@@ -22,288 +22,288 @@ |
||
| 22 | 22 | */ |
| 23 | 23 | class RequestValidationHelper |
| 24 | 24 | { |
| 25 | - /** @var IBanHelper */ |
|
| 26 | - private $banHelper; |
|
| 27 | - /** @var Request */ |
|
| 28 | - private $request; |
|
| 29 | - private $emailConfirmation; |
|
| 30 | - /** @var PdoDatabase */ |
|
| 31 | - private $database; |
|
| 32 | - /** @var IAntiSpoofProvider */ |
|
| 33 | - private $antiSpoofProvider; |
|
| 34 | - /** @var IXffTrustProvider */ |
|
| 35 | - private $xffTrustProvider; |
|
| 36 | - /** @var HttpHelper */ |
|
| 37 | - private $httpHelper; |
|
| 38 | - /** |
|
| 39 | - * @var string |
|
| 40 | - */ |
|
| 41 | - private $mediawikiApiEndpoint; |
|
| 42 | - private $titleBlacklistEnabled; |
|
| 43 | - /** |
|
| 44 | - * @var TorExitProvider |
|
| 45 | - */ |
|
| 46 | - private $torExitProvider; |
|
| 47 | - |
|
| 48 | - /** |
|
| 49 | - * Summary of __construct |
|
| 50 | - * |
|
| 51 | - * @param IBanHelper $banHelper |
|
| 52 | - * @param Request $request |
|
| 53 | - * @param string $emailConfirmation |
|
| 54 | - * @param PdoDatabase $database |
|
| 55 | - * @param IAntiSpoofProvider $antiSpoofProvider |
|
| 56 | - * @param IXffTrustProvider $xffTrustProvider |
|
| 57 | - * @param HttpHelper $httpHelper |
|
| 58 | - * @param string $mediawikiApiEndpoint |
|
| 59 | - * @param boolean $titleBlacklistEnabled |
|
| 60 | - * @param TorExitProvider $torExitProvider |
|
| 61 | - */ |
|
| 62 | - public function __construct( |
|
| 63 | - IBanHelper $banHelper, |
|
| 64 | - Request $request, |
|
| 65 | - $emailConfirmation, |
|
| 66 | - PdoDatabase $database, |
|
| 67 | - IAntiSpoofProvider $antiSpoofProvider, |
|
| 68 | - IXffTrustProvider $xffTrustProvider, |
|
| 69 | - HttpHelper $httpHelper, |
|
| 70 | - $mediawikiApiEndpoint, |
|
| 71 | - $titleBlacklistEnabled, |
|
| 72 | - TorExitProvider $torExitProvider |
|
| 73 | - ) { |
|
| 74 | - $this->banHelper = $banHelper; |
|
| 75 | - $this->request = $request; |
|
| 76 | - $this->emailConfirmation = $emailConfirmation; |
|
| 77 | - $this->database = $database; |
|
| 78 | - $this->antiSpoofProvider = $antiSpoofProvider; |
|
| 79 | - $this->xffTrustProvider = $xffTrustProvider; |
|
| 80 | - $this->httpHelper = $httpHelper; |
|
| 81 | - $this->mediawikiApiEndpoint = $mediawikiApiEndpoint; |
|
| 82 | - $this->titleBlacklistEnabled = $titleBlacklistEnabled; |
|
| 83 | - $this->torExitProvider = $torExitProvider; |
|
| 84 | - } |
|
| 85 | - |
|
| 86 | - /** |
|
| 87 | - * Summary of validateName |
|
| 88 | - * @return ValidationError[] |
|
| 89 | - */ |
|
| 90 | - public function validateName() |
|
| 91 | - { |
|
| 92 | - $errorList = array(); |
|
| 93 | - |
|
| 94 | - // ERRORS |
|
| 95 | - // name is empty |
|
| 96 | - if (trim($this->request->getName()) == "") { |
|
| 97 | - $errorList[ValidationError::NAME_EMPTY] = new ValidationError(ValidationError::NAME_EMPTY); |
|
| 98 | - } |
|
| 99 | - |
|
| 100 | - // name is banned |
|
| 101 | - $ban = $this->banHelper->nameIsBanned($this->request->getName()); |
|
| 102 | - if ($ban != false) { |
|
| 103 | - $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 104 | - } |
|
| 105 | - |
|
| 106 | - // username already exists |
|
| 107 | - if ($this->userExists()) { |
|
| 108 | - $errorList[ValidationError::NAME_EXISTS] = new ValidationError(ValidationError::NAME_EXISTS); |
|
| 109 | - } |
|
| 110 | - |
|
| 111 | - // username part of SUL account |
|
| 112 | - if ($this->userSulExists()) { |
|
| 113 | - // using same error slot as name exists - it's the same sort of error, and we probably only want to show one. |
|
| 114 | - $errorList[ValidationError::NAME_EXISTS] = new ValidationError(ValidationError::NAME_EXISTS_SUL); |
|
| 115 | - } |
|
| 116 | - |
|
| 117 | - // username is numbers |
|
| 118 | - if (preg_match("/^[0-9]+$/", $this->request->getName()) === 1) { |
|
| 119 | - $errorList[ValidationError::NAME_NUMONLY] = new ValidationError(ValidationError::NAME_NUMONLY); |
|
| 120 | - } |
|
| 121 | - |
|
| 122 | - // username can't contain #@/<>[]|{} |
|
| 123 | - if (preg_match("/[" . preg_quote("#@/<>[]|{}", "/") . "]/", $this->request->getName()) === 1) { |
|
| 124 | - $errorList[ValidationError::NAME_INVALIDCHAR] = new ValidationError(ValidationError::NAME_INVALIDCHAR); |
|
| 125 | - } |
|
| 126 | - |
|
| 127 | - // existing non-closed request for this name |
|
| 128 | - if ($this->nameRequestExists()) { |
|
| 129 | - $errorList[ValidationError::OPEN_REQUEST_NAME] = new ValidationError(ValidationError::OPEN_REQUEST_NAME); |
|
| 130 | - } |
|
| 131 | - |
|
| 132 | - return $errorList; |
|
| 133 | - } |
|
| 134 | - |
|
| 135 | - /** |
|
| 136 | - * Summary of validateEmail |
|
| 137 | - * @return ValidationError[] |
|
| 138 | - */ |
|
| 139 | - public function validateEmail() |
|
| 140 | - { |
|
| 141 | - $errorList = array(); |
|
| 142 | - |
|
| 143 | - // ERRORS |
|
| 144 | - |
|
| 145 | - // Email is banned |
|
| 146 | - $ban = $this->banHelper->emailIsBanned($this->request->getEmail()); |
|
| 147 | - if ($ban != false) { |
|
| 148 | - $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 149 | - } |
|
| 150 | - |
|
| 151 | - // email addresses must match |
|
| 152 | - if ($this->request->getEmail() != $this->emailConfirmation) { |
|
| 153 | - $errorList[ValidationError::EMAIL_MISMATCH] = new ValidationError(ValidationError::EMAIL_MISMATCH); |
|
| 154 | - } |
|
| 155 | - |
|
| 156 | - // email address must be validly formed |
|
| 157 | - if (trim($this->request->getEmail()) == "") { |
|
| 158 | - $errorList[ValidationError::EMAIL_EMPTY] = new ValidationError(ValidationError::EMAIL_EMPTY); |
|
| 159 | - } |
|
| 160 | - |
|
| 161 | - // email address must be validly formed |
|
| 162 | - if (!filter_var($this->request->getEmail(), FILTER_VALIDATE_EMAIL)) { |
|
| 163 | - if (trim($this->request->getEmail()) != "") { |
|
| 164 | - $errorList[ValidationError::EMAIL_INVALID] = new ValidationError(ValidationError::EMAIL_INVALID); |
|
| 165 | - } |
|
| 166 | - } |
|
| 167 | - |
|
| 168 | - // email address can't be wikimedia/wikipedia .com/org |
|
| 169 | - if (preg_match('/.*@.*wiki(m.dia|p.dia)\.(org|com)/i', $this->request->getEmail()) === 1) { |
|
| 170 | - $errorList[ValidationError::EMAIL_WIKIMEDIA] = new ValidationError(ValidationError::EMAIL_WIKIMEDIA); |
|
| 171 | - } |
|
| 172 | - |
|
| 173 | - // WARNINGS |
|
| 174 | - |
|
| 175 | - return $errorList; |
|
| 176 | - } |
|
| 177 | - |
|
| 178 | - /** |
|
| 179 | - * Summary of validateOther |
|
| 180 | - * @return ValidationError[] |
|
| 181 | - */ |
|
| 182 | - public function validateOther() |
|
| 183 | - { |
|
| 184 | - $errorList = array(); |
