) |
|
| 668 | 676 | { |
| 669 | 677 | $ban_items[$row['id_ban']]['type'] = 'hostname'; |
| 670 | 678 | $ban_items[$row['id_ban']]['hostname'] = str_replace('%', '*', $row['hostname']); |
| 671 | - } |
|
| 672 | - elseif (!empty($row['email_address'])) |
|
| 679 | + } elseif (!empty($row['email_address'])) |
|
| 673 | 680 | { |
| 674 | 681 | $ban_items[$row['id_ban']]['type'] = 'email'; |
| 675 | 682 | $ban_items[$row['id_ban']]['email'] = str_replace('%', '*', $row['email_address']); |
| 676 | - } |
|
| 677 | - elseif (!empty($row['id_member'])) |
|
| 683 | + } elseif (!empty($row['id_member'])) |
|
| 678 | 684 | { |
| 679 | 685 | $ban_items[$row['id_ban']]['type'] = 'user'; |
| 680 | 686 | $ban_items[$row['id_ban']]['user'] = array( |
@@ -740,9 +746,10 @@ discard block |
||
| 740 | 746 | $search_list += array('ips_in_messages' => 'banLoadAdditionalIPsMember', 'ips_in_errors' => 'banLoadAdditionalIPsError'); |
| 741 | 747 | |
| 742 | 748 | $return = array(); |
| 743 | - foreach ($search_list as $key => $callable) |
|
| 744 | - if (is_callable($callable)) |
|
| 749 | + foreach ($search_list as $key => $callable) { |
|
| 750 | + if (is_callable($callable)) |
|
| 745 | 751 | $return[$key] = call_user_func($callable, $member_id); |
| 752 | + } |
|
| 746 | 753 | |
| 747 | 754 | return $return; |
| 748 | 755 | } |
@@ -767,8 +774,9 @@ discard block |
||
| 767 | 774 | 'current_user' => $member_id, |
| 768 | 775 | ) |
| 769 | 776 | ); |
| 770 | - while ($row = $smcFunc['db_fetch_assoc']($request)) |
|
| 771 | - $message_ips[] = inet_dtop($row['poster_ip']); |
|
| 777 | + while ($row = $smcFunc['db_fetch_assoc']($request)) { |
|
| 778 | + $message_ips[] = inet_dtop($row['poster_ip']); |
|
| 779 | + } |
|
| 772 | 780 | $smcFunc['db_free_result']($request); |
| 773 | 781 | |
| 774 | 782 | return $message_ips; |
@@ -793,8 +801,9 @@ discard block |
||
| 793 | 801 | 'current_user' => $member_id, |
| 794 | 802 | ) |
| 795 | 803 | ); |
| 796 | - while ($row = $smcFunc['db_fetch_assoc']($request)) |
|
| 797 | - $error_ips[] = inet_dtop($row['ip']); |
|
| 804 | + while ($row = $smcFunc['db_fetch_assoc']($request)) { |
|
| 805 | + $error_ips[] = inet_dtop($row['ip']); |
|
| 806 | + } |
|
| 798 | 807 | $smcFunc['db_free_result']($request); |
| 799 | 808 | |
| 800 | 809 | return $error_ips; |
@@ -835,11 +844,13 @@ discard block |
||
| 835 | 844 | $ban_info['cannot']['login'] = !empty($ban_info['full_ban']) || empty($_POST['cannot_login']) ? 0 : 1; |
| 836 | 845 | |
| 837 | 846 | // Adding a new ban group |
| 838 | - if (empty($_REQUEST['bg'])) |
|
| 839 | - $ban_group_id = insertBanGroup($ban_info); |
|
| 847 | + if (empty($_REQUEST['bg'])) { |
|
| 848 | + $ban_group_id = insertBanGroup($ban_info); |
|
| 849 | + } |
|
| 840 | 850 | // Editing an existing ban group |
| 841 | - else |
|
| 842 | - $ban_group_id = updateBanGroup($ban_info); |
|
| 851 | + else { |
|
| 852 | + $ban_group_id = updateBanGroup($ban_info); |
|
| 853 | + } |
|
| 843 | 854 | |
| 844 | 855 | if (is_numeric($ban_group_id)) |
| 845 | 856 | { |
@@ -850,9 +861,10 @@ discard block |
||
| 850 | 861 | $context['ban'] = $ban_info; |
| 851 | 862 | } |
| 852 | 863 | |
| 853 | - if (isset($_POST['ban_suggestions'])) |
|
| 854 | - // @TODO: is $_REQUEST['bi'] ever set? |
|
| 864 | + if (isset($_POST['ban_suggestions'])) { |
|
| 865 | + // @TODO: is $_REQUEST['bi'] ever set? |
|
| 855 | 866 | $saved_triggers = saveTriggers($_POST['ban_suggestions'], $ban_info['id'], isset($_REQUEST['u']) ? (int) $_REQUEST['u'] : 0, isset($_REQUEST['bi']) ? (int) $_REQUEST['bi'] : 0); |
| 867 | + } |
|
| 856 | 868 | |
| 857 | 869 | // Something went wrong somewhere... Oh well, let's go back. |
| 858 | 870 | if (!empty($context['ban_errors'])) |
@@ -862,8 +874,9 @@ discard block |
||
| 862 | 874 | $context['ban_suggestions'] = array_merge($context['ban_suggestions'], getMemberData((int) $_REQUEST['u'])); |
| 863 | 875 | |
| 864 | 876 | // Not strictly necessary, but it's nice |
| 865 | - if (!empty($context['ban_suggestions']['member']['id'])) |
|
| 866 | - $context['ban_suggestions']['other_ips'] = banLoadAdditionalIPs($context['ban_suggestions']['member']['id']); |
|
| 877 | + if (!empty($context['ban_suggestions']['member']['id'])) { |
|
| 878 | + $context['ban_suggestions']['other_ips'] = banLoadAdditionalIPs($context['ban_suggestions']['member']['id']); |
|
| 879 | + } |
|
| 867 | 880 | return BanEdit(); |
| 868 | 881 | } |
