LogInOut.php 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790
  1. <?php
  2. /**
  3. * This file is concerned pretty entirely, as you see from its name, with
  4. * logging in and out members, and the validation of that.
  5. *
  6. * Simple Machines Forum (SMF)
  7. *
  8. * @package SMF
  9. * @author Simple Machines http://www.simplemachines.org
  10. * @copyright 2014 Simple Machines and individual contributors
  11. * @license http://www.simplemachines.org/about/smf/license.php BSD
  12. *
  13. * @version 2.1 Alpha 1
  14. */
  15. if (!defined('SMF'))
  16. die('No direct access...');
  17. /**
  18. * Ask them for their login information. (shows a page for the user to type
  19. * in their username and password.)
  20. * It caches the referring URL in $_SESSION['login_url'].
  21. * It is accessed from ?action=login.
  22. * @uses Login template and language file with the login sub-template.
  23. * @uses the protocol_login sub-template in the Wireless template,
  24. * if you are using a wireless device
  25. */
  26. function Login()
  27. {
  28. global $txt, $context, $scripturl, $user_info;
  29. // You are already logged in, go take a tour of the boards
  30. if (!empty($user_info['id']))
  31. redirectexit();
  32. // In wireless? If so, use the correct sub template.
  33. if (WIRELESS)
  34. $context['sub_template'] = WIRELESS_PROTOCOL . '_login';
  35. // Otherwise, we need to load the Login template/language file.
  36. else
  37. {
  38. loadLanguage('Login');
  39. $context['sub_template'] = 'login';
  40. if (!empty($_SERVER['HTTP_X_REQUESTED_WITH']) && $_SERVER['HTTP_X_REQUESTED_WITH'] == 'XMLHttpRequest')
  41. {
  42. $context['from_ajax'] = true;
  43. $context['template_layers'] = array();
  44. }
  45. }
  46. // Get the template ready.... not really much else to do.
  47. $context['page_title'] = $txt['login'];
  48. $context['default_username'] = &$_REQUEST['u'];
  49. $context['default_password'] = '';
  50. $context['never_expire'] = false;
  51. // Add the login chain to the link tree.
  52. $context['linktree'][] = array(
  53. 'url' => $scripturl . '?action=login',
  54. 'name' => $txt['login'],
  55. );
  56. // Set the login URL - will be used when the login process is done (but careful not to send us to an attachment).
  57. if (isset($_SESSION['old_url']) && strpos($_SESSION['old_url'], 'dlattach') === false && preg_match('~(board|topic)[=,]~', $_SESSION['old_url']) != 0)
  58. $_SESSION['login_url'] = $_SESSION['old_url'];
  59. else
  60. unset($_SESSION['login_url']);
  61. // Need some js goodies.
  62. loadJavascriptFile('sha1.js', array('default_theme' => true), 'smf_sha1');
  63. // Create a one time token.
  64. createToken('login');
  65. }
  66. /**
  67. * Actually logs you in.
  68. * What it does:
  69. * - checks credentials and checks that login was successful.
  70. * - it employs protection against a specific IP or user trying to brute force
  71. * a login to an account.
  72. * - upgrades password encryption on login, if necessary.
  73. * - after successful login, redirects you to $_SESSION['login_url'].
  74. * - accessed from ?action=login2, by forms.
  75. * On error, uses the same templates Login() uses.
  76. */
  77. function Login2()
  78. {
  79. global $txt, $scripturl, $user_info, $user_settings, $smcFunc;
  80. global $cookiename, $modSettings, $context, $sc, $sourcedir;
  81. // Load cookie authentication stuff.
  82. require_once($sourcedir . '/Subs-Auth.php');
  83. if (isset($_GET['sa']) && $_GET['sa'] == 'salt' && !$user_info['is_guest'])
  84. {
  85. if (isset($_COOKIE[$cookiename]) && preg_match('~^a:[34]:\{i:0;i:\d{1,7};i:1;s:(0|40):"([a-fA-F0-9]{40})?";i:2;[id]:\d{1,14};(i:3;i:\d;)?\}$~', $_COOKIE[$cookiename]) === 1)
  86. list (, , $timeout) = @unserialize($_COOKIE[$cookiename]);
  87. elseif (isset($_SESSION['login_' . $cookiename]))
  88. list (, , $timeout) = @unserialize($_SESSION['login_' . $cookiename]);
  89. else
  90. trigger_error('Login2(): Cannot be logged in without a session or cookie', E_USER_ERROR);
  91. $user_settings['password_salt'] = substr(md5(mt_rand()), 0, 4);
  92. updateMemberData($user_info['id'], array('password_salt' => $user_settings['password_salt']));
  93. setLoginCookie($timeout - time(), $user_info['id'], sha1($user_settings['passwd'] . $user_settings['password_salt']));
  94. redirectexit('action=login2;sa=check;member=' . $user_info['id'], $context['server']['needs_login_fix']);
  95. }
  96. // Double check the cookie...