|
| 185 | - |
|
| 186 | - $trustedIp = $this->xffTrustProvider->getTrustedClientIp($this->request->getIp(), |
|
| 187 | - $this->request->getForwardedIp()); |
|
| 188 | - |
|
| 189 | - // ERRORS |
|
| 190 | - |
|
| 191 | - // TOR nodes |
|
| 192 | - if ($this->torExitProvider->isTorExit($trustedIp)) { |
|
| 193 | - $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED_TOR); |
|
| 194 | - } |
|
| 195 | - |
|
| 196 | - // IP banned |
|
| 197 | - $ban = $this->banHelper->ipIsBanned($trustedIp); |
|
| 198 | - if ($ban != false) { |
|
| 199 | - $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 200 | - } |
|
| 201 | - |
|
| 202 | - // WARNINGS |
|
| 203 | - |
|
| 204 | - // Antispoof check |
|
| 205 | - $this->checkAntiSpoof(); |
|
| 206 | - |
|
| 207 | - // Blacklist check |
|
| 208 | - $this->checkTitleBlacklist(); |
|
| 209 | - |
|
| 210 | - return $errorList; |
|
| 211 | - } |
|
| 212 | - |
|
| 213 | - private function checkAntiSpoof() |
|
| 214 | - { |
|
| 215 | - try { |
|
| 216 | - if (count($this->antiSpoofProvider->getSpoofs($this->request->getName())) > 0) { |
|
| 217 | - // If there were spoofs an Admin should handle the request. |
|
| 218 | - $this->request->setStatus("Flagged users"); |
|
| 219 | - } |
|
| 220 | - } |
|
| 221 | - catch (Exception $ex) { |
|
| 222 | - // logme |
|
| 223 | - } |
|
| 224 | - } |
|
| 225 | - |
|
| 226 | - private function checkTitleBlacklist() |
|
| 227 | - { |
|
| 228 | - if ($this->titleBlacklistEnabled == 1) { |
|
| 229 | - $apiResult = $this->httpHelper->get( |
|
| 230 | - $this->mediawikiApiEndpoint, |
|
| 231 | - array( |
|
| 232 | - 'action' => 'titleblacklist', |
|
| 233 | - 'tbtitle' => $this->request->getName(), |
|
| 234 | - 'tbaction' => 'new-account', |
|
| 235 | - 'tbnooverride' => true, |
|
| 236 | - 'format' => 'php', |
|
| 237 | - ) |
|
| 238 | - ); |
|
| 239 | - |
|
| 240 | - $data = unserialize($apiResult); |
|
| 241 | - |
|
| 242 | - $requestIsOk = $data['titleblacklist']['result'] == "ok"; |
|
| 243 | - |
|
| 244 | - if (!$requestIsOk) { |
|
| 245 | - $this->request->setStatus("Flagged users"); |
|
| 246 | - } |
|
| 247 | - } |
|
| 248 | - } |
|
| 249 | - |
|
| 250 | - private function userExists() |
|
| 251 | - { |
|
| 252 | - $userExists = $this->httpHelper->get( |
|
| 253 | - $this->mediawikiApiEndpoint, |
|
| 254 | - array( |
|
| 255 | - 'action' => 'query', |
|
| 256 | - 'list' => 'users', |
|
| 257 | - 'ususers' => $this->request->getName(), |
|
| 258 | - 'format' => 'php', |
|
| 259 | - ) |
|
| 260 | - ); |
|
| 261 | - |
|
| 262 | - $ue = unserialize($userExists); |
|
| 263 | - if (!isset ($ue['query']['users']['0']['missing']) && isset ($ue['query']['users']['0']['userid'])) { |
|
| 264 | - return true; |
|
| 265 | - } |
|
| 266 | - |
|
| 267 | - return false; |
|
| 268 | - } |
|
| 269 | - |
|
| 270 | - private function userSulExists() |
|
| 271 | - { |
|
| 272 | - $requestName = $this->request->getName(); |
|
| 273 | - |
|
| 274 | - $userExists = $this->httpHelper->get( |
|
| 275 | - $this->mediawikiApiEndpoint, |
|
| 276 | - array( |
|
| 277 | - 'action' => 'query', |
|
| 278 | - 'meta' => 'globaluserinfo', |
|
| 279 | - 'guiuser' => $requestName, |
|
| 280 | - 'format' => 'php', |
|
| 281 | - ) |
|
| 282 | - ); |
|
| 283 | - |
|
| 284 | - $ue = unserialize($userExists); |
|
| 285 | - if (isset ($ue['query']['globaluserinfo']['id'])) { |
|
| 286 | - return true; |
|
| 287 | - } |
|
| 288 | - |
|
| 289 | - return false; |
|
| 290 | - } |
|
| 291 | - |
|
| 292 | - /** |
|
| 293 | - * Checks if a request with this name is currently open |
|
| 294 | - * |
|
| 295 | - * @return bool |
|
| 296 | - */ |
|
| 297 | - private function nameRequestExists() |
|
| 298 | - { |
|
| 299 | - $query = "SELECT COUNT(id) FROM request WHERE status != 'Closed' AND name = :name;"; |
|
| 300 | - $statement = $this->database->prepare($query); |
|
| 301 | - $statement->execute(array(':name' => $this->request->getName())); |
|
| 302 | - |
|
| 303 | - if (!$statement) { |
|
| 304 | - return false; |
|
| 305 | - } |
|
| 306 | - |
|
| 307 | - return $statement->fetchColumn() > 0; |
|
| 308 | - } |
|
| 25 | + /** @var IBanHelper */ |
|
| 26 | + private $banHelper; |
|
| 27 | + /** @var Request */ |
|
| 28 | + private $request; |
|
| 29 | + private $emailConfirmation; |
|
| 30 | + /** @var PdoDatabase */ |
|
| 31 | + private $database; |
|
| 32 | + /** @var IAntiSpoofProvider */ |
|
| 33 | + private $antiSpoofProvider; |
|
| 34 | + /** @var IXffTrustProvider */ |
|
| 35 | + private $xffTrustProvider; |
|
| 36 | + /** @var HttpHelper */ |
|
| 37 | + private $httpHelper; |
|
| 38 | + /** |
|
| 39 | + * @var string |
|
| 40 | + */ |
|
| 41 | + private $mediawikiApiEndpoint; |
|
| 42 | + private $titleBlacklistEnabled; |
|
| 43 | + /** |
|
| 44 | + * @var TorExitProvider |
|
| 45 | + */ |
|
| 46 | + private $torExitProvider; |
|
| 47 | + |
|
| 48 | + /** |
|
| 49 | + * Summary of __construct |
|
| 50 | + * |
|
| 51 | + * @param IBanHelper $banHelper |
|
| 52 | + * @param Request $request |
|
| 53 | + * @param string $emailConfirmation |
|
| 54 | + * @param PdoDatabase $database |
|
| 55 | + * @param IAntiSpoofProvider $antiSpoofProvider |
|
| 56 | + * @param IXffTrustProvider $xffTrustProvider |
|
| 57 | + * @param HttpHelper $httpHelper |
|
| 58 | + * @param string $mediawikiApiEndpoint |
|
| 59 | + * @param boolean $titleBlacklistEnabled |
|
| 60 | + * @param TorExitProvider $torExitProvider |
|
| 61 | + */ |
|
| 62 | + public function __construct( |
|
| 63 | + IBanHelper $banHelper, |
|
| 64 | + Request $request, |
|
| 65 | + $emailConfirmation, |
|
| 66 | + PdoDatabase $database, |
|
| 67 | + IAntiSpoofProvider $antiSpoofProvider, |
|
| 68 | + IXffTrustProvider $xffTrustProvider, |
|
| 69 | + HttpHelper $httpHelper, |
|
| 70 | + $mediawikiApiEndpoint, |
|
| 71 | + $titleBlacklistEnabled, |
|
| 72 | + TorExitProvider $torExitProvider |
|
| 73 | + ) { |
|
| 74 | + $this->banHelper = $banHelper; |
|
| 75 | + $this->request = $request; |
|
| 76 | + $this->emailConfirmation = $emailConfirmation; |
|
| 77 | + $this->database = $database; |
|
| 78 | + $this->antiSpoofProvider = $antiSpoofProvider; |
|
| 79 | + $this->xffTrustProvider = $xffTrustProvider; |
|
| 80 | + $this->httpHelper = $httpHelper; |
|
| 81 | + $this->mediawikiApiEndpoint = $mediawikiApiEndpoint; |
|
| 82 | + $this->titleBlacklistEnabled = $titleBlacklistEnabled; |
|
| 83 | + $this->torExitProvider = $torExitProvider; |
|
| 84 | + } |
|
| 85 | + |
|
| 86 | + /** |
|
| 87 | + * Summary of validateName |
|
| 88 | + * @return ValidationError[] |
|
| 89 | + */ |
|
| 90 | + public function validateName() |
|
| 91 | + { |
