1
0
mirror of https://github.com/vichan-devel/vichan.git synced 2025-01-22 11:23:45 +01:00
vichan/mod.php

209 lines
8.1 KiB
PHP
Raw Permalink Normal View History

2021-03-12 21:53:16 +01:00
<?php
2012-04-12 02:49:22 +10:00
/*
2014-04-12 11:12:42 -07:00
* Copyright (c) 2010-2014 Tinyboard Development Group
2012-04-12 02:49:22 +10:00
*/
2021-02-13 19:24:03 +01:00
require_once 'inc/bootstrap.php';
2012-04-12 02:49:22 +10:00
2024-08-15 16:52:29 +02:00
if ($config['debug']) {
$parse_start_time = microtime(true);
2024-08-15 16:52:29 +02:00
}
require_once 'inc/mod/pages.php';
$ctx = Vichan\build_context($config);
check_login($ctx, true);
$query = isset($_SERVER['QUERY_STRING']) ? rawurldecode($_SERVER['QUERY_STRING']) : '';
2012-04-12 02:49:22 +10:00
2024-08-15 16:52:29 +02:00
$pages = [
2013-09-23 16:48:56 +10:00
'' => ':?/', // redirect to dashboard
'/' => 'dashboard', // dashboard
'/confirm/(.+)' => 'confirm', // confirm action (if javascript didn't work)
'/logout' => 'secure logout', // logout
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/users' => 'users', // manage users
'/users/(\d+)/(promote|demote)' => 'secure user_promote', // prmote/demote user
'/users/(\d+)' => 'secure_POST user', // edit user
'/users/new' => 'secure_POST user_new', // create a new user
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/new_PM/([^/]+)' => 'secure_POST new_pm', // create a new pm
'/PM/(\d+)(/reply)?' => 'pm', // read a pm
'/inbox' => 'inbox', // pm inbox
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/log' => 'log', // modlog
'/log/(\d+)' => 'log', // modlog
2015-03-29 09:18:14 +08:00
'/log:([^/:]+)' => 'user_log', // modlog
'/log:([^/:]+)/(\d+)' => 'user_log', // modlog
'/log:b:([^/]+)' => 'board_log', // modlog
'/log:b:([^/]+)/(\d+)' => 'board_log', // modlog
'/edit_news' => 'secure_POST news', // view news
'/edit_news/(\d+)' => 'secure_POST news', // view news
'/edit_news/delete/(\d+)' => 'secure news_delete', // delete from news
'/edit_pages(?:/?(\%b)?)' => 'secure_POST pages',
'/edit_page/(\d+)' => 'secure_POST edit_page',
'/edit_pages/delete/([a-z0-9]+)' => 'secure delete_page',
'/edit_pages/delete/([a-z0-9]+)/(\%b)' => 'secure delete_page_board',
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/noticeboard' => 'secure_POST noticeboard', // view noticeboard
'/noticeboard/(\d+)' => 'secure_POST noticeboard', // view noticeboard
'/noticeboard/delete/(\d+)' => 'secure noticeboard_delete', // delete from noticeboard
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/edit/(\%b)' => 'secure_POST edit_board', // edit board details
'/new-board' => 'secure_POST new_board', // create a new board
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/rebuild' => 'secure_POST rebuild', // rebuild static files
'/reports' => 'reports', // report queue
'/reports/(\d+)/dismiss(&all|&post)?' => 'secure report_dismiss', // dismiss a report
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/IP/([\w.:]+)' => 'secure_POST ip', // view ip address
'/IP/([\w.:]+)/remove_note/(\d+)' => 'secure ip_remove_note', // remove note from ip address
2021-03-12 21:51:42 +01:00
'/ban' => 'secure_POST ban', // new ban
