discuz_admincp.php 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311
  1. <?php
  2. /**
  3. * [Discuz!] (C)2001-2099 Comsenz Inc.
  4. * This is NOT a freeware, use is subject to license terms
  5. *
  6. * $Id: discuz_admincp.php 31471 2012-08-31 07:33:26Z zhengqingpeng $
  7. */
  8. if(!defined('IN_DISCUZ')) {
  9. exit('Access Denied');
  10. }
  11. class discuz_admincp
  12. {
  13. var $core = null;
  14. var $script = null;
  15. var $userlogin = false;
  16. var $adminsession = array();
  17. var $adminuser = array();
  18. var $perms = null;
  19. var $panel = 1;
  20. var $isfounder = false;
  21. var $cpsetting = array();
  22. var $cpaccess = 0;
  23. var $sessionlife = 1800;
  24. var $sessionlimit = 0;
  25. function &instance() {
  26. static $object;
  27. if(empty($object)) {
  28. $object = new discuz_admincp();
  29. }
  30. return $object;
  31. }
  32. function __construct() {
  33. ;
  34. }
  35. function init() {
  36. if(empty($this->core) || !is_object($this->core)) {
  37. exit('No Discuz core found');
  38. }
  39. $this->cpsetting = $this->core->config['admincp'];
  40. $this->adminuser = & $this->core->var['member'];
  41. $this->isfounder = $this->checkfounder($this->adminuser);
  42. $this->sessionlimit = TIMESTAMP - $this->sessionlife;
  43. $this->check_cpaccess();
  44. $this->writecplog();
  45. }
  46. function writecplog() {
  47. global $_G;
  48. $extralog = implodearray(array('GET' => $_GET, 'POST' => $_POST), array('formhash', 'submit', 'addsubmit', 'admin_password', 'sid', 'action'));
  49. writelog('cplog', implode("\t", clearlogstring(array($_G['timestamp'], $_G['username'], $_G['adminid'], $_G['clientip'], getgpc('action'), $extralog))));
  50. }
  51. function check_cpaccess() {
  52. global $_G;
  53. $session = array();
  54. if(!$this->adminuser['uid']) {
  55. $this->cpaccess = 0;
  56. } else {
  57. if(!$this->isfounder) {
  58. $session = C::t('common_admincp_member')->fetch($this->adminuser['uid']);
  59. if($session) {
  60. $session = array_merge($session, C::t('common_admincp_session')->fetch($this->adminuser['uid'], $this->panel));
  61. }
  62. } else {
  63. $session = C::t('common_admincp_session')->fetch($this->adminuser['uid'], $this->panel);
  64. }
  65. if(empty($session)) {
  66. $this->cpaccess = $this->isfounder ? 1 : -2;
  67. } elseif($_G['setting']['adminipaccess'] && !ipaccess($_G['clientip'], $_G['setting']['adminipaccess'])) {
  68. $this->do_user_login();
  69. } elseif ($session && empty($session['uid'])) {
  70. $this->cpaccess = 1;
  71. } elseif ($session['dateline'] < $this->sessionlimit) {
  72. $this->cpaccess = 1;
  73. } elseif ($this->cpsetting['checkip'] && ($session['ip'] != $this->core->var['clientip'])) {
  74. $this->cpaccess = 1;
  75. } elseif ($session['errorcount'] >= 0 && $session['errorcount'] <= 3) {
  76. $this->cpaccess = 2;
  77. } elseif ($session['errorcount'] == -1) {
  78. $this->cpaccess = 3;
  79. } else {
  80. $this->cpaccess = -1;
  81. }
  82. }
  83. if($this->cpaccess == 2 || $this->cpaccess == 3) {
  84. if(!empty($session['customperm'])) {
  85. $session['customperm'] = dunserialize($session['customperm']);
  86. }
  87. }
  88. $this->adminsession = $session;
  89. if($_SERVER['REQUEST_METHOD'] == 'POST' && isset($_POST['admin_password'])) {
  90. if($this->cpaccess == 2) {
  91. $this->check_admin_login();
  92. } elseif($this->cpaccess == 0) {
  93. $this->check_user_login();
  94. }
  95. }
  96. if($this->cpaccess == 1) {
  97. C::t('common_admincp_session')->delete($this->adminuser['uid'], $this->panel, $this->sessionlife);
  98. C::t('common_admincp_session')->insert(array(
  99. 'uid' => $this->adminuser['uid'],
  100. 'adminid' => $this->adminuser['adminid'],
  101. 'panel' => $this->panel,
  102. 'ip' => $this->core->var['clientip'],
  103. 'dateline' => TIMESTAMP,
  104. 'errorcount' => 0,
  105. ));
  106. } elseif ($this->cpaccess == 3) {
  107. $this->load_admin_perms();
  108. C::t('common_admincp_session')->update($this->adminuser['uid'], $this->panel, array('dateline' => TIMESTAMP, 'ip' => $this->core->var['clientip'], 'errorcount' => -1));
  109. }
  110. if($this->cpaccess != 3) {
  111. $this->do_user_login();
  112. }
  113. }
  114. function check_admin_login() {
  115. global $_G;
  116. if((empty($_POST['admin_questionid']) || empty($_POST['admin_answer'])) && ($_G['config']['admincp']['forcesecques'] || $_G['group']['forcesecques'])) {
  117. $this->do_user_login();
  118. }
  119. loaducenter();
  120. $ucresult = uc_user_login($this->adminuser['uid'], $_POST['admin_password'], 1, 1, $_POST['admin_questionid'], $_POST['admin_answer'], $this->core->var['clientip']);
  121. if($ucresult[0] > 0) {
  122. C::t('common_admincp_session')->update($this->adminuser['uid'], $this->panel, array('dateline' => TIMESTAMP, 'ip' => $this->core->var['clientip'], 'errorcount' => -1));