|
| 92 | + $errorList = array(); |
|
| 93 | + |
|
| 94 | + // ERRORS |
|
| 95 | + // name is empty |
|
| 96 | + if (trim($this->request->getName()) == "") { |
|
| 97 | + $errorList[ValidationError::NAME_EMPTY] = new ValidationError(ValidationError::NAME_EMPTY); |
|
| 98 | + } |
|
| 99 | + |
|
| 100 | + // name is banned |
|
| 101 | + $ban = $this->banHelper->nameIsBanned($this->request->getName()); |
|
| 102 | + if ($ban != false) { |
|
| 103 | + $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 104 | + } |
|
| 105 | + |
|
| 106 | + // username already exists |
|
| 107 | + if ($this->userExists()) { |
|
| 108 | + $errorList[ValidationError::NAME_EXISTS] = new ValidationError(ValidationError::NAME_EXISTS); |
|
| 109 | + } |
|
| 110 | + |
|
| 111 | + // username part of SUL account |
|
| 112 | + if ($this->userSulExists()) { |
|
| 113 | + // using same error slot as name exists - it's the same sort of error, and we probably only want to show one. |
|
| 114 | + $errorList[ValidationError::NAME_EXISTS] = new ValidationError(ValidationError::NAME_EXISTS_SUL); |
|
| 115 | + } |
|
| 116 | + |
|
| 117 | + // username is numbers |
|
| 118 | + if (preg_match("/^[0-9]+$/", $this->request->getName()) === 1) { |
|
| 119 | + $errorList[ValidationError::NAME_NUMONLY] = new ValidationError(ValidationError::NAME_NUMONLY); |
|
| 120 | + } |
|
| 121 | + |
|
| 122 | + // username can't contain #@/<>[]|{} |
|
| 123 | + if (preg_match("/[" . preg_quote("#@/<>[]|{}", "/") . "]/", $this->request->getName()) === 1) { |
|
| 124 | + $errorList[ValidationError::NAME_INVALIDCHAR] = new ValidationError(ValidationError::NAME_INVALIDCHAR); |
|
| 125 | + } |
|
| 126 | + |
|
| 127 | + // existing non-closed request for this name |
|
| 128 | + if ($this->nameRequestExists()) { |
|
| 129 | + $errorList[ValidationError::OPEN_REQUEST_NAME] = new ValidationError(ValidationError::OPEN_REQUEST_NAME); |
|
| 130 | + } |
|
| 131 | + |
|
| 132 | + return $errorList; |
|
| 133 | + } |
|
| 134 | + |
|
| 135 | + /** |
|
| 136 | + * Summary of validateEmail |
|
| 137 | + * @return ValidationError[] |
|
| 138 | + */ |
|
| 139 | + public function validateEmail() |
|
| 140 | + { |
|
| 141 | + $errorList = array(); |
|
| 142 | + |
|
| 143 | + // ERRORS |
|
| 144 | + |
|
| 145 | + // Email is banned |
|
| 146 | + $ban = $this->banHelper->emailIsBanned($this->request->getEmail()); |
|
| 147 | + if ($ban != false) { |
|
| 148 | + $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 149 | + } |
|
| 150 | + |
|
| 151 | + // email addresses must match |
|
| 152 | + if ($this->request->getEmail() != $this->emailConfirmation) { |
|
| 153 | + $errorList[ValidationError::EMAIL_MISMATCH] = new ValidationError(ValidationError::EMAIL_MISMATCH); |
|
| 154 | + } |
|
| 155 | + |
|
| 156 | + // email address must be validly formed |
|
| 157 | + if (trim($this->request->getEmail()) == "") { |
|
| 158 | + $errorList[ValidationError::EMAIL_EMPTY] = new ValidationError(ValidationError::EMAIL_EMPTY); |
|
| 159 | + } |
|
| 160 | + |
|
| 161 | + // email address must be validly formed |
|
| 162 | + if (!filter_var($this->request->getEmail(), FILTER_VALIDATE_EMAIL)) { |
|
| 163 | + if (trim($this->request->getEmail()) != "") { |
|
| 164 | + $errorList[ValidationError::EMAIL_INVALID] = new ValidationError(ValidationError::EMAIL_INVALID); |
|
| 165 | + } |
|
| 166 | + } |
|
| 167 | + |
|
| 168 | + // email address can't be wikimedia/wikipedia .com/org |
|
| 169 | + if (preg_match('/.*@.*wiki(m.dia|p.dia)\.(org|com)/i', $this->request->getEmail()) === 1) { |
|
| 170 | + $errorList[ValidationError::EMAIL_WIKIMEDIA] = new ValidationError(ValidationError::EMAIL_WIKIMEDIA); |
|
| 171 | + } |
|
| 172 | + |
|
| 173 | + // WARNINGS |
|
| 174 | + |
|
| 175 | + return $errorList; |
|
| 176 | + } |
|
| 177 | + |
|
| 178 | + /** |
|
| 179 | + * Summary of validateOther |
|
| 180 | + * @return ValidationError[] |
|
| 181 | + */ |
|
| 182 | + public function validateOther() |
|
| 183 | + { |
|
| 184 | + $errorList = array(); |
|
| 185 | + |
|
| 186 | + $trustedIp = $this->xffTrustProvider->getTrustedClientIp($this->request->getIp(), |
|
| 187 | + $this->request->getForwardedIp()); |
|
| 188 | + |
|
| 189 | + // ERRORS |
|
| 190 | + |
|
| 191 | + // TOR nodes |
|
| 192 | + if ($this->torExitProvider->isTorExit($trustedIp)) { |
|
| 193 | + $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED_TOR); |
|
| 194 | + } |
|
| 195 | + |
|
| 196 | + // IP banned |
|
| 197 | + $ban = $this->banHelper->ipIsBanned($trustedIp); |
|
| 198 | + if ($ban != false) { |
|
| 199 | + $errorList[ValidationError::BANNED] = new ValidationError(ValidationError::BANNED); |
|
| 200 | + } |
|
| 201 | + |
|
| 202 | + // WARNINGS |
|
| 203 | + |
|
| 204 | + // Antispoof check |
|
| 205 | + $this->checkAntiSpoof(); |
|
| 206 | + |
|
| 207 | + // Blacklist check |
|
| 208 | + $this->checkTitleBlacklist(); |
|
| 209 | + |
|
| 210 | + return $errorList; |
|
| 211 | + } |
|
| 212 | + |
|
| 213 | + private function checkAntiSpoof() |
|
| 214 | + { |
|
| 215 | + try { |
|
| 216 | + if (count($this->antiSpoofProvider->getSpoofs($this->request->getName())) > 0) { |
|
| 217 | + // If there were spoofs an Admin should handle the request. |
|
| 218 | + $this->request->setStatus("Flagged users"); |
|
| 219 | + } |
|
| 220 | + } |
|
| 221 | + catch (Exception $ex) { |
|
| 222 | + // logme |
|
| 223 | + } |
|
| 224 | + } |
|
| 225 | + |
|
| 226 | + private function checkTitleBlacklist() |
|
| 227 | + { |
|
| 228 | + if ($this->titleBlacklistEnabled == 1) { |
|
| 229 | + $apiResult = $this->httpHelper->get( |
|
| 230 | + $this->mediawikiApiEndpoint, |
|
| 231 | + array( |
|
| 232 | + 'action' => 'titleblacklist', |
|
| 233 | + 'tbtitle' => $this->request->getName(), |
|
| 234 | + 'tbaction' => 'new-account', |
|
| 235 | + 'tbnooverride' => true, |
|
| 236 | + 'format' => 'php', |
|
| 237 | + ) |
|
| 238 | + ); |
|
| 239 | + |
|
| 240 | + $data = unserialize($apiResult); |
|
| 241 | + |
|
| 242 | + $requestIsOk = $data['titleblacklist']['result'] == "ok"; |
|
| 243 | + |
|
| 244 | + if (!$requestIsOk) { |
|
| 245 | + $this->request->setStatus("Flagged users"); |
|
| 246 | + } |
|
| 247 | + } |
|
| 248 | + } |
|
| 249 | + |
|
| 250 | + private function userExists() |
|
| 251 | + { |
|
| 252 | + $userExists = $this->httpHelper->get( |
|
| 253 | + $this->mediawikiApiEndpoint, |
|
| 254 | + array( |
|
| 255 | + 'action' => 'query', |
|
| 256 | + 'list' => 'users', |
|
| 257 | + 'ususers' => $this->request->getName(), |
|
| 258 | + 'format' => 'php', |
|
| 259 | + ) |
|
| 260 | + ); |
|
| 261 | + |
|
| 262 | + $ue = unserialize($userExists); |
|
