@@ -27,12 +27,12 @@ discard block |
||
| 27 | 27 | private static function signVals($key, $vals, $prefix, $expire, $time = null) |
| 28 | 28 | { |
| 29 | 29 | $exp = ($time ? $time : time()) + $expire; |
| 30 | - $val = $vals . '|' . $exp; |
|
| 30 | + $val = $vals.'|'.$exp; |
|
| 31 | 31 | $b64 = base64_encode($val); |
| 32 | - $cookie = $prefix . '|' . $b64; |
|
| 32 | + $cookie = $prefix.'|'.$b64; |
|
| 33 | 33 | |
| 34 | 34 | $sig = hash_hmac("sha1", $cookie, $key); |
| 35 | - return $cookie . '|' . $sig; |
|
| 35 | + return $cookie.'|'.$sig; |
|
| 36 | 36 | } |
| 37 | 37 | |
| 38 | 38 | private static function parseVals($key, $val, $prefix, $ikey, $time = null) |
@@ -45,7 +45,7 @@ discard block |
||
| 45 | 45 | } |
| 46 | 46 | list($u_prefix, $u_b64, $u_sig) = $parts; |
| 47 | 47 | |
| 48 | - $sig = hash_hmac("sha1", $u_prefix . '|' . $u_b64, $key); |
|
| 48 | + $sig = hash_hmac("sha1", $u_prefix.'|'.$u_b64, $key); |
|
| 49 | 49 | if (hash_hmac("sha1", $sig, $key) !== hash_hmac("sha1", $u_sig, $key)) { |
| 50 | 50 | return null; |
| 51 | 51 | } |
@@ -88,12 +88,12 @@ discard block |
||
| 88 | 88 | return self::ERR_AKEY; |
| 89 | 89 | } |
| 90 | 90 | |
| 91 | - $vals = $username . '|' . $ikey; |
|
| 91 | + $vals = $username.'|'.$ikey; |
|
| 92 | 92 | |
| 93 | 93 | $duo_sig = self::signVals($skey, $vals, self::DUO_PREFIX, self::DUO_EXPIRE, $time); |
| 94 | 94 | $app_sig = self::signVals($akey, $vals, self::APP_PREFIX, self::APP_EXPIRE, $time); |
| 95 | 95 | |
| 96 | - return $duo_sig . ':' . $app_sig; |
|
| 96 | + return $duo_sig.':'.$app_sig; |
|
| 97 | 97 | } |
| 98 | 98 | |
| 99 | 99 | public static function verifyResponse($ikey, $skey, $akey, $sig_response, $time = null) |
@@ -91,33 +91,33 @@ discard block |
||
| 91 | 91 | require_once $SETTINGS['cpassman_dir'].'/sources/core.php'; |
| 92 | 92 | |
| 93 | 93 | // Prepare POST variables |
| 94 | -$post_language = filter_input(INPUT_POST, 'language', FILTER_SANITIZE_STRING); |
|
| 95 | -$post_sig_response = filter_input(INPUT_POST, 'sig_response', FILTER_SANITIZE_STRING); |
|
| 96 | -$post_duo_login = filter_input(INPUT_POST, 'duo_login', FILTER_SANITIZE_STRING); |
|
| 97 | -$post_duo_data = filter_input(INPUT_POST, 'duo_data', FILTER_SANITIZE_STRING); |
|
| 98 | -$post_login = filter_input(INPUT_POST, 'login', FILTER_SANITIZE_STRING); |
|
| 99 | -$post_pw = filter_input(INPUT_POST, 'pw', FILTER_SANITIZE_STRING); |
|
| 94 | +$post_language = filter_input(INPUT_POST, 'language', FILTER_SANITIZE_STRING); |
|
| 95 | +$post_sig_response = filter_input(INPUT_POST, 'sig_response', FILTER_SANITIZE_STRING); |
|
| 96 | +$post_duo_login = filter_input(INPUT_POST, 'duo_login', FILTER_SANITIZE_STRING); |
|
| 97 | +$post_duo_data = filter_input(INPUT_POST, 'duo_data', FILTER_SANITIZE_STRING); |
|
| 98 | +$post_login = filter_input(INPUT_POST, 'login', FILTER_SANITIZE_STRING); |
|
| 99 | +$post_pw = filter_input(INPUT_POST, 'pw', FILTER_SANITIZE_STRING); |
|
| 100 | 100 | |
| 101 | 101 | // Prepare superGlobal variables |
| 102 | -$session_user_language = $superGlobal->get("user_language", "SESSION"); |
|
| 103 | -$session_user_id = $superGlobal->get("user_id", "SESSION"); |
|
| 104 | -$session_user_flag = $superGlobal->get("user_language_flag", "SESSION"); |
|
| 105 | -$session_user_admin = $superGlobal->get("user_admin", "SESSION"); |
|
| 106 | -$session_user_avatar_thumb = $superGlobal->get("user_avatar_thumb", "SESSION"); |
|
