C:\$Recycle.Bin\S-1-5-21-3967099092-2644009230-141905953-500\$RU7MSUA\html\include\checklogin.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
<?php
// $Id: checklogin.php,v 1.16.8.11.2.1 2005/09/18 13:05:03 mithyt2 Exp $
//  ------------------------------------------------------------------------ //
//                XOOPS - PHP Content Management System                      //
//                    Copyright (c) 2000 XOOPS.org                           //
//                       <http://www.xoops.org/>                             //
//  ------------------------------------------------------------------------ //
//  This program is free software; you can redistribute it and/or modify     //
//  it under the terms of the GNU General Public License as published by     //
//  the Free Software Foundation; either version 2 of the License, or        //
//  (at your option) any later version.                                      //
//                                                                           //
//  You may not change or alter any portion of this comment or credits       //
//  of supporting developers from this source code or any supporting         //
//  source code which is considered copyrighted (c) material of the          //
//  original comment or credit authors.                                      //
//                                                                           //
//  This program is distributed in the hope that it will be useful,          //
//  but WITHOUT ANY WARRANTY; without even the implied warranty of           //
//  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the            //
//  GNU General Public License for more details.                             //
//                                                                           //
//  You should have received a copy of the GNU General Public License        //
//  along with this program; if not, write to the Free Software              //
//  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307 USA //
//  ------------------------------------------------------------------------ //
// Author: Kazumi Ono (AKA onokazu)                                          //
// URL: http://www.xoops.org/ http://jp.xoops.org/  http://www.myweb.ne.jp/  //
// Project: The XOOPS Project (http://www.xoops.org/)                        //
// ------------------------------------------------------------------------- //

if (!defined('XOOPS_ROOT_PATH')) {
    exit();
}
include_once 
XOOPS_ROOT_PATH.'/language/'.$xoopsConfig['language'].'/user.php';
$uname = !isset($_POST['uname']) ? '' trim($_POST['uname']);
$pass = !isset($_POST['pass']) ? '' trim($_POST['pass']);
if (
$uname == '' || $pass == '') {
    
redirect_header(XOOPS_URL.'/user.php'1_US_INCORRECTLOGIN);
    exit();
}
$member_handler =& xoops_gethandler('member');
$myts =& MyTextsanitizer::getInstance();

// Place here the Auth class calls
//**** BEGIN AUTH ****
require_once XOOPS_ROOT_PATH.'/class/auth/authfactory.php';
$xoopsAuth =& XoopsAuthFactory::getAuthConnection();
$auth $xoopsAuth->authenticate($myts->addSlashes($uname), $myts->addSlashes($pass));
if (!
$auth) {
    
redirect_header(XOOPS_URL '/user.php'5_US_INCORRECTLOGIN$xoopsAuth->getHtmlErrors());
    exit();
}
//**** END AUTH ****

$user =& $member_handler->loginUser($myts->addSlashes($uname), $myts->addslashes($pass));
if (
false != $user) {
    if (
>= $user->getVar('level')) {
        
redirect_header(XOOPS_URL.'/index.php'5_US_NOACTTPADM);
        exit();
    }
    if (
$xoopsConfig['closesite'] == 1) {
        
$allowed false;
        foreach (
$user->getGroups() as $group) {
            if (
in_array($group$xoopsConfig['closesite_okgrp']) || XOOPS_GROUP_ADMIN == $group) {
                
$allowed true;
                break;
            }
        }
        if (!
$allowed) {
            
redirect_header(XOOPS_URL.'/index.php'1_NOPERM);
            exit();
        }
    }
    
$_SESSION = array();
    
$_SESSION['xoopsUserId'] = $user->getVar('uid');
    
$_SESSION['xoopsUserGroups'] = $user->getGroups();
    if (
$xoopsConfig['use_mysession'] && $xoopsConfig['session_name'] != '') {
        
setcookie($xoopsConfig['session_name'], session_id(), time()+(60 $xoopsConfig['session_expire']), '/',  ''0);
    }
    
$_SESSION['xoopsUserLastLogin'] = $user->getVar('last_login');
    if (!
$member_handler->updateUserByField($user'last_login'time())) {
    }
    
$user_theme $user->getVar('theme');
    if (
in_array($user_theme$xoopsConfig['theme_set_allowed'])) {
        
$_SESSION['xoopsUserTheme'] = $user_theme;
    }
    if (!empty(
$_POST['xoops_redirect']) && !strpos($_POST['xoops_redirect'], 'register')) {
//        if (!preg_match("/^http[s]*:\/\//i", $_POST['xoops_redirect'])) {
//            $url = XOOPS_URL.trim($_POST['xoops_redirect']);
//        }
//        else {
            
$url $_POST['xoops_redirect'];
//        }        
        /*$parsed = parse_url(XOOPS_URL);
        $url = isset($parsed['scheme']) ? $parsed['scheme'].'://' : 'http://';
        if (isset($parsed['host'])) {
            $url .= isset($parsed['port']) ?$parsed['host'].':'.$parsed['port'].trim($_POST['xoops_redirect']): $parsed['host'].trim($_POST['xoops_redirect']);
        } else {
            $url .= xoops_getenv('HTTP_HOST').trim($_POST['xoops_redirect']);
        }*/
    
} else {
        
$url XOOPS_URL.'/index.php';
    }

    
// RMV-NOTIFY
    // Perform some maintenance of notification records
    
$notification_handler =& xoops_gethandler('notification');
    
$notification_handler->doLoginMaintenance($user->getVar('uid'));

    
redirect_header($url1sprintf(_US_LOGGINGU$user->getVar('uname')));
} else {

    
redirect_header(XOOPS_URL.'/user.php',1,_US_INCORRECTLOGIN);
}
exit();
?>