| 263 | + if (!isset ($ue['query']['users']['0']['missing']) && isset ($ue['query']['users']['0']['userid'])) { |
|
| 264 | + return true; |
|
| 265 | + } |
|
| 266 | + |
|
| 267 | + return false; |
|
| 268 | + } |
|
| 269 | + |
|
| 270 | + private function userSulExists() |
|
| 271 | + { |
|
| 272 | + $requestName = $this->request->getName(); |
|
| 273 | + |
|
| 274 | + $userExists = $this->httpHelper->get( |
|
| 275 | + $this->mediawikiApiEndpoint, |
|
| 276 | + array( |
|
| 277 | + 'action' => 'query', |
|
| 278 | + 'meta' => 'globaluserinfo', |
|
| 279 | + 'guiuser' => $requestName, |
|
| 280 | + 'format' => 'php', |
|
| 281 | + ) |
|
| 282 | + ); |
|
| 283 | + |
|
| 284 | + $ue = unserialize($userExists); |
|
| 285 | + if (isset ($ue['query']['globaluserinfo']['id'])) { |
|
| 286 | + return true; |
|
| 287 | + } |
|
| 288 | + |
|
| 289 | + return false; |
|
| 290 | + } |
|
| 291 | + |
|
| 292 | + /** |
|
| 293 | + * Checks if a request with this name is currently open |
|
| 294 | + * |
|
| 295 | + * @return bool |
|
| 296 | + */ |
|
| 297 | + private function nameRequestExists() |
|
| 298 | + { |
|
| 299 | + $query = "SELECT COUNT(id) FROM request WHERE status != 'Closed' AND name = :name;"; |
|
| 300 | + $statement = $this->database->prepare($query); |
|
| 301 | + $statement->execute(array(':name' => $this->request->getName())); |
|
| 302 | + |
|
| 303 | + if (!$statement) { |
|
| 304 | + return false; |
|
| 305 | + } |
|
| 306 | + |
|
| 307 | + return $statement->fetchColumn() > 0; |
|
| 308 | + } |
|
| 309 | 309 | } |
@@ -120,7 +120,7 @@ |
||
| 120 | 120 | } |
| 121 | 121 | |
| 122 | 122 | // username can't contain #@/<>[]|{} |
| 123 | - if (preg_match("/[" . preg_quote("#@/<>[]|{}", "/") . "]/", $this->request->getName()) === 1) { |
|
| 123 | + if (preg_match("/[".preg_quote("#@/<>[]|{}", "/")."]/", $this->request->getName()) === 1) { |
|
| 124 | 124 | $errorList[ValidationError::NAME_INVALIDCHAR] = new ValidationError(ValidationError::NAME_INVALIDCHAR); |
| 125 | 125 | } |
| 126 | 126 | |
@@ -12,99 +12,99 @@ |
||
| 12 | 12 | |
| 13 | 13 | class ValidationError |
| 14 | 14 | { |
| 15 | - const NAME_EMPTY = "name_empty"; |
|
| 16 | - const NAME_EXISTS = "name_exists"; |
|
| 17 | - const NAME_EXISTS_SUL = "name_exists"; |
|
| 18 | - const NAME_NUMONLY = "name_numonly"; |
|
| 19 | - const NAME_INVALIDCHAR = "name_invalidchar"; |
|
| 20 | - const NAME_SANITISED = "name_sanitised"; |
|
| 21 | - const EMAIL_EMPTY = "email_empty"; |
|
| 22 | - const EMAIL_WIKIMEDIA = "email_wikimedia"; |
|
| 23 | - const EMAIL_INVALID = "email_invalid"; |
|
| 24 | - const EMAIL_MISMATCH = "email_mismatch"; |
|
| 25 | - const OPEN_REQUEST_NAME = "open_request_name"; |
|
| 26 | - const BANNED = "banned"; |
|
| 27 | - const BANNED_TOR = "banned_tor"; |
|
| 28 | - /** |
|
| 29 | - * @var array Error text for the above |
|
| 30 | - */ |
|
| 31 | - private static $errorText = array( |
|
| 32 | - self::NAME_EMPTY => 'You\'ve not chosen a username!', |
|
| 33 | - self::NAME_EXISTS => 'I\'m sorry, but the username you selected is already taken. Please try another. ' |
|
| 34 | - . 'Please note that Wikipedia automatically capitalizes the first letter of any user name, therefore ' |
|
| 35 | - . '[[User:example]] would become [[User:Example]].', |
|
| 36 | - self::NAME_EXISTS_SUL => 'I\'m sorry, but the username you selected is already taken. Please try another. ' |
|
| 37 | - . 'Please note that Wikipedia automatically capitalizes the first letter of any user name, therefore ' |
|
| 38 | - . '[[User:example]] would become [[User:Example]].', |
|
| 39 | - self::NAME_NUMONLY => 'The username you chose is invalid: it consists entirely of numbers. Please retry ' |
|
| 40 | - . 'with a valid username.', |
|
| 41 | - self::NAME_INVALIDCHAR => 'There appears to be an invalid character in your username. Please note that the ' |
|
| 42 | - . 'following characters are not allowed: <code># @ / < > [ ] | { }</code>', |
|
| 43 | - self::NAME_SANITISED => 'Your requested username has been automatically adjusted due to technical ' |
|
| 44 | - . 'restrictions. Underscores have been replaced with spaces, and the first character has been capitalised.', |
|
| 45 | - self::EMAIL_EMPTY => 'You need to supply an email address.', |
|
| 46 | - self::EMAIL_WIKIMEDIA => 'Please provide your email address here.', |
|
| 47 | - self::EMAIL_INVALID => 'Invalid E-mail address supplied. Please check you entered it correctly.', |
|
| 48 | - self::EMAIL_MISMATCH => 'The email addresses you entered do not match. Please try again.', |
|
| 49 | - self::OPEN_REQUEST_NAME => 'There is already an open request with this name in this system.', |
|
| 50 | - self::BANNED => 'I\'m sorry, but you are currently banned from requesting accounts using this tool. ' |
|
| 51 | - . 'However, you can still send an email to [email protected] to request an account.', |
|
| 52 | - self::BANNED_TOR => 'Tor exit nodes are currently banned from using this tool due to excessive abuse. ' |
|
| 53 | - . 'Please note that Tor is also currently banned from editing Wikipedia.', |
|
| 54 | - ); |
|
| 55 | - /** |
|
| 56 | - * Summary of $errorCode |
|
| 57 | - * @var string |
|
| 58 | - */ |
|
| 59 | - private $errorCode; |
|
| 60 | - /** |
|
| 61 | - * Summary of $isError |
|
| 62 | - * @var bool |
|
| 63 | - */ |
|
| 64 | - private $isError; |
|
| 15 | + const NAME_EMPTY = "name_empty"; |
|
| 16 | + const NAME_EXISTS = "name_exists"; |
|
| 17 | + const NAME_EXISTS_SUL = "name_exists"; |
|
| 18 | + const NAME_NUMONLY = "name_numonly"; |
|
| 19 | + const NAME_INVALIDCHAR = "name_invalidchar"; |
|
| 20 | + const NAME_SANITISED = "name_sanitised"; |
|
| 21 | + const EMAIL_EMPTY = "email_empty"; |
|
| 22 | + const EMAIL_WIKIMEDIA = "email_wikimedia"; |
|
| 23 | + const EMAIL_INVALID = "email_invalid"; |
|
| 24 | + const EMAIL_MISMATCH = "email_mismatch"; |
|
| 25 | + const OPEN_REQUEST_NAME = "open_request_name"; |
|
| 26 | + const BANNED = "banned"; |
|
| 27 | + const BANNED_TOR = "banned_tor"; |
|
| 28 | + /** |
|
| 29 | + * @var array Error text for the above |
|
| 30 | + */ |
|
| 31 | + private static $errorText = array( |
|
| 32 | + self::NAME_EMPTY => 'You\'ve not chosen a username!', |
|
| 33 | + self::NAME_EXISTS => 'I\'m sorry, but the username you selected is already taken. Please try another. ' |
|
| 34 | + . 'Please note that Wikipedia automatically capitalizes the first letter of any user name, therefore ' |
|
| 35 | + . '[[User:example]] would become [[User:Example]].', |
|
| 36 | + self::NAME_EXISTS_SUL => 'I\'m sorry, but the username you selected is already taken. Please try another. ' |
|