  123. dheader('Location: '.ADMINSCRIPT.'?'.cpurl('url', array('sid')));
  124. } else {
  125. $errorcount = $this->adminsession['errorcount'] + 1;
  126. C::t('common_admincp_session')->update($this->adminuser['uid'], $this->panel, array('dateline' => TIMESTAMP, 'ip' => $this->core->var['clientip'], 'errorcount' => $errorcount));
  127. }
  128. }
  129. function check_user_login() {
  130. global $_G;
  131. $admin_username = isset($_POST['admin_username']) ? trim($_POST['admin_username']) : '';
  132. if($admin_username != '') {
  133. require_once libfile('function/member');
  134. if(logincheck($_POST['admin_username'])) {
  135. if((empty($_POST['admin_questionid']) || empty($_POST['admin_answer'])) && ($_G['config']['admincp']['forcesecques'] || $_G['group']['forcesecques'])) {
  136. $this->do_user_login();
  137. }
  138. $result = userlogin($_POST['admin_username'], $_POST['admin_password'], $_POST['admin_questionid'], $_POST['admin_answer'], 'username', $this->core->var['clientip']);
  139. if($result['status'] == 1) {
  140. $cpgroupid = C::t('common_admincp_member')->fetch($result['member']['uid']);
  141. $cpgroupid = $cpgroupid['uid'];
  142. if($cpgroupid || $this->checkfounder($result['member'])) {
  143. C::t('common_admincp_session')->insert(array(
  144. 'uid' =>$result['member']['uid'],
  145. 'adminid' =>$result['member']['adminid'],
  146. 'panel' =>$this->panel,
  147. 'dateline' => TIMESTAMP,
  148. 'ip' => $this->core->var['clientip'],
  149. 'errorcount' => -1), false, true);
  150. setloginstatus($result['member'], 0);
  151. dheader('Location: '.ADMINSCRIPT.'?'.cpurl('url', array('sid')));
  152. } else {
  153. $this->cpaccess = -2;
  154. }
  155. } else {
  156. loginfailed($_POST['admin_username']);
  157. }
  158. } else {
  159. $this->cpaccess = -4;
  160. }
  161. }
  162. }
  163. function allow($action, $operation, $do) {
  164. if($this->perms === null) {
  165. $this->load_admin_perms();
  166. }
  167. if(isset($this->perms['all'])) {
  168. return $this->perms['all'];
  169. }
  170. if(!empty($_POST) && !array_key_exists('_allowpost', $this->perms) && $action.'_'.$operation != 'misc_custommenu') {
  171. return false;
  172. }
  173. $this->perms['misc_custommenu'] = 1;
  174. $key = $action;
  175. if(isset($this->perms[$key])) {
  176. return $this->perms[$key];
  177. }
  178. $key = $action.'_'.$operation;
  179. if(isset($this->perms[$key])) {
  180. return $this->perms[$key];
  181. }
  182. $key = $action.'_'.$operation.'_'.$do;
  183. if(isset($this->perms[$key])) {
  184. return $this->perms[$key];
  185. }
  186. return false;
  187. }
  188. function load_admin_perms() {
  189. $this->perms = array();
  190. if(!$this->isfounder) {
  191. if($this->adminsession['cpgroupid']) {
  192. foreach(C::t('common_admincp_perm')->fetch_all_by_cpgroupid($this->adminsession['cpgroupid']) as $perm) {
  193. if(empty($this->adminsession['customperm'])) {
  194. $this->perms[$perm['perm']] = true;
  195. } elseif(!in_array($perm['perm'], (array)$this->adminsession['customperm'])) {
  196. $this->perms[$perm['perm']] = true;
  197. }
  198. }
  199. } else {
  200. $this->perms['all'] = true;
  201. }
  202. } else {
  203. $this->perms['all'] = true;
  204. }
  205. }
  206. function checkfounder($user) {
  207. $founders = str_replace(' ', '', $this->cpsetting['founder']);
  208. if(!$user['uid'] || $user['groupid'] != 1 || $user['adminid'] != 1) {
  209. return false;
  210. } elseif(empty($founders)) {
  211. return true;
  212. } elseif(strexists(",$founders,", ",$user[uid],")) {
  213. return true;
  214. } elseif(!is_numeric($user['username']) && strexists(",$founders,", ",$user[username],")) {
  215. return true;
  216. } else {
  217. return FALSE;
  218. }
  219. }
  220. function do_user_login() {
  221. require $this->admincpfile('login');
  222. }
  223. function do_admin_logout() {
  224. C::t('common_admincp_session')->delete($this->adminuser['uid'], $this->panel, $this->sessionlife);
  225. }
  226. function admincpfile($action) {
  227. return './source/admincp/admincp_'.$action.'.php';
  228. }
  229. function show_admincp_main() {
  230. $this->do_request('main');
  231. }
  232. function show_no_access() {
  233. cpheader();
  234. cpmsg('action_noaccess', '', 'error');
  235. cpfooter();
  236. }
  237. function do_request($action) {
  238. global $_G;
  239. $lang = lang('admincp');
  240. $title = 'cplog_'.getgpc('action').(getgpc('operation') ? '_'.getgpc('operation') : '');
  241. $operation = getgpc('operation');
  242. $do = getgpc('do');
  243. $sid = $_G['sid'];
  244. $isfounder = $this->isfounder;
  245. if($action == 'main' || $this->allow($action, $operation, $do)) {
  246. require './source/admincp/admincp_'.$action.'.php';
  247. } else {
  248. cpheader();
  249. cpmsg('action_noaccess', '', 'error');
  250. }
  251. }
  252. }