2013-09-23 16:48:56 +10:00
'/bans' => 'secure_POST bans', // ban list
'/bans.json' => 'secure bans_json', // ban list JSON
'/edit_ban/(\d+)' => 'secure_POST edit_ban',
2013-09-23 16:48:56 +10:00
'/ban-appeals' => 'secure_POST ban_appeals', // view ban appeals
2024-03-07 14:37:01 +01:00
'/recent/(\d+)' => 'recent_posts', // view recent posts
2013-09-23 16:48:56 +10:00
'/search' => 'search_redirect', // search
'/search/(posts|IP_notes|bans|log)/(.+)/(\d+)' => 'search', // search
'/search/(posts|IP_notes|bans|log)/(.+)' => 'search', // search
'/(\%b)/ban(&delete)?/(\d+)' => 'secure_POST ban_post', // ban poster
'/(\%b)/move/(\d+)' => 'secure_POST move', // move thread
'/(\%b)/move_reply/(\d+)' => 'secure_POST move_reply', // move reply
'/(\%b)/edit(_raw)?/(\d+)' => 'secure_POST edit_post', // edit post
'/(\%b)/delete/(\d+)' => 'secure delete', // delete post
'/(\%b)/deletefile/(\d+)/(\d+)' => 'secure deletefile', // delete file from post
'/(\%b+)/spoiler/(\d+)/(\d+)' => 'secure spoiler_image', // spoiler file
'/(\%b)/deletebyip/(\d+)(/global)?' => 'secure deletebyip', // delete all posts by IP address
'/(\%b)/(un)?lock/(\d+)' => 'secure lock', // lock thread
'/(\%b)/(un)?sticky/(\d+)' => 'secure sticky', // sticky thread
2015-04-03 14:56:28 +08:00
'/(\%b)/(un)?cycle/(\d+)' => 'secure cycle', // cycle thread
'/(\%b)/bump(un)?lock/(\d+)' => 'secure bumplock', // "bumplock" thread
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/themes' => 'themes_list', // manage themes
'/themes/(\w+)' => 'secure_POST theme_configure', // configure/reconfigure theme
'/themes/(\w+)/rebuild' => 'secure theme_rebuild', // rebuild theme
'/themes/(\w+)/uninstall' => 'secure theme_uninstall', // uninstall theme
2024-03-07 14:37:01 +01:00
2013-09-23 16:48:56 +10:00
'/config' => 'secure_POST config', // config editor
'/config/(\%b)' => 'secure_POST config', // config editor
2024-03-07 14:37:01 +01:00
2012-04-16 20:11:10 +10:00
// these pages aren't listed in the dashboard without $config['debug']
//'/debug/antispam' => 'debug_antispam',
//'/debug/recent' => 'debug_recent_posts',
//'/debug/sql' => 'secure_POST debug_sql',
2024-03-07 14:37:01 +01:00
2012-04-13 02:11:41 +10:00
// This should always be at the end:
2013-07-31 02:08:55 -04:00
'/(\%b)/' => 'view_board',
'/(\%b)/' . preg_quote($config['file_index'], '!') => 'view_board',
2022-06-20 15:09:55 -03:00
'/(\%b)/' . preg_quote($config['file_catalog'], '!') => 'view_catalog',
2013-07-31 02:08:55 -04:00
'/(\%b)/' . str_replace('%d', '(\d+)', preg_quote($config['file_page'], '!')) => 'view_board',
'/(\%b)/' . preg_quote($config['dir']['res'], '!') .
str_replace('%d', '(\d+)', preg_quote($config['file_page50'], '!')) => 'view_thread50',
2013-07-31 02:08:55 -04:00
'/(\%b)/' . preg_quote($config['dir']['res'], '!') .
2012-05-06 12:44:37 +10:00
str_replace('%d', '(\d+)', preg_quote($config['file_page'], '!')) => 'view_thread',
'/(\%b)/' . preg_quote($config['dir']['res'], '!') .
2024-08-15 16:52:29 +02:00
str_replace([ '%d','%s' ], [ '(\d+)', '[a-z0-9-]+' ], preg_quote($config['file_page50_slug'], '!')) => 'view_thread50',
'/(\%b)/' . preg_quote($config['dir']['res'], '!') .