| 37 | + . 'Please note that Wikipedia automatically capitalizes the first letter of any user name, therefore ' |
|
| 38 | + . '[[User:example]] would become [[User:Example]].', |
|
| 39 | + self::NAME_NUMONLY => 'The username you chose is invalid: it consists entirely of numbers. Please retry ' |
|
| 40 | + . 'with a valid username.', |
|
| 41 | + self::NAME_INVALIDCHAR => 'There appears to be an invalid character in your username. Please note that the ' |
|
| 42 | + . 'following characters are not allowed: <code># @ / < > [ ] | { }</code>', |
|
| 43 | + self::NAME_SANITISED => 'Your requested username has been automatically adjusted due to technical ' |
|
| 44 | + . 'restrictions. Underscores have been replaced with spaces, and the first character has been capitalised.', |
|
| 45 | + self::EMAIL_EMPTY => 'You need to supply an email address.', |
|
| 46 | + self::EMAIL_WIKIMEDIA => 'Please provide your email address here.', |
|
| 47 | + self::EMAIL_INVALID => 'Invalid E-mail address supplied. Please check you entered it correctly.', |
|
| 48 | + self::EMAIL_MISMATCH => 'The email addresses you entered do not match. Please try again.', |
|
| 49 | + self::OPEN_REQUEST_NAME => 'There is already an open request with this name in this system.', |
|
| 50 | + self::BANNED => 'I\'m sorry, but you are currently banned from requesting accounts using this tool. ' |
|
| 51 | + . 'However, you can still send an email to [email protected] to request an account.', |
|
| 52 | + self::BANNED_TOR => 'Tor exit nodes are currently banned from using this tool due to excessive abuse. ' |
|
| 53 | + . 'Please note that Tor is also currently banned from editing Wikipedia.', |
|
| 54 | + ); |
|
| 55 | + /** |
|
| 56 | + * Summary of $errorCode |
|
| 57 | + * @var string |
|
| 58 | + */ |
|
| 59 | + private $errorCode; |
|
| 60 | + /** |
|
| 61 | + * Summary of $isError |
|
| 62 | + * @var bool |
|
| 63 | + */ |
|
| 64 | + private $isError; |
|
| 65 | 65 | |
| 66 | - /** |
|
| 67 | - * Summary of __construct |
|
| 68 | - * |
|
| 69 | - * @param string $errorCode |
|
| 70 | - * @param bool $isError |
|
| 71 | - */ |
|
| 72 | - public function __construct($errorCode, $isError = true) |
|
| 73 | - { |
|
| 74 | - $this->errorCode = $errorCode; |
|
| 75 | - $this->isError = $isError; |
|
| 76 | - } |
|
| 66 | + /** |
|
| 67 | + * Summary of __construct |
|
| 68 | + * |
|
| 69 | + * @param string $errorCode |
|
| 70 | + * @param bool $isError |
|
| 71 | + */ |
|
| 72 | + public function __construct($errorCode, $isError = true) |
|
| 73 | + { |
|
| 74 | + $this->errorCode = $errorCode; |
|
| 75 | + $this->isError = $isError; |
|
| 76 | + } |
|
| 77 | 77 | |
| 78 | - /** |
|
| 79 | - * Summary of getErrorCode |
|
| 80 | - * @return string |
|
| 81 | - */ |
|
| 82 | - public function getErrorCode() |
|
| 83 | - { |
|
| 84 | - return $this->errorCode; |
|
| 85 | - } |
|
| 78 | + /** |
|
| 79 | + * Summary of getErrorCode |
|
| 80 | + * @return string |
|
| 81 | + */ |
|
| 82 | + public function getErrorCode() |
|
| 83 | + { |
|
| 84 | + return $this->errorCode; |
|
| 85 | + } |
|
| 86 | 86 | |
| 87 | - /** |
|
| 88 | - * @return string |
|
| 89 | - * @throws Exception |
|
| 90 | - */ |
|
| 91 | - public function getErrorMessage() |
|
| 92 | - { |
|
| 93 | - $text = self::$errorText[$this->errorCode]; |
|
| 87 | + /** |
|
| 88 | + * @return string |
|
| 89 | + * @throws Exception |
|
| 90 | + */ |
|
| 91 | + public function getErrorMessage() |
|
| 92 | + { |
|
| 93 | + $text = self::$errorText[$this->errorCode]; |
|
| 94 | 94 | |
| 95 | - if ($text == null) { |
|
| 96 | - throw new Exception('Unknown validation error'); |
|
| 97 | - } |
|
| 95 | + if ($text == null) { |
|
| 96 | + throw new Exception('Unknown validation error'); |
|
| 97 | + } |
|
| 98 | 98 | |
| 99 | - return $text; |
|
| 100 | - } |
|
| 99 | + return $text; |
|
| 100 | + } |
|
| 101 | 101 | |
| 102 | - /** |
|
| 103 | - * Summary of isError |
|
| 104 | - * @return bool |
|
| 105 | - */ |
|
| 106 | - public function isError() |
|
| 107 | - { |
|
| 108 | - return $this->isError; |
|
| 109 | - } |
|
| 102 | + /** |
|
| 103 | + * Summary of isError |
|
| 104 | + * @return bool |
|
| 105 | + */ |
|
| 106 | + public function isError() |
|
| 107 | + { |
|
| 108 | + return $this->isError; |
|
| 109 | + } |
|
| 110 | 110 | } |
@@ -12,80 +12,80 @@ |
||
| 12 | 12 | |
| 13 | 13 | class Token |
| 14 | 14 | { |
| 15 | - /** @var string */ |
|
| 16 | - private $tokenData; |
|
| 17 | - /** @var string */ |
|
| 18 | - private $context; |
|
| 19 | - /** @var DateTimeImmutable */ |
|
| 20 | - private $generationTimestamp; |
|
| 21 | - /** @var DateTimeImmutable */ |
|
| 22 | - private $usageTimestamp; |
|
| 23 | - /** @var bool */ |
|
| 24 | - private $used; |
|
| 15 | + /** @var string */ |
|
| 16 | + private $tokenData; |
|
| 17 | + /** @var string */ |
|
| 18 | + private $context; |
|
| 19 | + /** @var DateTimeImmutable */ |
|
| 20 | + private $generationTimestamp; |
|
| 21 | + /** @var DateTimeImmutable */ |
|
| 22 | + private $usageTimestamp; |
|
| 23 | + /** @var bool */ |
|
| 24 | + private $used; |
|
| 25 | 25 | |
| 26 | - /** |
|
| 27 | - * Token constructor. |
|
| 28 | - * |
|
| 29 | - * @param string $tokenData |
|
| 30 | - * @param string $context |
|
| 31 | - */ |
|
| 32 | - public function __construct($tokenData, $context) |
|
| 33 | - { |
|
| 34 | - $this->tokenData = $tokenData; |
|
| 35 | - $this->context = $context; |
|
| 36 | - $this->generationTimestamp = new DateTimeImmutable(); |
|
| 37 | - $this->usageTimestamp = null; |
|
| 38 | - $this->used = false; |
|
| 39 | - } |
|
| 26 | + /** |
|
| 27 | + * Token constructor. |
|
| 28 | + * |
|
| 29 | + * @param string $tokenData |
|
| 30 | + * @param string $context |
|
| 31 | + */ |
|
| 32 | + public function __construct($tokenData, $context) |
|
| 33 | + { |
|
| 34 | + $this->tokenData = $tokenData; |
|
| 35 | + $this->context = $context; |
|
| 36 | + $this->generationTimestamp = new DateTimeImmutable(); |
|
| 37 | + $this->usageTimestamp = null; |
|
| 38 | + $this->used = false; |
|
| 39 | + } |
|
| 40 | 40 | |
| 41 | - /** |
|
| 42 | - * @return DateTimeImmutable |
|
| 43 | - */ |
|
| 44 | - public function getGenerationTimestamp() |
|
| 45 | - { |
|
| 46 | - return $this->generationTimestamp; |
|
| 47 | - } |
|
| 41 | + /** |
|
| 42 | + * @return DateTimeImmutable |
|
| 43 | + */ |
|
| 44 | + public function getGenerationTimestamp() |
|
| 45 | + { |
|
| 46 | + return $this->generationTimestamp; |
|
| 47 | + } |
|
| 48 | 48 | |
| 49 | - /** |
|
| 50 | - * @return string |
|
| 51 | - */ |
|
| 52 | - public function getContext() |
|
| 53 | - { |