  97. elseif (isset($_GET['sa']) && $_GET['sa'] == 'check')
  98. {
  99. // Strike! You're outta there!
  100. if ($_GET['member'] != $user_info['id'])
  101. fatal_lang_error('login_cookie_error', false);
  102. $user_info['can_mod'] = allowedTo('access_mod_center') || (!$user_info['is_guest'] && ($user_info['mod_cache']['gq'] != '0=1' || $user_info['mod_cache']['bq'] != '0=1' || ($modSettings['postmod_active'] && !empty($user_info['mod_cache']['ap']))));
  103. if ($user_info['can_mod'] && isset($user_settings['openid_uri']) && empty($user_settings['openid_uri']))
  104. {
  105. $_SESSION['moderate_time'] = time();
  106. unset($_SESSION['just_registered']);
  107. }
  108. // Some whitelisting for login_url...
  109. if (empty($_SESSION['login_url']))
  110. redirectexit();
  111. elseif (!empty($_SESSION['login_url']) && (strpos('http://', $_SESSION['login_url']) === false && strpos('https://', $_SESSION['login_url']) === false))
  112. {
  113. unset ($_SESSION['login_url']);
  114. redirectexit();
  115. }
  116. else
  117. {
  118. // Best not to clutter the session data too much...
  119. $temp = $_SESSION['login_url'];
  120. unset($_SESSION['login_url']);
  121. redirectexit($temp);
  122. }
  123. }
  124. // Beyond this point you are assumed to be a guest trying to login.
  125. if (!$user_info['is_guest'])
  126. redirectexit();
  127. // Are you guessing with a script?
  128. checkSession();
  129. $tk = validateToken('login');
  130. spamProtection('login');
  131. // Set the login_url if it's not already set (but careful not to send us to an attachment).
  132. if ((empty($_SESSION['login_url']) && isset($_SESSION['old_url']) && strpos($_SESSION['old_url'], 'dlattach') === false && preg_match('~(board|topic)[=,]~', $_SESSION['old_url']) != 0) || (isset($_GET['quicklogin']) && isset($_SESSION['old_url']) && strpos($_SESSION['old_url'], 'login') === false))
  133. $_SESSION['login_url'] = $_SESSION['old_url'];
  134. // Been guessing a lot, haven't we?
  135. if (isset($_SESSION['failed_login']) && $_SESSION['failed_login'] >= $modSettings['failed_login_threshold'] * 3)
  136. fatal_lang_error('login_threshold_fail', 'critical');
  137. // Set up the cookie length. (if it's invalid, just fall through and use the default.)
  138. if (isset($_POST['cookieneverexp']) || (!empty($_POST['cookielength']) && $_POST['cookielength'] == -1))
  139. $modSettings['cookieTime'] = 3153600;
  140. elseif (!empty($_POST['cookielength']) && ($_POST['cookielength'] >= 1 || $_POST['cookielength'] <= 525600))
  141. $modSettings['cookieTime'] = (int) $_POST['cookielength'];
  142. loadLanguage('Login');
  143. // Load the template stuff - wireless or normal.
  144. if (WIRELESS)
  145. $context['sub_template'] = WIRELESS_PROTOCOL . '_login';
  146. else
  147. $context['sub_template'] = 'login';
  148. // Set up the default/fallback stuff.
  149. $context['default_username'] = isset($_POST['user']) ? preg_replace('~&amp;#(\\d{1,7}|x[0-9a-fA-F]{1,6});~', '&#\\1;', $smcFunc['htmlspecialchars']($_POST['user'])) : '';
  150. $context['default_password'] = '';
  151. $context['never_expire'] = $modSettings['cookieTime'] == 525600 || $modSettings['cookieTime'] == 3153600;
  152. $context['login_errors'] = array($txt['error_occured']);
  153. $context['page_title'] = $txt['login'];
  154. // Add the login chain to the link tree.