| 869 | 882 | $context['ban_suggestions']['saved_triggers'] = !empty($saved_triggers) ? $saved_triggers : array(); |
@@ -910,10 +923,11 @@ discard block |
||
| 910 | 923 | |
| 911 | 924 | foreach ($suggestions as $key => $value) |
| 912 | 925 | { |
| 913 | - if (is_array($value)) |
|
| 914 | - $triggers[$key] = $value; |
|
| 915 | - else |
|
| 916 | - $triggers[$value] = !empty($_POST[$value]) ? $_POST[$value] : ''; |
|
| 926 | + if (is_array($value)) { |
|
| 927 | + $triggers[$key] = $value; |
|
| 928 | + } else { |
|
| 929 | + $triggers[$value] = !empty($_POST[$value]) ? $_POST[$value] : ''; |
|
| 930 | + } |
|
| 917 | 931 | } |
| 918 | 932 | |
| 919 | 933 | $ban_triggers = validateTriggers($triggers); |
@@ -921,16 +935,18 @@ discard block |
||
| 921 | 935 | // Time to save! |
| 922 | 936 | if (!empty($ban_triggers['ban_triggers']) && empty($context['ban_errors'])) |
| 923 | 937 | { |
| 924 | - if (empty($ban_id)) |
|
| 925 | - addTriggers($ban_group, $ban_triggers['ban_triggers'], $ban_triggers['log_info']); |
|
| 926 | - else |
|
| 927 | - updateTriggers($ban_id, $ban_group, array_shift($ban_triggers['ban_triggers']), $ban_triggers['log_info']); |
|
| 938 | + if (empty($ban_id)) { |
|
| 939 | + addTriggers($ban_group, $ban_triggers['ban_triggers'], $ban_triggers['log_info']); |
|
| 940 | + } else { |
|
| 941 | + updateTriggers($ban_id, $ban_group, array_shift($ban_triggers['ban_triggers']), $ban_triggers['log_info']); |
|
| 942 | + } |
|
| 943 | + } |
|
| 944 | + if (!empty($context['ban_errors'])) { |
|
| 945 | + return $triggers; |
|
| 946 | + } else { |
|
| 947 | + return false; |
|
| 948 | + } |
|
| 928 | 949 | } |
| 929 | - if (!empty($context['ban_errors'])) |
|
| 930 | - return $triggers; |
|
| 931 | - else |
|
| 932 | - return false; |
|
| 933 | -} |
|
| 934 | 950 | |
| 935 | 951 | /** |
| 936 | 952 | * This function removes a bunch of triggers based on ids |
@@ -944,14 +960,17 @@ discard block |
||
| 944 | 960 | { |
| 945 | 961 | global $smcFunc, $scripturl; |
| 946 | 962 | |
| 947 | - if ($group_id !== false) |
|
| 948 | - $group_id = (int) $group_id; |
|
| 963 | + if ($group_id !== false) { |
|
| 964 | + $group_id = (int) $group_id; |
|
| 965 | + } |
|
| 949 | 966 | |
| 950 | - if (empty($group_id) && empty($items_ids)) |
|
| 951 | - return false; |
|
| 967 | + if (empty($group_id) && empty($items_ids)) { |
|
| 968 | + return false; |
|
| 969 | + } |
|
| 952 | 970 | |
| 953 | - if (!is_array($items_ids)) |
|
| 954 | - $items_ids = array($items_ids); |
|
| 971 | + if (!is_array($items_ids)) { |
|
| 972 | + $items_ids = array($items_ids); |
|
| 973 | + } |
|
| 955 | 974 | |
| 956 | 975 | $log_info = array(); |
| 957 | 976 | $ban_items = array(); |
@@ -989,8 +1008,7 @@ discard block |
||
| 989 | 1008 | 'bantype' => ($is_range ? 'ip_range' : 'main_ip'), |
| 990 | 1009 | 'value' => $ban_items[$row['id_ban']]['ip'], |
| 991 | 1010 | ); |
| 992 | - } |
|
| 993 | - elseif (!empty($row['hostname'])) |
|
| 1011 | + } elseif (!empty($row['hostname'])) |
|
| 994 | 1012 | { |
| 995 | 1013 | $ban_items[$row['id_ban']]['type'] = 'hostname'; |
| 996 | 1014 | $ban_items[$row['id_ban']]['hostname'] = str_replace('%', '*', $row['hostname']); |
@@ -998,8 +1016,7 @@ discard block |
||
| 998 | 1016 | 'bantype' => 'hostname', |
| 999 | 1017 | 'value' => $row['hostname'], |
| 1000 | 1018 | ); |
| 1001 | - } |
|
| 1002 | - elseif (!empty($row['email_address'])) |
|
| 1019 | + } elseif (!empty($row['email_address'])) |
|
| 1003 | 1020 | { |
| 1004 | 1021 | $ban_items[$row['id_ban']]['type'] = 'email'; |
| 1005 | 1022 | $ban_items[$row['id_ban']]['email'] = str_replace('%', '*', $row['email_address']); |
@@ -1007,8 +1024,7 @@ discard block |
||
| 1007 | 1024 | 'bantype' => 'email', |
| 1008 | 1025 | 'value' => $ban_items[$row['id_ban']]['email'], |
| 1009 | 1026 | ); |
| 1010 | - } |
|
| 1011 | - elseif (!empty($row['id_member'])) |
|
| 1027 | + } elseif (!empty($row['id_member'])) |
|
| 1012 | 1028 | { |
| 1013 | 1029 | $ban_items[$row['id_ban']]['type'] = 'user'; |
| 1014 | 1030 | $ban_items[$row['id_ban']]['user'] = array( |
@@ -1041,8 +1057,7 @@ discard block |
||
| 1041 | 1057 | 'ban_group' => $group_id, |
| 1042 | 1058 | ) |
| 1043 | 1059 | ); |
| 1044 | - } |
|
| 1045 | - elseif (!empty($items_ids)) |
|
| 1060 | + } elseif (!empty($items_ids)) |
|
| 1046 | 1061 | { |
| 1047 | 1062 | $smcFunc['db_query']('', ' |
| 1048 | 1063 | DELETE FROM {db_prefix}ban_items |
@@ -1067,13 +1082,15 @@ discard block |
||
| 1067 | 1082 | { |
| 1068 | 1083 | global $smcFunc; |