|
| 54 | - return $this->context; |
|
| 55 | - } |
|
| 49 | + /** |
|
| 50 | + * @return string |
|
| 51 | + */ |
|
| 52 | + public function getContext() |
|
| 53 | + { |
|
| 54 | + return $this->context; |
|
| 55 | + } |
|
| 56 | 56 | |
| 57 | - /** |
|
| 58 | - * @return string |
|
| 59 | - */ |
|
| 60 | - public function getTokenData() |
|
| 61 | - { |
|
| 62 | - return $this->tokenData; |
|
| 63 | - } |
|
| 57 | + /** |
|
| 58 | + * @return string |
|
| 59 | + */ |
|
| 60 | + public function getTokenData() |
|
| 61 | + { |
|
| 62 | + return $this->tokenData; |
|
| 63 | + } |
|
| 64 | 64 | |
| 65 | - /** |
|
| 66 | - * Returns a value indicating whether the token has already been used or not |
|
| 67 | - * |
|
| 68 | - * @return boolean |
|
| 69 | - */ |
|
| 70 | - public function isUsed() |
|
| 71 | - { |
|
| 72 | - return $this->used; |
|
| 73 | - } |
|
| 65 | + /** |
|
| 66 | + * Returns a value indicating whether the token has already been used or not |
|
| 67 | + * |
|
| 68 | + * @return boolean |
|
| 69 | + */ |
|
| 70 | + public function isUsed() |
|
| 71 | + { |
|
| 72 | + return $this->used; |
|
| 73 | + } |
|
| 74 | 74 | |
| 75 | - /** |
|
| 76 | - * Marks the token as used |
|
| 77 | - */ |
|
| 78 | - public function markAsUsed() |
|
| 79 | - { |
|
| 80 | - $this->used = true; |
|
| 81 | - $this->usageTimestamp = new DateTimeImmutable(); |
|
| 82 | - } |
|
| 75 | + /** |
|
| 76 | + * Marks the token as used |
|
| 77 | + */ |
|
| 78 | + public function markAsUsed() |
|
| 79 | + { |
|
| 80 | + $this->used = true; |
|
| 81 | + $this->usageTimestamp = new DateTimeImmutable(); |
|
| 82 | + } |
|
| 83 | 83 | |
| 84 | - /** |
|
| 85 | - * @return DateTimeImmutable |
|
| 86 | - */ |
|
| 87 | - public function getUsageTimestamp() |
|
| 88 | - { |
|
| 89 | - return $this->usageTimestamp; |
|
| 90 | - } |
|
| 84 | + /** |
|
| 85 | + * @return DateTimeImmutable |
|
| 86 | + */ |
|
| 87 | + public function getUsageTimestamp() |
|
| 88 | + { |
|
| 89 | + return $this->usageTimestamp; |
|
| 90 | + } |
|
| 91 | 91 | } |
| 92 | 92 | \ No newline at end of file |
@@ -13,91 +13,91 @@ |
||
| 13 | 13 | |
| 14 | 14 | class TokenManager |
| 15 | 15 | { |
| 16 | - /** |
|
| 17 | - * Validates a CSRF token |
|
| 18 | - * |
|
| 19 | - * @param string $data The token data string itself |
|
| 20 | - * @param string|null $context Token context for extra validation |
|
| 21 | - * |
|
| 22 | - * @return bool |
|
| 23 | - */ |
|
| 24 | - public function validateToken($data, $context = null) |
|
| 25 | - { |
|
| 26 | - if (!is_string($data) || strlen($data) === 0) { |
|
| 27 | - // Nothing to validate |
|
| 28 | - return false; |
|
| 29 | - } |
|
| 30 | - |
|
| 31 | - $tokens = WebRequest::getSessionTokenData(); |
|
| 32 | - |
|
| 33 | - // if the token doesn't exist, then it's not valid |
|
| 34 | - if (!array_key_exists($data, $tokens)) { |
|
| 35 | - return false; |
|
| 36 | - } |
|
| 37 | - |
|
| 38 | - /** @var Token $token */ |
|
| 39 | - $token = unserialize($tokens[$data]); |
|
| 40 | - |
|
| 41 | - if ($token->getTokenData() !== $data) { |
|
| 42 | - return false; |
|
| 43 | - } |
|
| 44 | - |
|
| 45 | - if ($token->getContext() !== $context) { |
|
| 46 | - return false; |
|
| 47 | - } |
|
| 48 | - |
|
| 49 | - if ($token->isUsed()) { |
|
| 50 | - return false; |
|
| 51 | - } |
|
| 52 | - |
|
| 53 | - // mark the token as used, and save it back to the session |
|
| 54 | - $token->markAsUsed(); |
|
| 55 | - $this->storeToken($token); |
|
| 56 | - |
|
| 57 | - return true; |
|
| 58 | - } |
|
| 59 | - |
|
| 60 | - /** |
|
| 61 | - * @param string|null $context An optional context for extra validation |
|
| 62 | - * |
|
| 63 | - * @return Token |
|
| 64 | - */ |
|
| 65 | - public function getNewToken($context = null) |
|
| 66 | - { |
|
| 67 | - $token = new Token($this->generateTokenData(), $context); |
|
| 68 | - $this->storeToken($token); |
|
| 69 | - |
|
| 70 | - return $token; |
|
| 71 | - } |
|
| 72 | - |
|
| 73 | - /** |
|
| 74 | - * Stores a token in the session data |
|
| 75 | - * |
|
| 76 | - * @param Token $token |
|
| 77 | - */ |
|
| 78 | - private function storeToken(Token $token) |
|
| 79 | - { |
|
| 80 | - $tokens = WebRequest::getSessionTokenData(); |
|
| 81 | - $tokens[$token->getTokenData()] = serialize($token); |
|
| 82 | - WebRequest::setSessionTokenData($tokens); |
|
| 83 | - } |
|
| 84 | - |
|
| 85 | - /** |
|
| 86 | - * Generates a security token |
|
| 87 | - * |
|
| 88 | - * @return string |
|
| 89 | - * @throws Exception |
|
| 90 | - * |
|
| 91 | - * @category Security-Critical |
|
| 92 | - */ |
|
| 93 | - private function generateTokenData() |
|
| 94 | - { |
|
| 95 | - $genBytes = openssl_random_pseudo_bytes(33); |
|
| 96 | - |
|
| 97 | - if ($genBytes !== false) { |
|
| 98 | - return base64_encode($genBytes); |
|
| 99 | - } |
|
| 100 | - |
|
| 101 | - throw new Exception('Unable to generate secure token.'); |
|
| 102 | - } |
|
| 16 | + /** |
|
| 17 | + * Validates a CSRF token |
|
| 18 | + * |
|
| 19 | + * @param string $data The token data string itself |
|
| 20 | + * @param string|null $context Token context for extra validation |
|
| 21 | + * |
|
| 22 | + * @return bool |
|
| 23 | + */ |
|
| 24 | + public function validateToken($data, $context = null) |
|
| 25 | + { |
|
| 26 | + if (!is_string($data) || strlen($data) === 0) { |
|
| 27 | + // Nothing to validate |
|
| 28 | + return false; |
|
| 29 | + } |
|
| 30 | + |
|
| 31 | + $tokens = WebRequest::getSessionTokenData(); |
|
| 32 | + |
|
| 33 | + // if the token doesn't exist, then it's not valid |
|
| 34 | + if (!array_key_exists($data, $tokens)) { |
|
| 35 | + return false; |
|
| 36 | + } |
|
| 37 | + |
|
| 38 | + /** @var Token $token */ |
|
| 39 | + $token = unserialize($tokens[$data]); |
|
| 40 | + |
|
| 41 | + if ($token->getTokenData() !== $data) { |
|
| 42 | + return false; |
|
| 43 | + } |
|
| 44 | + |
|
| 45 | + if ($token->getContext() !== $context) { |
|
| 46 | + return false; |
|
| 47 | + } |
|
| 48 | + |
|
| 49 | + if ($token->isUsed()) { |
|
| 50 | + return false; |
|
| 51 | + } |
|
| 52 | + |
|
| 53 | + // mark the token as used, and save it back to the session |
|
| 54 | + $token->markAsUsed(); |
|
| 55 | + $this->storeToken($token); |
|
| 56 | + |
|
| 57 | + return true; |
|
| 58 | + } |
|
| 59 | + |
|
| 60 | + /** |
|
| 61 | + * @param string|null $context An optional context for extra validation |
|
| 62 | + * |
|
| 63 | + * @return Token |
|
| 64 | + */ |
|
| 65 | + public function getNewToken($context = null) |
|
| 66 | + { |
|
| 67 | + $token = new Token($this->generateTokenData(), $context); |
|
| 68 | + $this->storeToken($token); |