  155. $context['linktree'][] = array(
  156. 'url' => $scripturl . '?action=login',
  157. 'name' => $txt['login'],
  158. );
  159. if (!empty($_POST['openid_identifier']) && !empty($modSettings['enableOpenID']))
  160. {
  161. require_once($sourcedir . '/Subs-OpenID.php');
  162. if (($open_id = smf_openID_validate($_POST['openid_identifier'])) !== 'no_data')
  163. return $open_id;
  164. }
  165. // You forgot to type your username, dummy!
  166. if (!isset($_POST['user']) || $_POST['user'] == '')
  167. {
  168. $context['login_errors'] = array($txt['need_username']);
  169. return;
  170. }
  171. // Hmm... maybe 'admin' will login with no password. Uhh... NO!
  172. if ((!isset($_POST['passwrd']) || $_POST['passwrd'] == '') && (!isset($_POST['hash_passwrd']) || strlen($_POST['hash_passwrd']) != 40))
  173. {
  174. $context['login_errors'] = array($txt['no_password']);
  175. return;
  176. }
  177. // No funky symbols either.
  178. if (preg_match('~[<>&"\'=\\\]~', preg_replace('~(&#(\\d{1,7}|x[0-9a-fA-F]{1,6});)~', '', $_POST['user'])) != 0)
  179. {
  180. $context['login_errors'] = array($txt['error_invalid_characters_username']);
  181. return;
  182. }
  183. // And if it's too long, trim it back.
  184. if ($smcFunc['strlen']($_POST['user']) > 80)
  185. {
  186. $_POST['user'] = $smcFunc['substr']($_POST['user'], 0, 79);
  187. $context['default_username'] = preg_replace('~&amp;#(\\d{1,7}|x[0-9a-fA-F]{1,6});~', '&#\\1;', $smcFunc['htmlspecialchars']($_POST['user']));
  188. }
  189. // Are we using any sort of integration to validate the login?
  190. if (in_array('retry', call_integration_hook('integrate_validate_login', array($_POST['user'], isset($_POST['hash_passwrd']) && strlen($_POST['hash_passwrd']) == 40 ? $_POST['hash_passwrd'] : null, $modSettings['cookieTime'])), true))
  191. {
  192. $context['login_errors'] = array($txt['login_hash_error']);
  193. $context['disable_login_hashing'] = true;
  194. return;
  195. }
  196. // Load the data up!
  197. $request = $smcFunc['db_query']('', '
  198. SELECT passwd, id_member, id_group, lngfile, is_activated, email_address, additional_groups, member_name, password_salt,
  199. openid_uri, passwd_flood
  200. FROM {db_prefix}members
  201. WHERE ' . ($smcFunc['db_case_sensitive'] ? 'LOWER(member_name) = LOWER({string:user_name})' : 'member_name = {string:user_name}') . '
  202. LIMIT 1',
  203. array(
  204. 'user_name' => $smcFunc['db_case_sensitive'] ? strtolower($_POST['user']) : $_POST['user'],
  205. )
  206. );
  207. // Probably mistyped or their email, try it as an email address. (member_name first, though!)
  208. if ($smcFunc['db_num_rows']($request) == 0 && strpos($_POST['user'], '@') !== false)
  209. {
  210. $smcFunc['db_free_result']($request);
  211. $request = $smcFunc['db_query']('', '
  212. SELECT passwd, id_member, id_group, lngfile, is_activated, email_address, additional_groups, member_name, password_salt, openid_uri,
  213. passwd_flood
  214. FROM {db_prefix}members
  215. WHERE email_address = {string:user_name}
  216. LIMIT 1',
  217. array(
  218. 'user_name' => $_POST['user'],
  219. )
  220. );
  221. }
  222. // Let them try again, it didn't match anything...
  223. if ($smcFunc['db_num_rows']($request) == 0)
  224. {
  225. $context['login_errors'] = array($txt['username_no_exist']);
  226. return;
  227. }
  228. $user_settings = $smcFunc['db_fetch_assoc']($request);
  229. $smcFunc['db_free_result']($request);
  230. // Figure out the password using SMF's encryption - if what they typed is right.
  231. if (isset($_POST['hash_passwrd']) && strlen($_POST['hash_passwrd']) == 40)
  232. {
  233. // Needs upgrading?