| 1069 | 1084 | |
| 1070 | - if (!is_array($group_ids)) |
|
| 1071 | - $group_ids = array($group_ids); |
|
| 1085 | + if (!is_array($group_ids)) { |
|
| 1086 | + $group_ids = array($group_ids); |
|
| 1087 | + } |
|
| 1072 | 1088 | |
| 1073 | 1089 | $group_ids = array_unique($group_ids); |
| 1074 | 1090 | |
| 1075 | - if (empty($group_ids)) |
|
| 1076 | - return false; |
|
| 1091 | + if (empty($group_ids)) { |
|
| 1092 | + return false; |
|
| 1093 | + } |
|
| 1077 | 1094 | |
| 1078 | 1095 | $smcFunc['db_query']('', ' |
| 1079 | 1096 | DELETE FROM {db_prefix}ban_groups |
@@ -1097,21 +1114,23 @@ discard block |
||
| 1097 | 1114 | { |
| 1098 | 1115 | global $smcFunc; |
| 1099 | 1116 | |
| 1100 | - if (empty($ids)) |
|
| 1101 | - $smcFunc['db_query']('truncate_table', ' |
|
| 1117 | + if (empty($ids)) { |
|
| 1118 | + $smcFunc['db_query']('truncate_table', ' |
|
| 1102 | 1119 | TRUNCATE {db_prefix}log_banned', |
| 1103 | 1120 | array( |
| 1104 | 1121 | ) |
| 1105 | 1122 | ); |
| 1106 | - else |
|
| 1123 | + } else |
|
| 1107 | 1124 | { |
| 1108 | - if (!is_array($ids)) |
|
| 1109 | - $ids = array($ids); |
|
| 1125 | + if (!is_array($ids)) { |
|
| 1126 | + $ids = array($ids); |
|
| 1127 | + } |
|
| 1110 | 1128 | |
| 1111 | 1129 | $ids = array_unique($ids); |
| 1112 | 1130 | |
| 1113 | - if (empty($ids)) |
|
| 1114 | - return false; |
|
| 1131 | + if (empty($ids)) { |
|
| 1132 | + return false; |
|
| 1133 | + } |
|
| 1115 | 1134 | |
| 1116 | 1135 | $smcFunc['db_query']('', ' |
| 1117 | 1136 | DELETE FROM {db_prefix}log_banned |
@@ -1137,8 +1156,9 @@ discard block |
||
| 1137 | 1156 | { |
| 1138 | 1157 | global $context, $smcFunc; |
| 1139 | 1158 | |
| 1140 | - if (empty($triggers)) |
|
| 1141 | - $context['ban_erros'][] = 'ban_empty_triggers'; |
|
| 1159 | + if (empty($triggers)) { |
|
| 1160 | + $context['ban_erros'][] = 'ban_empty_triggers'; |
|
| 1161 | + } |
|
| 1142 | 1162 | |
| 1143 | 1163 | $ban_triggers = array(); |
| 1144 | 1164 | $log_info = array(); |
@@ -1147,39 +1167,39 @@ discard block |
||
| 1147 | 1167 | { |
| 1148 | 1168 | if (!empty($value)) |
| 1149 | 1169 | { |
| 1150 | - if ($key == 'member') |
|
| 1151 | - continue; |
|
| 1170 | + if ($key == 'member') { |
|
| 1171 | + continue; |
|
| 1172 | + } |
|
| 1152 | 1173 | |
| 1153 | 1174 | if ($key == 'main_ip') |
| 1154 | 1175 | { |
| 1155 | 1176 | $value = trim($value); |
| 1156 | 1177 | $ip_parts = ip2range($value); |
| 1157 | - if (!checkExistingTriggerIP($ip_parts, $value)) |
|
| 1158 | - $context['ban_erros'][] = 'invalid_ip'; |
|
| 1159 | - else |
|
| 1178 | + if (!checkExistingTriggerIP($ip_parts, $value)) { |
|
| 1179 | + $context['ban_erros'][] = 'invalid_ip'; |
|
| 1180 | + } else |
|
| 1160 | 1181 | { |
| 1161 | 1182 | $ban_triggers['main_ip'] = array( |
| 1162 | 1183 | 'ip_low' => $ip_parts['low'], |
| 1163 | 1184 | 'ip_high' => $ip_parts['high'] |
| 1164 | 1185 | ); |
| 1165 | 1186 | } |
| 1166 | - } |
|
| 1167 | - elseif ($key == 'hostname') |
|
| 1187 | + } elseif ($key == 'hostname') |
|
| 1168 | 1188 | { |
| 1169 | - if (preg_match('/[^\w.\-*]/', $value) == 1) |
|
| 1170 | - $context['ban_erros'][] = 'invalid_hostname'; |
|
| 1171 | - else |
|
| 1189 | + if (preg_match('/[^\w.\-*]/', $value) == 1) { |
|
| 1190 | + $context['ban_erros'][] = 'invalid_hostname'; |
|
| 1191 | + } else |
|
| 1172 | 1192 | { |
| 1173 | 1193 | // Replace the * wildcard by a MySQL wildcard %. |
| 1174 | 1194 | $value = substr(str_replace('*', '%', $value), 0, 255); |
| 1175 | 1195 | |
| 1176 | 1196 | $ban_triggers['hostname']['hostname'] = $value; |
| 1177 | 1197 | } |
| 1178 | - } |
|
| 1179 | - elseif ($key == 'email') |
|
| 1198 | + } elseif ($key == 'email') |
|
| 1180 | 1199 | { |
| 1181 | - if (preg_match('/[^\w.\-\+*@]/', $value) == 1) |
|
| 1182 | - $context['ban_erros'][] = 'invalid_email'; |
|
| 1200 | + if (preg_match('/[^\w.\-\+*@]/', $value) == 1) { |
|
| 1201 | + $context['ban_erros'][] = 'invalid_email'; |
|
| 1202 | + } |
|
| 1183 | 1203 | |
| 1184 | 1204 | // Check the user is not banning an admin. |
| 1185 | 1205 | $request = $smcFunc['db_query']('', ' |
@@ -1193,15 +1213,15 @@ discard block |
||
| 1193 | 1213 | 'email' => $value, |
| 1194 | 1214 | ) |
| 1195 | 1215 | ); |
| 1196 | - if ($smcFunc['db_num_rows']($request) != 0) |
|
| 1197 | - $context['ban_erros'][] = 'no_ban_admin'; |
|
| 1216 | + if ($smcFunc['db_num_rows']($request) != 0) { |
|
| 1217 | + $context['ban_erros'][] = 'no_ban_admin'; |
|
| 1218 | + } |
