2013-07-19 01:02:06 +02:00
|
|
|
<?php
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Class ParameterConfirmationToken
|
|
|
|
*
|
|
|
|
* When you need to use a dangerous GET parameter that needs to be set before core/Core.php is
|
|
|
|
* established, this class takes care of allowing some other code of confirming the parameter,
|
|
|
|
* by generating a one-time-use token & redirecting with that token included in the redirected URL
|
|
|
|
*
|
|
|
|
* WARNING: This class is experimental and designed specifically for use pre-startup in main.php
|
|
|
|
* It will likely be heavily refactored before the release of 3.2
|
|
|
|
*/
|
|
|
|
class ParameterConfirmationToken {
|
|
|
|
protected $parameterName = null;
|
|
|
|
protected $parameter = null;
|
|
|
|
protected $token = null;
|
|
|
|
|
|
|
|
protected function pathForToken($token) {
|
2013-07-22 03:53:40 +02:00
|
|
|
return TEMP_FOLDER.'/token_'.preg_replace('/[^a-z0-9]+/', '', $token);
|
2013-07-19 01:02:06 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
protected function genToken() {
|
|
|
|
// Generate a new random token (as random as possible)
|
2013-07-19 04:28:50 +02:00
|
|
|
require_once(dirname(dirname(dirname(__FILE__))).'/security/RandomGenerator.php');
|
2013-07-19 01:02:06 +02:00
|
|
|
$rg = new RandomGenerator();
|
|
|
|
$token = $rg->randomToken('md5');
|
|
|
|
|
|
|
|
// Store a file in the session save path (safer than /tmp, as open_basedir might limit that)
|
|
|
|
file_put_contents($this->pathForToken($token), $token);
|
|
|
|
|
|
|
|
return $token;
|
|
|
|
}
|
|
|
|
|
|
|
|
protected function checkToken($token) {
|
|
|
|
$file = $this->pathForToken($token);
|
|
|
|
$content = null;
|
|
|
|
|
|
|
|
if (file_exists($file)) {
|
|
|
|
$content = file_get_contents($file);
|
|
|
|
unlink($file);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $content == $token;
|
|
|
|
}
|
|
|
|
|
|
|
|
public function __construct($parameterName) {
|
|
|
|
// Store the parameter name
|
|
|
|
$this->parameterName = $parameterName;
|
|
|
|
// Store the parameter value
|
|
|
|
$this->parameter = isset($_GET[$parameterName]) ? $_GET[$parameterName] : null;
|
|
|
|
// Store the token
|
|
|
|
$this->token = isset($_GET[$parameterName.'token']) ? $_GET[$parameterName.'token'] : null;
|
|
|
|
|
2013-07-19 05:04:50 +02:00
|
|
|
// If a token was provided, but isn't valid, ignore it
|
|
|
|
if ($this->token && (!$this->checkToken($this->token))) $this->token = null;
|
2013-07-19 01:02:06 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
public function parameterProvided() {
|
|
|
|
return $this->parameter !== null;
|
|
|
|
}
|
|
|
|
|
|
|
|
public function tokenProvided() {
|
|
|
|
return $this->token !== null;
|
|
|
|
}
|
|
|
|
|
|
|
|
public function params() {
|
|
|
|
return array(
|
|
|
|
$this->parameterName => $this->parameter,
|
|
|
|
$this->parameterName.'token' => $this->genToken()
|
|
|
|
);
|
|
|
|
}
|
|
|
|
|
|
|
|
public function reloadWithToken() {
|
|
|
|
global $url;
|
|
|
|
|
|
|
|
// Are we http or https?
|
|
|
|
$proto = 'http';
|
|
|
|
|
|
|
|
if(isset($_SERVER['HTTP_X_FORWARDED_PROTOCOL'])) {
|
|
|
|
if(strtolower($_SERVER['HTTP_X_FORWARDED_PROTOCOL']) == 'https') $proto = 'https';
|
|
|
|
}
|
|
|
|
|
|
|
|
if((!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off')) $proto = 'https';
|
|
|
|
if(isset($_SERVER['SSL'])) $proto = 'https';
|
|
|
|
|
|
|
|
// What's our host
|
|
|
|
$host = $_SERVER['HTTP_HOST'];
|
|
|
|
|
|
|
|
// What's our GET params (ensuring they include the original parameter + a new token)
|
|
|
|
$params = array_merge($_GET, $this->params());
|
|
|
|
unset($params['url']);
|
|
|
|
|
|
|
|
// Join them all together into the original URL
|
2013-12-18 03:44:30 +01:00
|
|
|
$location = "$proto://" . $host . (strlen(trim(BASE_URL, '/')) > 0 ? '/' . trim(BASE_URL, '/') : '' ) . (strlen(trim($url, '/')) > 0 ? '/' . trim($url, '/') : '' ) . ($params ? '?'.http_build_query($params) : '');
|
2013-07-19 01:02:06 +02:00
|
|
|
|
|
|
|
// And redirect
|
2013-07-31 23:42:52 +02:00
|
|
|
if (headers_sent()) {
|
|
|
|
echo "
|
|
|
|
<script>location.href='$location';</script>
|
|
|
|
<noscript><meta http-equiv='refresh' content='0; url=$location'></noscript>
|
|
|
|
You are being redirected. If you are not redirected soon, <a href='$location'>click here to continue the flush</a>
|
|
|
|
";
|
|
|
|
}
|
|
|
|
else header('location: '.$location, true, 302);
|
2013-07-19 01:02:06 +02:00
|
|
|
die;
|
|
|
|
}
|
|
|
|
}
|