  234. if (strlen($user_settings['passwd']) != 40)
  235. {
  236. $context['login_errors'] = array($txt['login_hash_error']);
  237. $context['disable_login_hashing'] = true;
  238. unset($user_settings);
  239. return;
  240. }
  241. // Challenge passed.
  242. elseif ($_POST['hash_passwrd'] == sha1($user_settings['passwd'] . $sc . $tk))
  243. $sha_passwd = $user_settings['passwd'];
  244. else
  245. {
  246. // Don't allow this!
  247. validatePasswordFlood($user_settings['id_member'], $user_settings['passwd_flood']);
  248. $_SESSION['failed_login'] = isset($_SESSION['failed_login']) ? ($_SESSION['failed_login'] + 1) : 1;
  249. if ($_SESSION['failed_login'] >= $modSettings['failed_login_threshold'])
  250. redirectexit('action=reminder');
  251. else
  252. {
  253. log_error($txt['incorrect_password'] . ' - <span class="remove">' . $user_settings['member_name'] . '</span>', 'user');
  254. $context['disable_login_hashing'] = true;
  255. $context['login_errors'] = array($txt['incorrect_password']);
  256. unset($user_settings);
  257. return;
  258. }
  259. }
  260. }
  261. else
  262. $sha_passwd = sha1(strtolower($user_settings['member_name']) . un_htmlspecialchars($_POST['passwrd']));
  263. // Bad password! Thought you could fool the database?!
  264. if ($user_settings['passwd'] != $sha_passwd)
  265. {
  266. // Let's be cautious, no hacking please. thanx.
  267. validatePasswordFlood($user_settings['id_member'], $user_settings['passwd_flood']);
  268. // Maybe we were too hasty... let's try some other authentication methods.
  269. $other_passwords = array();
  270. // None of the below cases will be used most of the time (because the salt is normally set.)
  271. if (!empty($modSettings['enable_password_conversion']) && $user_settings['password_salt'] == '')
  272. {
  273. // YaBB SE, Discus, MD5 (used a lot), SHA-1 (used some), SMF 1.0.x, IkonBoard, and none at all.
  274. $other_passwords[] = crypt($_POST['passwrd'], substr($_POST['passwrd'], 0, 2));
  275. $other_passwords[] = crypt($_POST['passwrd'], substr($user_settings['passwd'], 0, 2));
  276. $other_passwords[] = md5($_POST['passwrd']);
  277. $other_passwords[] = sha1($_POST['passwrd']);
  278. $other_passwords[] = md5_hmac($_POST['passwrd'], strtolower($user_settings['member_name']));
  279. $other_passwords[] = md5($_POST['passwrd'] . strtolower($user_settings['member_name']));
  280. $other_passwords[] = md5(md5($_POST['passwrd']));
  281. $other_passwords[] = $_POST['passwrd'];
  282. // This one is a strange one... MyPHP, crypt() on the MD5 hash.
  283. $other_passwords[] = crypt(md5($_POST['passwrd']), md5($_POST['passwrd']));
  284. // Snitz style - SHA-256. Technically, this is a downgrade, but most PHP configurations don't support sha256 anyway.
  285. if (strlen($user_settings['passwd']) == 64 && function_exists('mhash') && defined('MHASH_SHA256'))
  286. $other_passwords[] = bin2hex(mhash(MHASH_SHA256, $_POST['passwrd']));
  287. // phpBB3 users new hashing. We now support it as well ;).
  288. $other_passwords[] = phpBB3_password_check($_POST['passwrd'], $user_settings['passwd']);
  289. // APBoard 2 Login Method.
  290. $other_passwords[] = md5(crypt($_POST['passwrd'], 'CRYPT_MD5'));
  291. }
  292. // The hash should be 40 if it's SHA-1, so we're safe with more here too.
  293. elseif (!empty($modSettings['enable_password_conversion']) && strlen($user_settings['passwd']) == 32)
  294. {
  295. // vBulletin 3 style hashing? Let's welcome them with open arms \o/.
  296. $other_passwords[] = md5(md5($_POST['passwrd']) . stripslashes($user_settings['password_salt']));
  297. // Hmm.. p'raps it's Invision 2 style?
  298. $other_passwords[] = md5(md5($user_settings['password_salt']) . md5($_POST['passwrd']));
  299. // Some common md5 ones.
  300. $other_passwords[] = md5($user_settings['password_salt'] . $_POST['passwrd']);
  301. $other_passwords[] = md5($_POST['passwrd'] . $user_settings['password_salt']);
  302. }
  303. elseif (strlen($user_settings['passwd']) == 40)
  304. {
  305. // Maybe they are using a hash from before the password fix.