|
| 69 | + |
|
| 70 | + return $token; |
|
| 71 | + } |
|
| 72 | + |
|
| 73 | + /** |
|
| 74 | + * Stores a token in the session data |
|
| 75 | + * |
|
| 76 | + * @param Token $token |
|
| 77 | + */ |
|
| 78 | + private function storeToken(Token $token) |
|
| 79 | + { |
|
| 80 | + $tokens = WebRequest::getSessionTokenData(); |
|
| 81 | + $tokens[$token->getTokenData()] = serialize($token); |
|
| 82 | + WebRequest::setSessionTokenData($tokens); |
|
| 83 | + } |
|
| 84 | + |
|
| 85 | + /** |
|
| 86 | + * Generates a security token |
|
| 87 | + * |
|
| 88 | + * @return string |
|
| 89 | + * @throws Exception |
|
| 90 | + * |
|
| 91 | + * @category Security-Critical |
|
| 92 | + */ |
|
| 93 | + private function generateTokenData() |
|
| 94 | + { |
|
| 95 | + $genBytes = openssl_random_pseudo_bytes(33); |
|
| 96 | + |
|
| 97 | + if ($genBytes !== false) { |
|
| 98 | + return base64_encode($genBytes); |
|
| 99 | + } |
|
| 100 | + |
|
| 101 | + throw new Exception('Unable to generate secure token.'); |
|
| 102 | + } |
|
| 103 | 103 | } |
| 104 | 104 | \ No newline at end of file |
@@ -20,43 +20,43 @@ |
||
| 20 | 20 | |
| 21 | 21 | class ApiRequestRouter implements IRequestRouter |
| 22 | 22 | { |
| 23 | - /** |
|
| 24 | - * @return string[] |
|
| 25 | - */ |
|
| 26 | - public static function getActionList() |
|
| 27 | - { |
|
| 28 | - return array("count", "status", "stats", "help", "monitor"); |
|
| 29 | - } |
|
| 23 | + /** |
|
| 24 | + * @return string[] |
|
| 25 | + */ |
|
| 26 | + public static function getActionList() |
|
| 27 | + { |
|
| 28 | + return array("count", "status", "stats", "help", "monitor"); |
|
| 29 | + } |
|
| 30 | 30 | |
| 31 | - /** |
|
| 32 | - * @return IRoutedTask |
|
| 33 | - * @throws Exception |
|
| 34 | - */ |
|
| 35 | - public function route() |
|
| 36 | - { |
|
| 37 | - $requestAction = WebRequest::getString('action'); |
|
| 31 | + /** |
|
| 32 | + * @return IRoutedTask |
|
| 33 | + * @throws Exception |
|
| 34 | + */ |
|
| 35 | + public function route() |
|
| 36 | + { |
|
| 37 | + $requestAction = WebRequest::getString('action'); |
|
| 38 | 38 | |
| 39 | - switch ($requestAction) { |
|
| 40 | - case "count": |
|
| 41 | - $result = new CountAction(); |
|
| 42 | - break; |
|
| 43 | - case "status": |
|
| 44 | - $result = new StatusAction(); |
|
| 45 | - break; |
|
| 46 | - case "stats": |
|
| 47 | - $result = new StatsAction(); |
|
| 48 | - break; |
|
| 49 | - case "help": |
|
| 50 | - $result = new HelpAction(); |
|
| 51 | - break; |
|
| 52 | - case "monitor": |
|
| 53 | - $result = new MonitorAction(); |
|
| 54 | - break; |
|
| 55 | - default: |
|
| 56 | - $result = new UnknownAction(); |
|
| 57 | - break; |
|
| 58 | - } |
|
| 39 | + switch ($requestAction) { |
|
| 40 | + case "count": |
|
| 41 | + $result = new CountAction(); |
|
| 42 | + break; |
|
| 43 | + case "status": |
|
| 44 | + $result = new StatusAction(); |
|
| 45 | + break; |
|
| 46 | + case "stats": |
|
| 47 | + $result = new StatsAction(); |
|
| 48 | + break; |
|
| 49 | + case "help": |
|
| 50 | + $result = new HelpAction(); |
|
| 51 | + break; |
|
| 52 | + case "monitor": |
|
| 53 | + $result = new MonitorAction(); |
|
| 54 | + break; |
|
| 55 | + default: |
|
| 56 | + $result = new UnknownAction(); |
|
| 57 | + break; |
|
| 58 | + } |
|
| 59 | 59 | |
| 60 | - return $result; |
|
| 61 | - } |
|
| 60 | + return $result; |
|
| 61 | + } |
|
| 62 | 62 | } |
| 63 | 63 | \ No newline at end of file |
@@ -18,9 +18,9 @@ |
||
| 18 | 18 | */ |
| 19 | 19 | interface IRequestRouter |
| 20 | 20 | { |
| 21 | - /** |
|
| 22 | - * @return IRoutedTask |
|
| 23 | - * @throws Exception |
|
| 24 | - */ |
|
| 25 | - public function route(); |
|
| 21 | + /** |
|
| 22 | + * @return IRoutedTask |
|
| 23 | + * @throws Exception |
|
| 24 | + */ |
|
| 25 | + public function route(); |
|
| 26 | 26 | } |
| 27 | 27 | \ No newline at end of file |
@@ -13,36 +13,36 @@ |
||
| 13 | 13 | */ |
| 14 | 14 | class AutoLoader |
| 15 | 15 | { |
| 16 | - public static function load($class) |
|
| 17 | - { |
|
| 18 | - // handle namespaces sensibly |
|
| 19 | - if (strpos($class, "Waca") !== false) { |
|
| 20 | - // strip off the initial namespace |
|
| 21 | - $class = str_replace("Waca\\", "", $class); |
|
| 16 | + public static function load($class) |
|
| 17 | + { |
|
| 18 | + // handle namespaces sensibly |
|
| 19 | + if (strpos($class, "Waca") !== false) { |
|
| 20 | + // strip off the initial namespace |
|
| 21 | + $class = str_replace("Waca\\", "", $class); |
|
| 22 | 22 | |
| 23 | - // swap backslashes for forward slashes to map to directory names |
|
| 24 | - $class = str_replace("\\", "/", $class); |
|
| 25 | - } |
|
| 23 | + // swap backslashes for forward slashes to map to directory names |
|
| 24 | + $class = str_replace("\\", "/", $class); |
|
| 25 | + } |
|
| 26 | 26 | |
| 27 | - $paths = array( |
|
| 28 | - __DIR__ . '/' . $class . ".php", |
|
| 29 | - __DIR__ . '/DataObjects/' . $class . ".php", |
|
| 30 | - __DIR__ . '/Providers/' . $class . ".php", |
|
| 31 | - __DIR__ . '/Providers/Interfaces/' . $class . ".php", |
|
| 32 | - __DIR__ . '/Validation/' . $class . ".php", |
|
| 33 | - __DIR__ . '/Helpers/' . $class . ".php", |
|
| 34 | - __DIR__ . '/Helpers/Interfaces/' . $class . ".php", |
|
| 35 | - __DIR__ . '/' . $class . ".php", |
|
| 36 | - ); |
|
| 27 | + $paths = array( |
|
| 28 | + __DIR__ . '/' . $class . ".php", |
|
| 29 | + __DIR__ . '/DataObjects/' . $class . ".php", |
|
| 30 | + __DIR__ . '/Providers/' . $class . ".php", |
|
| 31 | + __DIR__ . '/Providers/Interfaces/' . $class . ".php", |
|
| 32 | + __DIR__ . '/Validation/' . $class . ".php", |
|
| 33 | + __DIR__ . '/Helpers/' . $class . ".php", |
|
| 34 | + __DIR__ . '/Helpers/Interfaces/' . $class . ".php", |
|
| 35 | + __DIR__ . '/' . $class . ".php", |
|
| 36 | + ); |
|
| 37 | 37 | |
| 38 | - foreach ($paths as $file) { |
|
| 39 | - if (file_exists($file)) { |
|
| 40 | - require_once($file); |
|
| 41 | - } |
|
| 38 | + foreach ($paths as $file) { |
|
| 39 | + if (file_exists($file)) { |
|
| 40 | + require_once($file); |
|
| 41 | + } |
|
| 42 | 42 | |
| 43 | - if (class_exists($class)) { |
|
| 44 | - return; |
|
| 45 | - } |
|
| 46 | - } |
|
| 47 | - } |
|
| 43 | + if (class_exists($class)) { |
|
| 44 | + return; |
|
| 45 | + } |
|
| 46 | + } |
|
| 47 | + } |
|
| 48 | 48 | } |
@@ -25,14 +25,14 @@ |
||
| 25 | 25 | } |
| 26 | 26 | |
| 27 | 27 | $paths = array( |
| 28 | - __DIR__ . '/' . $class . ".php", |
|
| 29 | - __DIR__ . '/DataObjects/' . $class . ".php", |
|
| 30 | - __DIR__ . '/Providers/' . $class . ".php", |
|
| 31 | - __DIR__ . '/Providers/Interfaces/' . $class . ".php", |