|
| 1198 | 1219 | $smcFunc['db_free_result']($request); |
| 1199 | 1220 | |
| 1200 | 1221 | $value = substr(strtolower(str_replace('*', '%', $value)), 0, 255); |
| 1201 | 1222 | |
| 1202 | 1223 | $ban_triggers['email']['email_address'] = $value; |
| 1203 | - } |
|
| 1204 | - elseif ($key == 'user') |
|
| 1224 | + } elseif ($key == 'user') |
|
| 1205 | 1225 | { |
| 1206 | 1226 | $user = preg_replace('~&#(\d{4,5}|[2-9]\d{2,4}|1[2-9]\d);~', '&#$1;', $smcFunc['htmlspecialchars']($value, ENT_QUOTES)); |
| 1207 | 1227 | |
@@ -1215,8 +1235,9 @@ discard block |
||
| 1215 | 1235 | 'username' => $user, |
| 1216 | 1236 | ) |
| 1217 | 1237 | ); |
| 1218 | - if ($smcFunc['db_num_rows']($request) == 0) |
|
| 1219 | - $context['ban_erros'][] = 'invalid_username'; |
|
| 1238 | + if ($smcFunc['db_num_rows']($request) == 0) { |
|
| 1239 | + $context['ban_erros'][] = 'invalid_username'; |
|
| 1240 | + } |
|
| 1220 | 1241 | list ($value, $isAdmin) = $smcFunc['db_fetch_row']($request); |
| 1221 | 1242 | $smcFunc['db_free_result']($request); |
| 1222 | 1243 | |
@@ -1224,25 +1245,25 @@ discard block |
||
| 1224 | 1245 | { |
| 1225 | 1246 | unset($value); |
| 1226 | 1247 | $context['ban_erros'][] = 'no_ban_admin'; |
| 1248 | + } else { |
|
| 1249 | + $ban_triggers['user']['id_member'] = $value; |
|
| 1227 | 1250 | } |
| 1228 | - else |
|
| 1229 | - $ban_triggers['user']['id_member'] = $value; |
|
| 1230 | - } |
|
| 1231 | - elseif (in_array($key, array('ips_in_messages', 'ips_in_errors'))) |
|
| 1251 | + } elseif (in_array($key, array('ips_in_messages', 'ips_in_errors'))) |
|
| 1232 | 1252 | { |
| 1233 | 1253 | // Special case, those two are arrays themselves |
| 1234 | 1254 | $values = array_unique($value); |
| 1235 | 1255 | // Don't add the main IP again. |
| 1236 | - if (isset($triggers['main_ip'])) |
|
| 1237 | - $values = array_diff($values, array($triggers['main_ip'])); |
|
| 1256 | + if (isset($triggers['main_ip'])) { |
|
| 1257 | + $values = array_diff($values, array($triggers['main_ip'])); |
|
| 1258 | + } |
|
| 1238 | 1259 | unset($value); |
| 1239 | 1260 | foreach ($values as $val) |
| 1240 | 1261 | { |
| 1241 | 1262 | $val = trim($val); |
| 1242 | 1263 | $ip_parts = ip2range($val); |
| 1243 | - if (!checkExistingTriggerIP($ip_parts, $val)) |
|
| 1244 | - $context['ban_erros'][] = 'invalid_ip'; |
|
| 1245 | - else |
|
| 1264 | + if (!checkExistingTriggerIP($ip_parts, $val)) { |
|
| 1265 | + $context['ban_erros'][] = 'invalid_ip'; |
|
| 1266 | + } else |
|
| 1246 | 1267 | { |
| 1247 | 1268 | $ban_triggers[$key][] = array( |
| 1248 | 1269 | 'ip_low' => $ip_parts['low'], |
@@ -1255,15 +1276,16 @@ discard block |
||
| 1255 | 1276 | ); |
| 1256 | 1277 | } |
| 1257 | 1278 | } |
| 1279 | + } else { |
|
| 1280 | + $context['ban_erros'][] = 'no_bantype_selected'; |
|
| 1258 | 1281 | } |
| 1259 | - else |
|
| 1260 | - $context['ban_erros'][] = 'no_bantype_selected'; |
|
| 1261 | 1282 | |
| 1262 | - if (isset($value) && !is_array($value)) |
|
| 1263 | - $log_info[] = array( |
|
| 1283 | + if (isset($value) && !is_array($value)) { |
|
| 1284 | + $log_info[] = array( |
|
| 1264 | 1285 | 'value' => $value, |
| 1265 | 1286 | 'bantype' => $key, |
| 1266 | 1287 | ); |
| 1288 | + } |
|
| 1267 | 1289 | } |
| 1268 | 1290 | } |
| 1269 | 1291 | return array('ban_triggers' => $ban_triggers, 'log_info' => $log_info); |
@@ -1283,8 +1305,9 @@ discard block |
||
| 1283 | 1305 | { |
| 1284 | 1306 | global $smcFunc, $context; |
| 1285 | 1307 | |
| 1286 | - if (empty($group_id)) |
|
| 1287 | - $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1308 | + if (empty($group_id)) { |
|
| 1309 | + $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1310 | + } |
|
| 1288 | 1311 | |
| 1289 | 1312 | // Preset all values that are required. |
| 1290 | 1313 | $values = array( |
@@ -1309,18 +1332,21 @@ discard block |
||
| 1309 | 1332 | foreach ($triggers as $key => $trigger) |
| 1310 | 1333 | { |
| 1311 | 1334 | // Exceptions, exceptions, exceptions...always exceptions... :P |
| 1312 | - if (in_array($key, array('ips_in_messages', 'ips_in_errors'))) |
|
| 1313 | - foreach ($trigger as $real_trigger) |
|
| 1335 | + if (in_array($key, array('ips_in_messages', 'ips_in_errors'))) { |
|
| 1336 | + foreach ($trigger as $real_trigger) |
|
| 1314 | 1337 | $insertTriggers[] = array_merge($values, $real_trigger); |
| 1315 | - else |
|
| 1316 | - $insertTriggers[] = array_merge($values, $trigger); |
|
| 1338 | + } else { |
|