  306. $other_passwords[] = sha1(strtolower($user_settings['member_name']) . un_htmlspecialchars($_POST['passwrd']));
  307. // BurningBoard3 style of hashing.
  308. if (!empty($modSettings['enable_password_conversion']))
  309. $other_passwords[] = sha1($user_settings['password_salt'] . sha1($user_settings['password_salt'] . sha1($_POST['passwrd'])));
  310. // Perhaps we converted to UTF-8 and have a valid password being hashed differently.
  311. if ($context['character_set'] == 'utf8' && !empty($modSettings['previousCharacterSet']) && $modSettings['previousCharacterSet'] != 'utf8')
  312. {
  313. // Try iconv first, for no particular reason.
  314. if (function_exists('iconv'))
  315. $other_passwords['iconv'] = sha1(strtolower(iconv('UTF-8', $modSettings['previousCharacterSet'], $user_settings['member_name'])) . un_htmlspecialchars(iconv('UTF-8', $modSettings['previousCharacterSet'], $_POST['passwrd'])));
  316. // Say it aint so, iconv failed!
  317. if (empty($other_passwords['iconv']) && function_exists('mb_convert_encoding'))
  318. $other_passwords[] = sha1(strtolower(mb_convert_encoding($user_settings['member_name'], 'UTF-8', $modSettings['previousCharacterSet'])) . un_htmlspecialchars(mb_convert_encoding($_POST['passwrd'], 'UTF-8', $modSettings['previousCharacterSet'])));
  319. }
  320. }
  321. // SMF's sha1 function can give a funny result on Linux (Not our fault!). If we've now got the real one let the old one be valid!
  322. if (stripos(PHP_OS, 'win') !== 0)
  323. {
  324. require_once($sourcedir . '/Subs-Compat.php');
  325. $other_passwords[] = sha1_smf(strtolower($user_settings['member_name']) . un_htmlspecialchars($_POST['passwrd']));
  326. }
  327. // Allows mods to easily extend the $other_passwords array
  328. call_integration_hook('integrate_other_passwords', array(&$other_passwords));
  329. // Whichever encryption it was using, let's make it use SMF's now ;).
  330. if (in_array($user_settings['passwd'], $other_passwords))
  331. {
  332. $user_settings['passwd'] = $sha_passwd;
  333. $user_settings['password_salt'] = substr(md5(mt_rand()), 0, 4);
  334. // Update the password and set up the hash.
  335. updateMemberData($user_settings['id_member'], array('passwd' => $user_settings['passwd'], 'password_salt' => $user_settings['password_salt'], 'passwd_flood' => ''));
  336. }
  337. // Okay, they for sure didn't enter the password!
  338. else
  339. {
  340. // They've messed up again - keep a count to see if they need a hand.
  341. $_SESSION['failed_login'] = isset($_SESSION['failed_login']) ? ($_SESSION['failed_login'] + 1) : 1;
  342. // Hmm... don't remember it, do you? Here, try the password reminder ;).
  343. if ($_SESSION['failed_login'] >= $modSettings['failed_login_threshold'])
  344. redirectexit('action=reminder');
  345. // We'll give you another chance...
  346. else
  347. {
  348. // Log an error so we know that it didn't go well in the error log.
  349. log_error($txt['incorrect_password'] . ' - <span class="remove">' . $user_settings['member_name'] . '</span>', 'user');
  350. $context['login_errors'] = array($txt['incorrect_password']);
  351. return;
  352. }
  353. }
  354. }
  355. elseif (!empty($user_settings['passwd_flood']))
  356. {
  357. // Let's be sure they weren't a little hacker.
  358. validatePasswordFlood($user_settings['id_member'], $user_settings['passwd_flood'], true);
  359. // If we got here then we can reset the flood counter.
  360. updateMemberData($user_settings['id_member'], array('passwd_flood' => ''));
  361. }
  362. // Correct password, but they've got no salt; fix it!
  363. if ($user_settings['password_salt'] == '')
  364. {
  365. $user_settings['password_salt'] = substr(md5(mt_rand()), 0, 4);
  366. updateMemberData($user_settings['id_member'], array('password_salt' => $user_settings['password_salt']));
  367. }
  368. // Check their activation status.