| 107 | -$session_name = $superGlobal->get("name", "SESSION"); |
|
| 108 | -$session_lastname = $superGlobal->get("lastname", "SESSION"); |
|
| 109 | -$session_user_manager = $superGlobal->get("user_manager", "SESSION"); |
|
| 110 | -$session_user_read_only = $superGlobal->get("user_read_only", "SESSION"); |
|
| 111 | -$session_is_admin = $superGlobal->get("is_admin", "SESSION"); |
|
| 112 | -$session_login = $superGlobal->get("login", "SESSION"); |
|
| 113 | -$session_validite_pw = $superGlobal->get("validite_pw", "SESSION"); |
|
| 114 | -$session_nb_folders = $superGlobal->get("nb_folders", "SESSION"); |
|
| 115 | -$session_nb_roles = $superGlobal->get("nb_roles", "SESSION"); |
|
| 116 | -$session_autoriser = $superGlobal->get("autoriser", "SESSION"); |
|
| 117 | -$session_hide_maintenance = $superGlobal->get("hide_maintenance", "SESSION"); |
|
| 118 | -$session_initial_url = $superGlobal->get("initial_url", "SESSION"); |
|
| 119 | -$server_request_uri = $superGlobal->get("REQUEST_URI", "SERVER"); |
|
| 120 | -$session_nb_users_online = $superGlobal->get("nb_users_online", "SESSION"); |
|
| 102 | +$session_user_language = $superGlobal->get("user_language", "SESSION"); |
|
| 103 | +$session_user_id = $superGlobal->get("user_id", "SESSION"); |
|
| 104 | +$session_user_flag = $superGlobal->get("user_language_flag", "SESSION"); |
|
| 105 | +$session_user_admin = $superGlobal->get("user_admin", "SESSION"); |
|
| 106 | +$session_user_avatar_thumb = $superGlobal->get("user_avatar_thumb", "SESSION"); |
|
| 107 | +$session_name = $superGlobal->get("name", "SESSION"); |
|
| 108 | +$session_lastname = $superGlobal->get("lastname", "SESSION"); |
|
| 109 | +$session_user_manager = $superGlobal->get("user_manager", "SESSION"); |
|
| 110 | +$session_user_read_only = $superGlobal->get("user_read_only", "SESSION"); |
|
| 111 | +$session_is_admin = $superGlobal->get("is_admin", "SESSION"); |
|
| 112 | +$session_login = $superGlobal->get("login", "SESSION"); |
|
| 113 | +$session_validite_pw = $superGlobal->get("validite_pw", "SESSION"); |
|
| 114 | +$session_nb_folders = $superGlobal->get("nb_folders", "SESSION"); |
|
| 115 | +$session_nb_roles = $superGlobal->get("nb_roles", "SESSION"); |
|
| 116 | +$session_autoriser = $superGlobal->get("autoriser", "SESSION"); |
|
| 117 | +$session_hide_maintenance = $superGlobal->get("hide_maintenance", "SESSION"); |
|
| 118 | +$session_initial_url = $superGlobal->get("initial_url", "SESSION"); |
|
| 119 | +$server_request_uri = $superGlobal->get("REQUEST_URI", "SERVER"); |
|
| 120 | +$session_nb_users_online = $superGlobal->get("nb_users_online", "SESSION"); |
|
| 121 | 121 | |
| 122 | 122 | |
| 123 | 123 | /* DEFINE WHAT LANGUAGE TO USE */ |
@@ -237,9 +237,7 @@ discard block |
||
| 237 | 237 | <div style="float:right; margin:-10px 5px 0 0; color:#FFF;">' |
| 238 | 238 | .$LANG['index_welcome'].' <b>'.$session_name.' '.$session_lastname |
| 239 | 239 | .' ['.$session_login.']</b> - ' |
| 240 | - , $session_user_admin === '1' ? $LANG['god'] : |
|
| 241 | - ($session_user_manager === '1' ? $LANG['gestionnaire'] : |
|
| 242 | - ($session_user_read_only === '1' ? $LANG['read_only_account'] : $LANG['user']) |
|
| 240 | + , $session_user_admin === '1' ? $LANG['god'] : ($session_user_manager === '1' ? $LANG['gestionnaire'] : ($session_user_read_only === '1' ? $LANG['read_only_account'] : $LANG['user']) |
|
| 243 | 241 | ), ' '.strtolower($LANG['index_login']).'</div>'; |
| 244 | 242 | |
| 245 | 243 | echo ' |