2024-08-15 16:52:29 +02:00
str_replace([ '%d','%s' ], [ '(\d+)', '[a-z0-9-]+' ], preg_quote($config['file_page_slug'], '!')) => 'view_thread',
];
2012-04-13 02:11:41 +10:00
2012-05-06 01:33:10 +10:00
if (!$mod) {
2024-08-15 16:52:29 +02:00
$pages = [ '!^(.+)?$!' => 'login' ];
2012-05-06 01:33:10 +10:00
} elseif (isset($_GET['status'], $_GET['r'])) {
2012-05-06 12:29:54 +10:00
header('Location: ' . $_GET['r'], true, (int)$_GET['status']);
2012-05-06 12:44:37 +10:00
exit;
}
if (isset($config['mod']['custom_pages'])) {
2012-05-06 01:33:10 +10:00
$pages = array_merge($pages, $config['mod']['custom_pages']);
}
2012-04-13 02:11:41 +10:00
2024-08-15 16:52:29 +02:00
$new_pages = [];
2012-05-06 12:44:37 +10:00
foreach ($pages as $key => $callback) {
2024-08-15 16:52:29 +02:00
if (is_string($callback) && preg_match('/^secure /', $callback)) {
2012-08-27 15:19:05 +10:00
$key .= '(/(?P<token>[a-f0-9]{8}))?';
2024-08-15 16:52:29 +02:00
}
$key = str_replace('\%b', '?P<board>' . sprintf(substr($config['board_path'], 0, -1), $config['board_regex']), $key);
$new_pages[(!empty($key) and $key[0] == '!') ? $key : '!^' . $key . '(?:&[^&=]+=[^&]*)*$!u'] = $callback;
2012-05-06 12:44:37 +10:00
}
$pages = $new_pages;
2012-04-13 02:11:41 +10:00
foreach ($pages as $uri => $handler) {
if (preg_match($uri, $query, $matches)) {
$matches[0] = $ctx; // Replace the text captured by the full pattern with a reference to the context.
2024-03-07 14:37:01 +01:00
if (isset($matches['board'])) {
$board_match = $matches['board'];
unset($matches['board']);
$key = array_search($board_match, $matches);
if (preg_match('/^' . sprintf(substr($config['board_path'], 0, -1), '(' . $config['board_regex'] . ')') . '$/u', $matches[$key], $board_match)) {
$matches[$key] = $board_match[1];
}
}
2024-03-07 14:37:01 +01:00
if (is_string($handler) && preg_match('/^secure(_POST)? /', $handler, $m)) {
2012-08-27 15:19:05 +10:00
$secure_post_only = isset($m[1]);
if (!$secure_post_only || $_SERVER['REQUEST_METHOD'] == 'POST') {
$token = isset($matches['token']) ? $matches['token'] : (isset($_POST['token']) ? $_POST['token'] : false);
2024-03-07 14:37:01 +01:00
2012-08-27 15:19:05 +10:00
if ($token === false) {
if ($secure_post_only)
error($config['error']['csrf']);
else {
2024-10-06 11:25:57 +02:00
mod_confirm($ctx, substr($query, 1));
2012-08-27 15:19:05 +10:00
exit;
}
}
2024-03-07 14:37:01 +01:00
2012-08-27 15:19:05 +10:00
// CSRF-protected page; validate security token
$actual_query = preg_replace('!/([a-f0-9]{8})$!', '', $query);
if ($token != make_secure_link_token(substr($actual_query, 1))) {
error($config['error']['csrf']);
}
}
$handler = preg_replace('/^secure(_POST)? /', '', $handler);
}
2024-03-07 14:37:01 +01:00
2012-04-13 02:11:41 +10:00
if ($config['debug']) {
2024-08-15 16:52:29 +02:00
$debug['mod_page'] = [
2012-04-13 02:11:41 +10:00
'req' => $query,
'match' => $uri,
'handler' => $handler,
2024-08-15 16:52:29 +02:00
];
$debug['time']['parse_mod_req'] = '~' . round((microtime(true) - $parse_start_time) * 1000, 2) . 'ms';
2012-04-12 02:49:22 +10:00
}
// We don't want to call named parameters (PHP 8).
$matches = array_values($matches);
2012-05-06 01:33:10 +10:00
if (is_string($handler)) {
if ($handler[0] == ':') {
header('Location: ' . substr($handler, 1), true, $config['redirect_http']);
} elseif (is_callable("mod_$handler")) {
call_user_func_array("mod_$handler", $matches);
} else {
error("Mod page '$handler' not found!");
}
} elseif (is_callable($handler)) {
call_user_func_array($handler, $matches);
2012-04-12 02:49:22 +10:00
} else {
2012-05-06 01:33:10 +10:00
error("Mod page '$handler' not a string, and not callable!");
2012-04-12 02:49:22 +10:00
}
2024-03-07 14:37:01 +01:00
2012-04-13 02:11:41 +10:00
exit;
2010-12-01 21:53:11 +11:00
}
2012-04-12 02:49:22 +10:00
}
2012-04-13 02:11:41 +10:00
error($config['error']['404']);