  369. if (!checkActivation())
  370. return;
  371. DoLogin();
  372. }
  373. /**
  374. * Check activation status of the current user.
  375. */
  376. function checkActivation()
  377. {
  378. global $context, $txt, $scripturl, $user_settings, $modSettings;
  379. if (!isset($context['login_errors']))
  380. $context['login_errors'] = array();
  381. // What is the true activation status of this account?
  382. $activation_status = $user_settings['is_activated'] > 10 ? $user_settings['is_activated'] - 10 : $user_settings['is_activated'];
  383. // Check if the account is activated - COPPA first...
  384. if ($activation_status == 5)
  385. {
  386. $context['login_errors'][] = $txt['coppa_no_concent'] . ' <a href="' . $scripturl . '?action=coppa;member=' . $user_settings['id_member'] . '">' . $txt['coppa_need_more_details'] . '</a>';
  387. return false;
  388. }
  389. // Awaiting approval still?
  390. elseif ($activation_status == 3)
  391. fatal_lang_error('still_awaiting_approval', 'user');
  392. // Awaiting deletion, changed their mind?
  393. elseif ($activation_status == 4)
  394. {
  395. if (isset($_REQUEST['undelete']))
  396. {
  397. updateMemberData($user_settings['id_member'], array('is_activated' => 1));
  398. updateSettings(array('unapprovedMembers' => ($modSettings['unapprovedMembers'] > 0 ? $modSettings['unapprovedMembers'] - 1 : 0)));
  399. }
  400. else
  401. {
  402. $context['disable_login_hashing'] = true;
  403. $context['login_errors'][] = $txt['awaiting_delete_account'];
  404. $context['login_show_undelete'] = true;
  405. return false;
  406. }
  407. }
  408. // Standard activation?
  409. elseif ($activation_status != 1)
  410. {
  411. log_error($txt['activate_not_completed1'] . ' - <span class="remove">' . $user_settings['member_name'] . '</span>', false);
  412. $context['login_errors'][] = $txt['activate_not_completed1'] . ' <a href="' . $scripturl . '?action=activate;sa=resend;u=' . $user_settings['id_member'] . '">' . $txt['activate_not_completed2'] . '</a>';
  413. return false;
  414. }
  415. return true;
  416. }
  417. /**
  418. * Perform the logging in. (set cookie, call hooks, etc)
  419. */
  420. function DoLogin()
  421. {
  422. global $user_info, $user_settings, $smcFunc;
  423. global $maintenance, $modSettings, $context, $sourcedir;
  424. // Load cookie authentication stuff.
  425. require_once($sourcedir . '/Subs-Auth.php');
  426. // Call login integration functions.
  427. call_integration_hook('integrate_login', array($user_settings['member_name'], isset($_POST['hash_passwrd']) && strlen($_POST['hash_passwrd']) == 40 ? $_POST['hash_passwrd'] : null, $modSettings['cookieTime']));
  428. // Get ready to set the cookie...
  429. $username = $user_settings['member_name'];
  430. $user_info['id'] = $user_settings['id_member'];
  431. // Bam! Cookie set. A session too, just in case.
  432. setLoginCookie(60 * $modSettings['cookieTime'], $user_settings['id_member'], sha1($user_settings['passwd'] . $user_settings['password_salt']));
  433. // Reset the login threshold.
  434. if (isset($_SESSION['failed_login']))
  435. unset($_SESSION['failed_login']);
  436. $user_info['is_guest'] = false;
  437. $user_settings['additional_groups'] = explode(',', $user_settings['additional_groups']);
  438. $user_info['is_admin'] = $user_settings['id_group'] == 1 || in_array(1, $user_settings['additional_groups']);
  439. // Are you banned?
  440. is_not_banned(true);
  441. // An administrator, set up the login so they don't have to type it again.
  442. if ($user_info['is_admin'] && isset($user_settings['openid_uri']) && empty($user_settings['openid_uri']))
  443. {
  444. $_SESSION['admin_time'] = time();
  445. unset($_SESSION['just_registered']);
  446. }
  447. // Don't stick the language or theme after this point.
  448. unset($_SESSION['language'], $_SESSION['id_theme']);
  449. // First login?
  450. $request = $smcFunc['db_query']('', '
  451. SELECT last_login
  452. FROM {db_prefix}members
  453. WHERE id_member = {int:id_member}
  454. AND last_login = 0',
  455. array(
  456. 'id_member' => $user_info['id'],
  457. )
  458. );
  459. if ($smcFunc['db_num_rows']($request) == 1)
  460. $_SESSION['first_login'] = true;
  461. else
  462. unset($_SESSION['first_login']);
  463. $smcFunc['db_free_result']($request);
  464. // You've logged in, haven't you?
