lainchan/mod.php

166 lines
5.6 KiB
PHP
Raw Normal View History

2010-12-01 05:53:11 -05:00
<?php
2012-04-11 12:49:22 -04:00
/*
* Copyright (c) 2010-2012 Tinyboard Development Group
*/
require 'inc/functions.php';
2012-04-12 12:11:41 -04:00
require 'inc/mod/auth.php';
require 'inc/mod/pages.php';
2012-04-11 12:49:22 -04:00
2012-04-12 12:11:41 -04:00
// Fix for magic quotes
2012-04-11 12:49:22 -04:00
if (get_magic_quotes_gpc()) {
function strip_array($var) {
return is_array($var) ? array_map('strip_array', $var) : stripslashes($var);
2012-04-11 12:49:22 -04:00
}
2010-12-01 05:53:11 -05:00
2012-04-11 12:49:22 -04:00
$_GET = strip_array($_GET);
$_POST = strip_array($_POST);
}
$query = isset($_SERVER['QUERY_STRING']) ? $_SERVER['QUERY_STRING'] : '';
2012-04-12 12:11:41 -04:00
$pages = array(
2012-05-05 22:44:37 -04:00
'' => ':?/', // redirect to dashboard
'/' => 'dashboard', // dashboard
'/confirm/(.+)' => 'confirm', // confirm action (if javascript didn't work)
'/logout' => 'logout', // logout
2012-04-16 02:40:24 -04:00
2012-05-05 22:44:37 -04:00
'/users' => 'users', // manage users
'/users/(\d+)' => 'user', // edit user
'/users/(\d+)/(promote|demote)' => 'user_promote', // prmote/demote user
'/users/new' => 'user_new', // create a new user
'/new_PM/([^/]+)' => 'new_pm', // create a new pm
'/PM/(\d+)(/reply)?' => 'pm', // read a pm
'/inbox' => 'inbox', // pm inbox
2012-04-12 20:41:30 -04:00
2012-05-05 22:44:37 -04:00
'/noticeboard' => 'noticeboard', // view noticeboard
'/noticeboard/(\d+)' => 'noticeboard', // view noticeboard
'/noticeboard/delete/(\d+)' => 'noticeboard_delete',// delete from noticeboard
'/log' => 'log', // modlog
'/log/(\d+)' => 'log', // modlog
2012-08-27 08:13:47 -04:00
'/log:([^/]+)' => 'user_log', // modlog
'/log:([^/]+)/(\d+)' => 'user_log', // modlog
2012-05-05 22:44:37 -04:00
'/news' => 'news', // view news
'/news/(\d+)' => 'news', // view news
'/news/delete/(\d+)' => 'news_delete', // delete from news
2012-05-05 11:33:10 -04:00
2012-05-05 22:44:37 -04:00
'/edit/(\w+)' => 'edit_board', // edit board details
'/new-board' => 'new_board', // create a new board
2012-05-05 11:33:10 -04:00
2012-05-05 22:44:37 -04:00
'/rebuild' => 'rebuild', // rebuild static files
'/reports' => 'reports', // report queue
'/reports/(\d+)/dismiss(all)?' => 'report_dismiss', // dismiss a report
2012-05-05 22:44:37 -04:00
'/IP/([\w.:]+)' => 'ip', // view ip address
'/IP/([\w.:]+)/remove_note/(\d+)' => 'ip_remove_note', // remove note from ip address
'/bans' => 'bans', // ban list
'/bans/(\d+)' => 'bans', // ban list
2012-08-27 01:19:05 -04:00
// CSRF-protected moderator actions
'/ban' => 'secure_POST ban', // new ban
'/([\w+.]+)/ban(&delete)?/(\d+)' => 'secure_POST ban_post', // ban poster
'/([\w+.]+)/move/(\d+)' => 'secure_POST move', // move thread
'/([\w+.]+)/delete/(\d+)' => 'secure delete', // delete post
'/([\w+.]+)/deletefile/(\d+)' => 'secure deletefile', // delete file from post
'/([\w+.]+)/deletebyip/(\d+)(/global)?' => 'secure deletebyip', // delete all posts by IP address
'/([\w+.]+)/(un)?lock/(\d+)' => 'secure lock', // lock thread
'/([\w+.]+)/(un)?sticky/(\d+)' => 'secure sticky', // sticky thread
'/([\w+.]+)/bump(un)?lock/(\d+)' => 'secure bumplock', // "bumplock" thread
2012-04-16 06:11:10 -04:00
2012-08-12 10:18:13 -04:00
'/themes' => 'themes_list', // manage themes
'/themes/(\w+)' => 'theme_configure', // configure/reconfigure theme
'/themes/(\w+)/rebuild' => 'theme_rebuild', // rebuild theme
'/themes/(\w+)/uninstall' => 'theme_uninstall', // uninstall theme
2012-05-20 06:20:50 -04:00
'/config' => 'config', // config editor
2012-04-16 06:11:10 -04:00
// these pages aren't listed in the dashboard without $config['debug']
2012-05-05 22:44:37 -04:00
'/debug/antispam' => 'debug_antispam',
2012-04-11 12:49:22 -04:00
2012-04-12 12:11:41 -04:00
// This should always be at the end:
'/([\w+.]+)/' => 'view_board',
'/([\w+.]+)/' . preg_quote($config['file_index'], '!') => 'view_board',
'/([\w+.]+)/' . str_replace('%d', '(\d+)', preg_quote($config['file_page'], '!')) => 'view_board',
'/([\w+.]+)/' . preg_quote($config['dir']['res'], '!') .