|
| 32 | - __DIR__ . '/Validation/' . $class . ".php", |
|
| 33 | - __DIR__ . '/Helpers/' . $class . ".php", |
|
| 34 | - __DIR__ . '/Helpers/Interfaces/' . $class . ".php", |
|
| 35 | - __DIR__ . '/' . $class . ".php", |
|
| 28 | + __DIR__.'/'.$class.".php", |
|
| 29 | + __DIR__.'/DataObjects/'.$class.".php", |
|
| 30 | + __DIR__.'/Providers/'.$class.".php", |
|
| 31 | + __DIR__.'/Providers/Interfaces/'.$class.".php", |
|
| 32 | + __DIR__.'/Validation/'.$class.".php", |
|
| 33 | + __DIR__.'/Helpers/'.$class.".php", |
|
| 34 | + __DIR__.'/Helpers/Interfaces/'.$class.".php", |
|
| 35 | + __DIR__.'/'.$class.".php", |
|
| 36 | 36 | ); |
| 37 | 37 | |
| 38 | 38 | foreach ($paths as $file) { |
@@ -10,77 +10,77 @@ |
||
| 10 | 10 | |
| 11 | 11 | class StringFunctions |
| 12 | 12 | { |
| 13 | - /** |
|
| 14 | - * Formats a string to be used as a username. |
|
| 15 | - * |
|
| 16 | - * @param $username |
|
| 17 | - * |
|
| 18 | - * @return string |
|
| 19 | - */ |
|
| 20 | - public function formatAsUsername($username) |
|
| 21 | - { |
|
| 22 | - // trim whitespace from the ends |
|
| 23 | - $uname = mb_ereg_replace("^[ \t]+|[ \t]+$", "", $username); |
|
| 13 | + /** |
|
| 14 | + * Formats a string to be used as a username. |
|
| 15 | + * |
|
| 16 | + * @param $username |
|
| 17 | + * |
|
| 18 | + * @return string |
|
| 19 | + */ |
|
| 20 | + public function formatAsUsername($username) |
|
| 21 | + { |
|
| 22 | + // trim whitespace from the ends |
|
| 23 | + $uname = mb_ereg_replace("^[ \t]+|[ \t]+$", "", $username); |
|
| 24 | 24 | |
| 25 | - // convert first char to uppercase |
|
| 26 | - $uname = $this->ucfirst($uname); |
|
| 25 | + // convert first char to uppercase |
|
| 26 | + $uname = $this->ucfirst($uname); |
|
| 27 | 27 | |
| 28 | - // replace spaces with underscores |
|
| 29 | - $uname = mb_ereg_replace("[ ]+", "_", $uname); |
|
| 28 | + // replace spaces with underscores |
|
| 29 | + $uname = mb_ereg_replace("[ ]+", "_", $uname); |
|
| 30 | 30 | |
| 31 | - // trim underscores from the end |
|
| 32 | - $uname = mb_ereg_replace("[_]+$", "", $uname); |
|
| 31 | + // trim underscores from the end |
|
| 32 | + $uname = mb_ereg_replace("[_]+$", "", $uname); |
|
| 33 | 33 | |
| 34 | - return $uname; |
|
| 35 | - } |
|
| 34 | + return $uname; |
|
| 35 | + } |
|
| 36 | 36 | |
| 37 | - /** |
|
| 38 | - * Formats a string to be used as an email (specifically strips whitespace |
|
| 39 | - * from the beginning/end of the Email, as well as immediately before/after |
|
| 40 | - * the @ in the Email). |
|
| 41 | - * |
|
| 42 | - * @param $email |
|
| 43 | - * |
|
| 44 | - * @return string |
|
| 45 | - */ |
|
| 46 | - public static function formatAsEmail($email) |
|
| 47 | - { |
|
| 48 | - // trim whitespace from the ends |
|
| 49 | - $newemail = mb_ereg_replace("^[ \t]+|[ \t]+$", "", $email); |
|
| 37 | + /** |
|
| 38 | + * Formats a string to be used as an email (specifically strips whitespace |
|
| 39 | + * from the beginning/end of the Email, as well as immediately before/after |
|
| 40 | + * the @ in the Email). |
|
| 41 | + * |
|
| 42 | + * @param $email |
|
| 43 | + * |
|
| 44 | + * @return string |
|
| 45 | + */ |
|
| 46 | + public static function formatAsEmail($email) |
|
| 47 | + { |
|
| 48 | + // trim whitespace from the ends |
|
| 49 | + $newemail = mb_ereg_replace("^[ \t]+|[ \t]+$", "", $email); |
|
| 50 | 50 | |
| 51 | - // trim whitespace from around the email address |
|
| 52 | - $newemail = mb_ereg_replace("[ \t]+@", "@", $newemail); |
|
| 53 | - $newemail = mb_ereg_replace("@[ \t]+", "@", $newemail); |
|
| 51 | + // trim whitespace from around the email address |
|
| 52 | + $newemail = mb_ereg_replace("[ \t]+@", "@", $newemail); |
|
| 53 | + $newemail = mb_ereg_replace("@[ \t]+", "@", $newemail); |
|
| 54 | 54 | |
| 55 | - return $newemail; |
|
| 56 | - } |
|
| 55 | + return $newemail; |
|
| 56 | + } |
|
| 57 | 57 | |
| 58 | - /** |
|
| 59 | - * Returns true if a string is a multibyte string |
|
| 60 | - * |
|
| 61 | - * @param string $string |
|
| 62 | - * |
|
| 63 | - * @return bool |
|
| 64 | - */ |
|
| 65 | - public function isMultibyte($string) |
|
| 66 | - { |
|
| 67 | - return strlen($string) !== mb_strlen($string); |
|
| 68 | - } |
|
| 58 | + /** |
|
| 59 | + * Returns true if a string is a multibyte string |
|
| 60 | + * |
|
| 61 | + * @param string $string |
|
| 62 | + * |
|
| 63 | + * @return bool |
|
| 64 | + */ |
|
| 65 | + public function isMultibyte($string) |
|
| 66 | + { |
|
| 67 | + return strlen($string) !== mb_strlen($string); |
|
| 68 | + } |
|
| 69 | 69 | |
| 70 | - /** |
|
| 71 | - * Make a string's first character uppercase |
|
| 72 | - * |
|
| 73 | - * @param string $string |
|
| 74 | - * |
|
| 75 | - * @return string |
|
| 76 | - */ |
|
| 77 | - public function ucfirst($string) |
|
| 78 | - { |
|
| 79 | - if (ord($string) < 128) { |
|
| 80 | - return ucfirst($string); |
|
| 81 | - } |
|
| 82 | - else { |
|
| 83 | - return mb_strtoupper(mb_substr($string, 0, 1)) . mb_substr($string, 1); |
|
| 84 | - } |
|
| 85 | - } |
|
| 70 | + /** |
|
| 71 | + * Make a string's first character uppercase |
|
| 72 | + * |
|
| 73 | + * @param string $string |
|
| 74 | + * |
|
| 75 | + * @return string |
|
| 76 | + */ |
|
| 77 | + public function ucfirst($string) |
|
| 78 | + { |
|
| 79 | + if (ord($string) < 128) { |
|
| 80 | + return ucfirst($string); |
|
| 81 | + } |
|
| 82 | + else { |
|
| 83 | + return mb_strtoupper(mb_substr($string, 0, 1)) . mb_substr($string, 1); |
|
| 84 | + } |
|
| 85 | + } |
|
| 86 | 86 | } |
@@ -80,7 +80,7 @@ |
||
| 80 | 80 | return ucfirst($string); |
| 81 | 81 | } |
| 82 | 82 | else { |
| 83 | - return mb_strtoupper(mb_substr($string, 0, 1)) . mb_substr($string, 1); |
|
| 83 | + return mb_strtoupper(mb_substr($string, 0, 1)).mb_substr($string, 1); |
|
| 84 | 84 | } |
| 85 | 85 | } |
| 86 | 86 | } |
@@ -13,14 +13,14 @@ |
||
| 13 | 13 | |
| 14 | 14 | class UpdateTorExitTask extends ConsoleTaskBase |
| 15 | 15 | { |
| 16 | - /** |
|
| 17 | - * @return void |
|
| 18 | - */ |
|
| 19 | - public function execute() |
|
| 20 | - { |
|
| 21 | - TorExitProvider::regenerate( |
|
| 22 | - $this->getDatabase(), |
|
| 23 | - $this->getHttpHelper(), |
|
| 24 | - $this->getSiteConfiguration()->getTorExitPaths()); |
|
| 25 | - } |
|
| 16 | + /** |
|
| 17 | + * @return void |
|
| 18 | + */ |
|
| 19 | + public function execute() |
|
| 20 | + { |
|
| 21 | + TorExitProvider::regenerate( |
|
| 22 | + $this->getDatabase(), |
|
| 23 | + $this->getHttpHelper(), |
|
| 24 | + $this->getSiteConfiguration()->getTorExitPaths()); |
|
| 25 | + } |
|
| 26 | 26 | } |
| 27 | 27 | \ No newline at end of file |