  465. updateMemberData($user_info['id'], array('last_login' => time(), 'member_ip' => $user_info['ip'], 'member_ip2' => $_SERVER['BAN_CHECK_IP']));
  466. // Get rid of the online entry for that old guest....
  467. $smcFunc['db_query']('', '
  468. DELETE FROM {db_prefix}log_online
  469. WHERE session = {string:session}',
  470. array(
  471. 'session' => 'ip' . $user_info['ip'],
  472. )
  473. );
  474. $_SESSION['log_time'] = 0;
  475. // Log this entry, only if we have it enabled.
  476. if (!empty($modSettings['loginHistoryDays']))
  477. $smcFunc['db_insert']('insert',
  478. '{db_prefix}member_logins',
  479. array(
  480. 'id_member' => 'int', 'time' => 'int', 'ip' => 'string', 'ip2' => 'string',
  481. ),
  482. array(
  483. $user_info['id'], time(), $user_info['ip'], $user_info['ip2']
  484. ),
  485. array(
  486. 'id_member', 'time'
  487. )
  488. );
  489. // Just log you back out if it's in maintenance mode and you AREN'T an admin.
  490. if (empty($maintenance) || allowedTo('admin_forum'))
  491. redirectexit('action=login2;sa=check;member=' . $user_info['id'], $context['server']['needs_login_fix']);
  492. else
  493. redirectexit('action=logout;' . $context['session_var'] . '=' . $context['session_id'], $context['server']['needs_login_fix']);
  494. }
  495. /**
  496. * Logs the current user out of their account.
  497. * It requires that the session hash is sent as well, to prevent automatic logouts by images or javascript.
  498. * It redirects back to $_SESSION['logout_url'], if it exists.
  499. * It is accessed via ?action=logout;session_var=...
  500. *
  501. * @param bool $internal if true, it doesn't check the session
  502. * @param $redirect
  503. */
  504. function Logout($internal = false, $redirect = true)
  505. {
  506. global $sourcedir, $user_info, $user_settings, $context, $smcFunc;
  507. // Make sure they aren't being auto-logged out.
  508. if (!$internal)
  509. checkSession('get');
  510. require_once($sourcedir . '/Subs-Auth.php');
  511. if (isset($_SESSION['pack_ftp']))
  512. $_SESSION['pack_ftp'] = null;
  513. // They cannot be open ID verified any longer.
  514. if (isset($_SESSION['openid']))
  515. unset($_SESSION['openid']);
  516. // It won't be first login anymore.
  517. unset($_SESSION['first_login']);
  518. // Just ensure they aren't a guest!
  519. if (!$user_info['is_guest'])
  520. {
  521. // Pass the logout information to integrations.
  522. call_integration_hook('integrate_logout', array($user_settings['member_name']));
  523. // If you log out, you aren't online anymore :P.
  524. $smcFunc['db_query']('', '
  525. DELETE FROM {db_prefix}log_online
  526. WHERE id_member = {int:current_member}',
  527. array(
  528. 'current_member' => $user_info['id'],
  529. )
  530. );
  531. }
  532. $_SESSION['log_time'] = 0;
  533. // Empty the cookie! (set it in the past, and for id_member = 0)
  534. setLoginCookie(-3600, 0);
  535. // And some other housekeeping while we're at it.
  536. session_destroy();
  537. if (!empty($user_info['id']))
  538. updateMemberData($user_info['id'], array('password_salt' => substr(md5(mt_rand()), 0, 4)));
  539. // Off to the merry board index we go!