| 1339 | + $insertTriggers[] = array_merge($values, $trigger); |
|
| 1340 | + } |
|
| 1317 | 1341 | } |
| 1318 | 1342 | |
| 1319 | - if (empty($insertTriggers)) |
|
| 1320 | - $context['ban_errors'][] = 'ban_no_triggers'; |
|
| 1343 | + if (empty($insertTriggers)) { |
|
| 1344 | + $context['ban_errors'][] = 'ban_no_triggers'; |
|
| 1345 | + } |
|
| 1321 | 1346 | |
| 1322 | - if (!empty($context['ban_errors'])) |
|
| 1323 | - return false; |
|
| 1347 | + if (!empty($context['ban_errors'])) { |
|
| 1348 | + return false; |
|
| 1349 | + } |
|
| 1324 | 1350 | |
| 1325 | 1351 | $smcFunc['db_insert']('', |
| 1326 | 1352 | '{db_prefix}ban_items', |
@@ -1348,15 +1374,19 @@ discard block |
||
| 1348 | 1374 | { |
| 1349 | 1375 | global $smcFunc, $context; |
| 1350 | 1376 | |
| 1351 | - if (empty($ban_item)) |
|
| 1352 | - $context['ban_errors'][] = 'ban_ban_item_empty'; |
|
| 1353 | - if (empty($group_id)) |
|
| 1354 | - $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1355 | - if (empty($trigger)) |
|
| 1356 | - $context['ban_errors'][] = 'ban_no_triggers'; |
|
| 1377 | + if (empty($ban_item)) { |
|
| 1378 | + $context['ban_errors'][] = 'ban_ban_item_empty'; |
|
| 1379 | + } |
|
| 1380 | + if (empty($group_id)) { |
|
| 1381 | + $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1382 | + } |
|
| 1383 | + if (empty($trigger)) { |
|
| 1384 | + $context['ban_errors'][] = 'ban_no_triggers'; |
|
| 1385 | + } |
|
| 1357 | 1386 | |
| 1358 | - if (!empty($context['ban_errors'])) |
|
| 1359 | - return; |
|
| 1387 | + if (!empty($context['ban_errors'])) { |
|
| 1388 | + return; |
|
| 1389 | + } |
|
| 1360 | 1390 | |
| 1361 | 1391 | // Preset all values that are required. |
| 1362 | 1392 | $values = array( |
@@ -1397,8 +1427,9 @@ discard block |
||
| 1397 | 1427 | */ |
| 1398 | 1428 | function logTriggersUpdates($logs, $new = true, $removal = false) |
| 1399 | 1429 | { |
| 1400 | - if (empty($logs)) |
|
| 1401 | - return; |
|
| 1430 | + if (empty($logs)) { |
|
| 1431 | + return; |
|
| 1432 | + } |
|
| 1402 | 1433 | |
| 1403 | 1434 | $log_name_map = array( |
| 1404 | 1435 | 'main_ip' => 'ip_range', |
@@ -1409,14 +1440,15 @@ discard block |
||
| 1409 | 1440 | ); |
| 1410 | 1441 | |
| 1411 | 1442 | // Log the addion of the ban entries into the moderation log. |
| 1412 | - foreach ($logs as $log) |
|
| 1413 | - logAction('ban' . ($removal == true ? 'remove' : ''), array( |
|
| 1443 | + foreach ($logs as $log) { |
|
| 1444 | + logAction('ban' . ($removal == true ? 'remove' : ''), array( |
|
| 1414 | 1445 | $log_name_map[$log['bantype']] => $log['value'], |
| 1415 | 1446 | 'new' => empty($new) ? 0 : 1, |
| 1416 | 1447 | 'remove' => empty($removal) ? 0 : 1, |
| 1417 | 1448 | 'type' => $log['bantype'], |
| 1418 | 1449 | )); |
| 1419 | -} |
|
| 1450 | + } |
|
| 1451 | + } |
|
| 1420 | 1452 | |
| 1421 | 1453 | /** |
| 1422 | 1454 | * Updates an existing ban group |
@@ -1430,12 +1462,15 @@ discard block |
||
| 1430 | 1462 | { |
| 1431 | 1463 | global $smcFunc, $context; |
| 1432 | 1464 | |
| 1433 | - if (empty($ban_info['name'])) |
|
| 1434 | - $context['ban_errors'][] = 'ban_name_empty'; |
|
| 1435 | - if (empty($ban_info['id'])) |
|
| 1436 | - $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1437 | - if (empty($ban_info['cannot']['access']) && empty($ban_info['cannot']['register']) && empty($ban_info['cannot']['post']) && empty($ban_info['cannot']['login'])) |
|
| 1438 | - $context['ban_errors'][] = 'ban_unknown_restriction_type'; |
|
| 1465 | + if (empty($ban_info['name'])) { |
|
| 1466 | + $context['ban_errors'][] = 'ban_name_empty'; |
|
| 1467 | + } |
|
| 1468 | + if (empty($ban_info['id'])) { |
|
| 1469 | + $context['ban_errors'][] = 'ban_id_empty'; |
|
| 1470 | + } |
|
| 1471 | + if (empty($ban_info['cannot']['access']) && empty($ban_info['cannot']['register']) && empty($ban_info['cannot']['post']) && empty($ban_info['cannot']['login'])) { |
|
| 1472 | + $context['ban_errors'][] = 'ban_unknown_restriction_type'; |
|
| 1473 | + } |
|
| 1439 | 1474 | |
| 1440 | 1475 | if (!empty($ban_info['id'])) |
| 1441 | 1476 | { |
@@ -1450,8 +1485,9 @@ discard block |
||
| 1450 | 1485 | ) |
| 1451 | 1486 | ); |
| 1452 | 1487 | |
| 1453 | - if ($smcFunc['db_num_rows']($request) == 0) |
|
| 1454 | - $context['ban_errors'][] = 'ban_not_found'; |
|
| 1488 | + if ($smcFunc['db_num_rows']($request) == 0) { |
|
| 1489 | + $context['ban_errors'][] = 'ban_not_found'; |
|
| 1490 | + } |
|
| 1455 | 1491 | $smcFunc['db_free_result']($request); |