2012-05-05 22:44:37 -04:00
str_replace('%d', '(\d+)', preg_quote($config['file_page'], '!')) => 'view_thread',
2012-04-12 12:11:41 -04:00
);
2012-05-05 11:33:10 -04:00
if (!$mod) {
2012-05-05 22:44:37 -04:00
$pages = array('!!' => 'login');
2012-05-05 11:33:10 -04:00
} elseif (isset($_GET['status'], $_GET['r'])) {
2012-05-05 22:29:54 -04:00
header('Location: ' . $_GET['r'], true, (int)$_GET['status']);
2012-05-05 22:44:37 -04:00
exit;
}
if (isset($config['mod']['custom_pages'])) {
2012-05-05 11:33:10 -04:00
$pages = array_merge($pages, $config['mod']['custom_pages']);
}
2012-04-12 12:11:41 -04:00
2012-05-05 22:44:37 -04:00
$new_pages = array();
foreach ($pages as $key => $callback) {
2012-08-27 01:19:05 -04:00
if (preg_match('/^secure /', $callback))
$key .= '(/(?P<token>[a-f0-9]{8}))?';
2012-05-05 22:44:37 -04:00
$new_pages[@$key[0] == '!' ? $key : "!^$key$!"] = $callback;
}
$pages = $new_pages;
2012-04-12 12:11:41 -04:00
foreach ($pages as $uri => $handler) {
if (preg_match($uri, $query, $matches)) {
$matches = array_slice($matches, 1);
2012-08-27 01:19:05 -04:00
if (preg_match('/^secure(_POST)? /', $handler, $m)) {
$secure_post_only = isset($m[1]);
if (!$secure_post_only || $_SERVER['REQUEST_METHOD'] == 'POST') {
$token = isset($matches['token']) ? $matches['token'] : (isset($_POST['token']) ? $_POST['token'] : false);
if ($token === false) {
if ($secure_post_only)
error($config['error']['csrf']);
else {
mod_confirm(substr($query, 1));
exit;
}
}
// CSRF-protected page; validate security token
$actual_query = preg_replace('!/([a-f0-9]{8})$!', '', $query);
if ($token != make_secure_link_token(substr($actual_query, 1))) {
error($config['error']['csrf']);
}
}
$handler = preg_replace('/^secure(_POST)? /', '', $handler);
}
2012-04-12 12:11:41 -04:00
if ($config['debug']) {
$debug['mod_page'] = array(
'req' => $query,
'match' => $uri,
'handler' => $handler
2012-04-11 12:49:22 -04:00
);
}
2012-05-05 11:33:10 -04:00
if (is_string($handler)) {
if ($handler[0] == ':') {
header('Location: ' . substr($handler, 1), true, $config['redirect_http']);
} elseif (is_callable("mod_page_$handler")) {
call_user_func_array("mod_page_$handler", $matches);
} elseif (is_callable("mod_$handler")) {
call_user_func_array("mod_$handler", $matches);
} else {
error("Mod page '$handler' not found!");
}
} elseif (is_callable($handler)) {
call_user_func_array($handler, $matches);
2012-04-11 12:49:22 -04:00
} else {
2012-05-05 11:33:10 -04:00
error("Mod page '$handler' not a string, and not callable!");
2012-04-11 12:49:22 -04:00
}
2012-04-12 12:11:41 -04:00
exit;
2010-12-01 05:53:11 -05:00
}
2012-04-11 12:49:22 -04:00
}
2012-04-12 12:11:41 -04:00
error($config['error']['404']);