  540. if ($redirect)
  541. {
  542. if (empty($_SESSION['logout_url']))
  543. redirectexit('', $context['server']['needs_login_fix']);
  544. elseif (!empty($_SESSION['logout_url']) && (strpos('http://', $_SESSION['logout_url']) === false && strpos('https://', $_SESSION['logout_url']) === false))
  545. {
  546. unset ($_SESSION['logout_url']);
  547. redirectexit();
  548. }
  549. else
  550. {
  551. $temp = $_SESSION['logout_url'];
  552. unset($_SESSION['logout_url']);
  553. redirectexit($temp, $context['server']['needs_login_fix']);
  554. }
  555. }
  556. }
  557. /**
  558. * MD5 Encryption used for older passwords. (SMF 1.0.x/YaBB SE 1.5.x hashing)
  559. *
  560. * @param string $data
  561. * @param string $key
  562. * @return string, the HMAC MD5 of data with key
  563. */
  564. function md5_hmac($data, $key)
  565. {
  566. $key = str_pad(strlen($key) <= 64 ? $key : pack('H*', md5($key)), 64, chr(0x00));
  567. return md5(($key ^ str_repeat(chr(0x5c), 64)) . pack('H*', md5(($key ^ str_repeat(chr(0x36), 64)) . $data)));
  568. }
  569. /**
  570. * Custom encryption for phpBB3 based passwords.
  571. *
  572. * @param string $passwd
  573. * @param string $passwd_hash
  574. * @return string
  575. */
  576. function phpBB3_password_check($passwd, $passwd_hash)
  577. {
  578. // Too long or too short?
  579. if (strlen($passwd_hash) != 34)
  580. return;
  581. // Range of characters allowed.
  582. $range = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz';
  583. // Tests
  584. $strpos = strpos($range, $passwd_hash[3]);
  585. $count = 1 << $strpos;
  586. $count2 = $count;
  587. $salt = substr($passwd_hash, 4, 8);
  588. $hash = md5($salt . $passwd, true);
  589. for (; $count != 0; --$count)
  590. $hash = md5($hash . $passwd, true);
  591. $output = substr($passwd_hash, 0, 12);
  592. $i = 0;
  593. while ($i < 16)
  594. {
  595. $value = ord($hash[$i++]);
  596. $output .= $range[$value & 0x3f];
  597. if ($i < 16)
  598. $value |= ord($hash[$i]) << 8;
  599. $output .= $range[($value >> 6) & 0x3f];
  600. if ($i++ >= 16)
  601. break;
  602. if ($i < 16)
  603. $value |= ord($hash[$i]) << 16;
  604. $output .= $range[($value >> 12) & 0x3f];
  605. if ($i++ >= 16)
  606. break;
  607. $output .= $range[($value >> 18) & 0x3f];
  608. }
  609. // Return now.
  610. return $output;
  611. }
  612. /**
  613. * This protects against brute force attacks on a member's password.
  614. * Importantly, even if the password was right we DON'T TELL THEM!
  615. *
  616. * @param $id_member
  617. * @param $password_flood_value = false
  618. * @param $was_correct = false
  619. */
  620. function validatePasswordFlood($id_member, $password_flood_value = false, $was_correct = false)
  621. {
  622. global $cookiename, $sourcedir;
  623. // As this is only brute protection, we allow 5 attempts every 10 seconds.
  624. // Destroy any session or cookie data about this member, as they validated wrong.
  625. require_once($sourcedir . '/Subs-Auth.php');
  626. setLoginCookie(-3600, 0);
  627. if (isset($_SESSION['login_' . $cookiename]))
  628. unset($_SESSION['login_' . $cookiename]);
  629. // We need a member!
  630. if (!$id_member)
  631. {
  632. // Redirect back!
  633. redirectexit();
  634. // Probably not needed, but still make sure...
  635. fatal_lang_error('no_access', false);
  636. }
  637. // Right, have we got a flood value?
  638. if ($password_flood_value !== false)
  639. @list ($time_stamp, $number_tries) = explode('|', $password_flood_value);
  640. // Timestamp or number of tries invalid?
  641. if (empty($number_tries) || empty($time_stamp))
  642. {
  643. $number_tries = 0;
  644. $time_stamp = time();
  645. }
  646. // They've failed logging in already
  647. if (!empty($number_tries))
  648. {
  649. // Give them less chances if they failed before
  650. $number_tries = $time_stamp < time() - 20 ? 2 : $number_tries;
  651. // They are trying too fast, make them wait longer
  652. if ($time_stamp < time() - 10)
  653. $time_stamp = time();
  654. }
  655. $number_tries++;
  656. // Broken the law?
  657. if ($number_tries > 5)
  658. fatal_lang_error('login_threshold_brute_fail', 'critical');
  659. // Otherwise set the members data. If they correct on their first attempt then we actually clear it, otherwise we set it!
  660. updateMemberData($id_member, array('passwd_flood' => $was_correct && $number_tries == 1 ? '' : $time_stamp . '|' . $number_tries));
  661. }
  662. ?>