| 1456 | 1492 | } |
| 1457 | 1493 | |
@@ -1469,13 +1505,15 @@ discard block |
||
| 1469 | 1505 | 'new_ban_name' => $ban_info['name'], |
| 1470 | 1506 | ) |
| 1471 | 1507 | ); |
| 1472 | - if ($smcFunc['db_num_rows']($request) != 0) |
|
| 1473 | - $context['ban_errors'][] = 'ban_name_exists'; |
|
| 1508 | + if ($smcFunc['db_num_rows']($request) != 0) { |
|
| 1509 | + $context['ban_errors'][] = 'ban_name_exists'; |
|
| 1510 | + } |
|
| 1474 | 1511 | $smcFunc['db_free_result']($request); |
| 1475 | 1512 | } |
| 1476 | 1513 | |
| 1477 | - if (!empty($context['ban_errors'])) |
|
| 1478 | - return $ban_info['id']; |
|
| 1514 | + if (!empty($context['ban_errors'])) { |
|
| 1515 | + return $ban_info['id']; |
|
| 1516 | + } |
|
| 1479 | 1517 | |
| 1480 | 1518 | $smcFunc['db_query']('', ' |
| 1481 | 1519 | UPDATE {db_prefix}ban_groups |
@@ -1519,10 +1557,12 @@ discard block |
||
| 1519 | 1557 | { |
| 1520 | 1558 | global $smcFunc, $context; |
| 1521 | 1559 | |
| 1522 | - if (empty($ban_info['name'])) |
|
| 1523 | - $context['ban_errors'][] = 'ban_name_empty'; |
|
| 1524 | - if (empty($ban_info['cannot']['access']) && empty($ban_info['cannot']['register']) && empty($ban_info['cannot']['post']) && empty($ban_info['cannot']['login'])) |
|
| 1525 | - $context['ban_errors'][] = 'ban_unknown_restriction_type'; |
|
| 1560 | + if (empty($ban_info['name'])) { |
|
| 1561 | + $context['ban_errors'][] = 'ban_name_empty'; |
|
| 1562 | + } |
|
| 1563 | + if (empty($ban_info['cannot']['access']) && empty($ban_info['cannot']['register']) && empty($ban_info['cannot']['post']) && empty($ban_info['cannot']['login'])) { |
|
| 1564 | + $context['ban_errors'][] = 'ban_unknown_restriction_type'; |
|
| 1565 | + } |
|
| 1526 | 1566 | |
| 1527 | 1567 | if (!empty($ban_info['name'])) |
| 1528 | 1568 | { |
@@ -1537,13 +1577,15 @@ discard block |
||
| 1537 | 1577 | ) |
| 1538 | 1578 | ); |
| 1539 | 1579 | |
| 1540 | - if ($smcFunc['db_num_rows']($request) == 1) |
|
| 1541 | - $context['ban_errors'][] = 'ban_name_exists'; |
|
| 1580 | + if ($smcFunc['db_num_rows']($request) == 1) { |
|
| 1581 | + $context['ban_errors'][] = 'ban_name_exists'; |
|
| 1582 | + } |
|
| 1542 | 1583 | $smcFunc['db_free_result']($request); |
| 1543 | 1584 | } |
| 1544 | 1585 | |
| 1545 | - if (!empty($context['ban_errors'])) |
|
| 1546 | - return; |
|
| 1586 | + if (!empty($context['ban_errors'])) { |
|
| 1587 | + return; |
|
| 1588 | + } |
|
| 1547 | 1589 | |
| 1548 | 1590 | // Yes yes, we're ready to add now. |
| 1549 | 1591 | $ban_info['id'] = $smcFunc['db_insert']('', |
@@ -1560,8 +1602,9 @@ discard block |
||
| 1560 | 1602 | 1 |
| 1561 | 1603 | ); |
| 1562 | 1604 | |
| 1563 | - if (empty($ban_info['id'])) |
|
| 1564 | - $context['ban_errors'][] = 'impossible_insert_new_bangroup'; |
|
| 1605 | + if (empty($ban_info['id'])) { |
|
| 1606 | + $context['ban_errors'][] = 'impossible_insert_new_bangroup'; |
|
| 1607 | + } |
|
| 1565 | 1608 | |
| 1566 | 1609 | return $ban_info['id']; |
| 1567 | 1610 | } |
@@ -1586,24 +1629,24 @@ discard block |
||
| 1586 | 1629 | $ban_group = isset($_REQUEST['bg']) ? (int) $_REQUEST['bg'] : 0; |
| 1587 | 1630 | $ban_id = isset($_REQUEST['bi']) ? (int) $_REQUEST['bi'] : 0; |
| 1588 | 1631 | |
| 1589 | - if (empty($ban_group)) |
|
| 1590 | - fatal_lang_error('ban_not_found', false); |
|
| 1632 | + if (empty($ban_group)) { |
|
| 1633 | + fatal_lang_error('ban_not_found', false); |
|
| 1634 | + } |
|
| 1591 | 1635 | |
| 1592 | 1636 | if (isset($_POST['add_new_trigger']) && !empty($_POST['ban_suggestions'])) |
| 1593 | 1637 | { |
| 1594 | 1638 | saveTriggers($_POST['ban_suggestions'], $ban_group, 0, $ban_id); |
| 1595 | 1639 | redirectexit('action=admin;area=ban;sa=edit' . (!empty($ban_group) ? ';bg=' . $ban_group : '')); |
| 1596 | - } |
|
| 1597 | - elseif (isset($_POST['edit_trigger']) && !empty($_POST['ban_suggestions'])) |
|
| 1640 | + } elseif (isset($_POST['edit_trigger']) && !empty($_POST['ban_suggestions'])) |
|
| 1598 | 1641 | { |
| 1599 | 1642 | // The first replaces the old one, the others are added new (simplification, otherwise it would require another query and some work...) |
| 1600 | 1643 | saveTriggers(array_shift($_POST['ban_suggestions']), $ban_group, 0, $ban_id); |
| 1601 | - if (!empty($_POST['ban_suggestions'])) |
|
| 1602 | - saveTriggers($_POST['ban_suggestions'], $ban_group); |
|
| 1644 | + if (!empty($_POST['ban_suggestions'])) { |
|
| 1645 | + saveTriggers($_POST['ban_suggestions'], $ban_group); |
|
| 1646 | + } |
|
| 1603 | 1647 | |
| 1604 | 1648 | redirectexit('action=admin;area=ban;sa=edit' . (!empty($ban_group) ? ';bg=' . $ban_group : '')); |
| 1605 | - } |
|
| 1606 | - elseif (isset($_POST['edit_trigger'])) |
|
| 1649 | + } elseif (isset($_POST['edit_trigger'])) |
|
| 1607 | 1650 | { |
| 1608 | 1651 | removeBanTriggers($ban_id); |
| 1609 | 1652 | redirectexit('action=admin;area=ban;sa=edit' . (!empty($ban_group) ? ';bg=' . $ban_group : '')); |
@@ -1634,8 +1677,7 @@ discard block |
||
| 1634 | 1677 | ), |
| 1635 | 1678 | 'is_new' => true, |
| 1636 | 1679 | ); |
| 1637 | - } |
|
| 1638 | - else |
|
| 1680 | + } else |
|
| 1639 | 1681 | { |
| 1640 | 1682 | $request = $smcFunc['db_query']('', ' |
| 1641 | 1683 | SELECT |
@@ -1652,8 +1694,9 @@ discard block |
||
| 1652 | 1694 | 'ban_group' => $ban_group, |
| 1653 | 1695 | ) |
| 1654 | 1696 | ); |
| 1655 | - if ($smcFunc['db_num_rows']($request) == 0) |
|
| 1656 | - fatal_lang_error('ban_not_found', false); |
|
| 1697 | + if ($smcFunc['db_num_rows']($request) == 0) { |
|
| 1698 | + fatal_lang_error('ban_not_found', false); |
|
| 1699 | + } |
|
| 1657 | 1700 | $row = $smcFunc['db_fetch_assoc']($request); |
| 1658 | 1701 | $smcFunc['db_free_result']($request); |
| 1659 | 1702 | |
@@ -1702,8 +1745,9 @@ discard block |
||
| 1702 | 1745 | removeBanTriggers($_POST['remove']); |
| 1703 | 1746 | |
| 1704 | 1747 | // Rehabilitate some members. |
| 1705 | - if ($_REQUEST['entity'] == 'member') |
|
| 1706 | - updateBanMembers(); |
|
| 1748 | + if ($_REQUEST['entity'] == 'member') { |
|
| 1749 | + updateBanMembers(); |
|
| 1750 | + } |
|
| 1707 | 1751 | |
| 1708 | 1752 | // Make sure the ban cache is refreshed. |
| 1709 | 1753 | updateSettings(array('banLastUpdated' => time())); |
@@ -1816,8 +1860,7 @@ discard block |
||
| 1816 | 1860 | 'default' => 'bi.ip_low, bi.ip_high, bi.ip_low', |
| 1817 | 1861 | 'reverse' => 'bi.ip_low DESC, bi.ip_high DESC', |
| 1818 | 1862 | ); |
| 1819 | - } |
|
| 1820 | - elseif ($context['selected_entity'] === 'hostname') |
|
| 1863 | + } elseif ($context['selected_entity'] === 'hostname') |
|
| 1821 | 1864 | { |
| 1822 | 1865 | $listOptions['columns']['banned_entity']['data'] = array( |
| 1823 | 1866 | 'function' => function($rowData) use ($smcFunc) |
@@ -1829,8 +1872,7 @@ discard block |
||
| 1829 | 1872 | 'default' => 'bi.hostname', |
| 1830 | 1873 | 'reverse' => 'bi.hostname DESC', |
| 1831 | 1874 | ); |
| 1832 | - } |
|
| 1833 | - elseif ($context['selected_entity'] === 'email') |
|
| 1875 | + } elseif ($context['selected_entity'] === 'email') |
|
| 1834 | 1876 | { |
| 1835 | 1877 | $listOptions['columns']['banned_entity']['data'] = array( |
| 1836 | 1878 | 'function' => function($rowData) use ($smcFunc) |
@@ -1842,8 +1884,7 @@ discard block |
||
| 1842 | 1884 | 'default' => 'bi.email_address', |
| 1843 | 1885 | 'reverse' => 'bi.email_address DESC', |
| 1844 | 1886 | ); |
| 1845 | - } |
|
| 1846 | - elseif ($context['selected_entity'] === 'member') |
|
| 1887 | + } elseif ($context['selected_entity'] === 'member') |
|
| 1847 | 1888 | { |
| 1848 | 1889 | $listOptions['columns']['banned_entity']['data'] = array( |
| 1849 | 1890 | 'sprintf' => array( |
@@ -1907,8 +1948,9 @@ discard block |
||
| 1907 | 1948 | ) |
| 1908 | 1949 | ); |
| 1909 | 1950 | $ban_triggers = array(); |
| 1910 | - while ($row = $smcFunc['db_fetch_assoc']($request)) |
|
| 1911 | - $ban_triggers[] = $row; |
|
| 1951 | + while ($row = $smcFunc['db_fetch_assoc']($request)) { |
|
| 1952 | + $ban_triggers[] = $row; |
|
| 1953 | + } |
|
| 1912 | 1954 | $smcFunc['db_free_result']($request); |
| 1913 | 1955 | |
| 1914 | 1956 | return $ban_triggers; |
@@ -1964,8 +2006,9 @@ discard block |
||
| 1964 | 2006 | validateToken('admin-bl'); |
| 1965 | 2007 | |
| 1966 | 2008 | // 'Delete all entries' button was pressed. |
| 1967 | - if (!empty($_POST['removeAll'])) |
|
| 1968 | - removeBanLogs(); |
|
| 2009 | + if (!empty($_POST['removeAll'])) { |
|
| 2010 | + removeBanLogs(); |
|
| 2011 | + } |
|
| 1969 | 2012 | // 'Delete selection' button was pressed. |
| 1970 | 2013 | else |
| 1971 | 2014 | { |
@@ -2174,12 +2217,15 @@ discard block |
||
| 2174 | 2217 | $low = inet_dtop($low); |
| 2175 | 2218 | $high = inet_dtop($high); |
| 2176 | 2219 | |
| 2177 | - if ($low == '255.255.255.255') return 'unknown'; |
|
| 2178 | - if ($low == $high) |
|
| 2179 | - return $low; |
|
| 2180 | - else |
|
| 2181 | - return $low . '-' . $high; |
|
| 2182 | -} |
|
| 2220 | + if ($low == '255.255.255.255') { |
|
| 2221 | + return 'unknown'; |
|
| 2222 | + } |
|
| 2223 | + if ($low == $high) { |
|
| 2224 | + return $low; |
|
| 2225 | + } else { |
|
| 2226 | + return $low . '-' . $high; |
|
| 2227 | + } |
|
| 2228 | + } |
|
| 2183 | 2229 | |
| 2184 | 2230 | /** |
| 2185 | 2231 | * Checks whether a given IP range already exists in the trigger list. |
@@ -2255,15 +2301,17 @@ discard block |
||
| 2255 | 2301 | $memberEmailWild = array(); |
| 2256 | 2302 | while ($row = $smcFunc['db_fetch_assoc']($request)) |
| 2257 | 2303 | { |
| 2258 | - if ($row['id_member']) |
|
| 2259 | - $memberIDs[$row['id_member']] = $row['id_member']; |
|
| 2304 | + if ($row['id_member']) { |
|
| 2305 | + $memberIDs[$row['id_member']] = $row['id_member']; |
|
| 2306 | + } |
|
| 2260 | 2307 | if ($row['email_address']) |
| 2261 | 2308 | { |
| 2262 | 2309 | // Does it have a wildcard - if so we can't do a IN on it. |
| 2263 | - if (strpos($row['email_address'], '%') !== false) |
|
| 2264 | - $memberEmailWild[$row['email_address']] = $row['email_address']; |
|
| 2265 | - else |
|
| 2266 | - $memberEmails[$row['email_address']] = $row['email_address']; |
|
| 2310 | + if (strpos($row['email_address'], '%') !== false) { |
|
| 2311 | + $memberEmailWild[$row['email_address']] = $row['email_address']; |
|
| 2312 | + } else { |
|
| 2313 | + $memberEmails[$row['email_address']] = $row['email_address']; |
|
| 2314 | + } |
|
| 2267 | 2315 | } |
| 2268 | 2316 | } |
| 2269 | 2317 | $smcFunc['db_free_result']($request); |
@@ -2314,14 +2362,15 @@ discard block |
||
| 2314 | 2362 | } |
| 2315 | 2363 | |
| 2316 | 2364 | // We welcome our new members in the realm of the banned. |
| 2317 | - if (!empty($newMembers)) |
|
| 2318 | - $smcFunc['db_query']('', ' |
|
| 2365 | + if (!empty($newMembers)) { |
|
| 2366 | + $smcFunc['db_query']('', ' |
|
| 2319 | 2367 | DELETE FROM {db_prefix}log_online |
| 2320 | 2368 | WHERE id_member IN ({array_int:new_banned_members})', |
| 2321 | 2369 | array( |
| 2322 | 2370 | 'new_banned_members' => $newMembers, |
| 2323 | 2371 | ) |
| 2324 | 2372 | ); |
| 2373 | + } |
|
| 2325 | 2374 | |
| 2326 | 2375 | // Find members that are wrongfully marked as banned. |
| 2327 | 2376 | $request = $smcFunc['db_query']('', ' |
@@ -2348,9 +2397,10 @@ discard block |
||
| 2348 | 2397 | } |
| 2349 | 2398 | $smcFunc['db_free_result']($request); |
| 2350 | 2399 | |
| 2351 | - if (!empty($updates)) |
|
| 2352 | - foreach ($updates as $newStatus => $members) |
|
| 2400 | + if (!empty($updates)) { |
|
| 2401 | + foreach ($updates as $newStatus => $members) |
|
| 2353 | 2402 | updateMemberData($members, array('is_activated' => $newStatus)); |
| 2403 | + } |
|
| 2354 | 2404 | |
| 2355 | 2405 | // Update the latest member and our total members as banning may change them. |
| 2356 | 2406 | updateStats('member'); |
@@ -283,11 +283,11 @@ discard block |
||
| 283 | 283 | if (removeItems == 0) |
| 284 | 284 | { |
| 285 | 285 | e.preventDefault(); |
| 286 | - return alert("'. $txt['select_item_check'] .'"); |
|
| 286 | + return alert("'. $txt['select_item_check'] . '"); |
|
| 287 | 287 | } |
| 288 | 288 | |
| 289 | 289 | |
| 290 | - return confirm("'. $txt['ban_remove_selected_confirm'] .'"); |
|
| 290 | + return confirm("'. $txt['ban_remove_selected_confirm'] . '"); |
|
| 291 | 291 | });', |
| 292 | 292 | ); |
| 293 | 293 | |
@@ -488,7 +488,7 @@ discard block |
||
| 488 | 488 | 'value' => ' |
| 489 | 489 | <input type="submit" name="remove_selection" value="' . $txt['ban_remove_selected_triggers'] . '" class="button"> <a class="button" |
| 490 | 490 | href="' . |
| 491 | - $scripturl . '?action=admin;area=ban;sa=edittrigger;bg=' . $ban_group_id . '">' . $txt['ban_add_trigger'] . '</a>', |
|
| 491 | + $scripturl . '?action=admin;area=ban;sa=edittrigger;bg=' . $ban_group_id . '">' . $txt['ban_add_trigger'] . '</a>', |
|
| 492 | 492 | 'style' => 'text-align: right;', |
| 493 | 493 | ), |
| 494 | 494 | array( |
@@ -508,11 +508,11 @@ discard block |
||
| 508 | 508 | if (removeItems == 0) |
| 509 | 509 | { |
| 510 | 510 | e.preventDefault(); |
| 511 | - return alert("'. $txt['select_item_check'] .'"); |
|
| 511 | + return alert("'. $txt['select_item_check'] . '"); |
|
| 512 | 512 | } |
| 513 | 513 | |
| 514 | 514 | |
| 515 | - return confirm("'. $txt['ban_remove_selected_confirm'] .'"); |
|
| 515 | + return confirm("'. $txt['ban_remove_selected_confirm'] . '"); |
|
| 516 | 516 | });', |
| 517 | 517 | ); |
| 518 | 518 | createList($listOptions); |