Oppaitime's version of Gazelle
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

autoenable.class.php 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361
  1. <?
  2. class AutoEnable {
  3. // Constants for database values
  4. const APPROVED = 1;
  5. const DENIED = 2;
  6. const DISCARDED = 3;
  7. // Cache key to store the number of enable requests
  8. const CACHE_KEY_NAME = 'num_enable_requests';
  9. // The default request rejected message
  10. const REJECTED_MESSAGE = "Your request to re-enable your account has been rejected.<br />This may be because a request is already pending for your username, or because a recent request was denied.<br /><br />You are encouraged to discuss this with staff by visiting %s on %s";
  11. // The default request received message
  12. const RECEIVED_MESSAGE = "Your request to re-enable your account has been received. You can expect a reply message in your email within 48 hours.<br />If you do not receive an email after 48 hours have passed, please visit us on IRC for assistance.";
  13. /**
  14. * Handle a new enable request
  15. *
  16. * @param string $Username The user's username
  17. * @param string $Email The user's email address
  18. * @return string The output
  19. */
  20. public static function new_request($Username, $Email) {
  21. if (empty($Username)) {
  22. header("Location: login.php");
  23. die();
  24. }
  25. // Get the user's ID
  26. G::$DB->query("
  27. SELECT um.ID
  28. FROM users_main AS um
  29. JOIN users_info ui ON ui.UserID = um.ID
  30. WHERE um.Username = '$Username'
  31. AND um.Enabled = '2'");
  32. if (G::$DB->has_results()) {
  33. // Make sure the user can make another request
  34. list($UserID) = G::$DB->next_record();
  35. G::$DB->query("
  36. SELECT 1 FROM users_enable_requests
  37. WHERE UserID = '$UserID'
  38. AND (
  39. (
  40. Timestamp > NOW() - INTERVAL 1 WEEK
  41. AND HandledTimestamp IS NULL
  42. )
  43. OR
  44. (
  45. Timestamp > NOW() - INTERVAL 2 MONTH
  46. AND
  47. (Outcome = '".self::DENIED."'
  48. OR Outcome = '".self::DISCARDED."')
  49. )
  50. )");
  51. }
  52. $IP = $_SERVER['REMOTE_ADDR'];
  53. if (G::$DB->has_results() || !isset($UserID)) {
  54. // User already has/had a pending activation request or username is invalid
  55. $Output = sprintf(self::REJECTED_MESSAGE, BOT_DISABLED_CHAN, BOT_SERVER);
  56. if (isset($UserID)) {
  57. Tools::update_user_notes($UserID, sqltime() . " - Enable request rejected from $IP\n\n");
  58. }
  59. } else {
  60. // New disable activation request
  61. $UserAgent = db_string($_SERVER['HTTP_USER_AGENT']);
  62. G::$DB->query("
  63. INSERT INTO users_enable_requests
  64. (UserID, Email, IP, UserAgent, Timestamp)
  65. VALUES ('$UserID', '".DBCrypt::encrypt($Email)."', '".DBCrypt::encrypt($IP)."', '$UserAgent', '".sqltime()."')");
  66. // Cache the number of requests for the modbar
  67. G::$Cache->increment_value(self::CACHE_KEY_NAME);
  68. setcookie('username', '', time() - 60 * 60, '/', '', false);
  69. $Output = self::RECEIVED_MESSAGE;
  70. Tools::update_user_notes($UserID, sqltime() . " - Enable request " . G::$DB->inserted_id() . " received from $IP\n\n");
  71. }
  72. return $Output;
  73. }
  74. /*
  75. * Handle requests
  76. *
  77. * @param int|int[] $IDs An array of IDs, or a single ID
  78. * @param int $Status The status to mark the requests as
  79. * @param string $Comment The staff member comment
  80. */
  81. public static function handle_requests($IDs, $Status, $Comment) {
  82. if ($Status != self::APPROVED && $Status != self::DENIED && $Status != self::DISCARDED) {
  83. error(404);
  84. }
  85. $UserInfo = array();
  86. $IDs = (!is_array($IDs)) ? [$IDs] : $IDs;
  87. if (count($IDs) == 0) {
  88. error(404);
  89. }
  90. foreach ($IDs as $ID) {
  91. if (!is_number($ID)) {
  92. error(404);
  93. }
  94. }
  95. G::$DB->query("SELECT Email, ID, UserID
  96. FROM users_enable_requests
  97. WHERE ID IN (".implode(',', $IDs).")
  98. AND Outcome IS NULL");
  99. $Results = G::$DB->to_array(false, MYSQLI_NUM);
  100. if ($Status != self::DISCARDED) {
  101. // Prepare email
  102. require(SERVER_ROOT . '/classes/templates.class.php');
  103. $TPL = NEW TEMPLATE;
  104. if ($Status == self::APPROVED) {
  105. $TPL->open(SERVER_ROOT . '/templates/enable_request_accepted.tpl');
  106. $TPL->set('SITE_URL', NONSSL_SITE_URL);
  107. } else {
  108. $TPL->open(SERVER_ROOT . '/templates/enable_request_denied.tpl');
  109. }
  110. $TPL->set('SITE_NAME', SITE_NAME);
  111. foreach ($Results as $Result) {
  112. list($Email, $ID, $UserID) = $Result;
  113. $Email = DBCrypt::decrypt($Email);
  114. $UserInfo[] = array($ID, $UserID);
  115. if ($Status == self::APPROVED) {
  116. // Generate token
  117. $Token = db_string(Users::make_secret());
  118. G::$DB->query("
  119. UPDATE users_enable_requests
  120. SET Token = '$Token'
  121. WHERE ID = '$ID'");
  122. $TPL->set('TOKEN', $Token);
  123. }
  124. // Send email
  125. $Subject = "Your enable request for " . SITE_NAME . " has been ";
  126. $Subject .= ($Status == self::APPROVED) ? 'approved' : 'denied';
  127. Misc::send_email($Email, $Subject, $TPL->get(), 'noreply');
  128. }
  129. } else {
  130. foreach ($Results as $Result) {
  131. list(, $ID, $UserID) = $Result;
  132. $UserInfo[] = array($ID, $UserID);
  133. }
  134. }
  135. // User notes stuff
  136. G::$DB->query("
  137. SELECT Username
  138. FROM users_main
  139. WHERE ID = '" . G::$LoggedUser['ID'] . "'");
  140. list($StaffUser) = G::$DB->next_record();
  141. foreach ($UserInfo as $User) {
  142. list($ID, $UserID) = $User;
  143. $BaseComment = sqltime() . " - Enable request $ID " . strtolower(self::get_outcome_string($Status)) . ' by [user]'.$StaffUser.'[/user]';
  144. $BaseComment .= (!empty($Comment)) ? "\nReason: $Comment\n\n" : "\n\n";
  145. Tools::update_user_notes($UserID, $BaseComment);
  146. }
  147. // Update database values and decrement cache
  148. G::$DB->query("
  149. UPDATE users_enable_requests
  150. SET HandledTimestamp = '".sqltime()."',
  151. CheckedBy = '".G::$LoggedUser['ID']."',
  152. Outcome = '$Status'
  153. WHERE ID IN (".implode(',', $IDs).")");
  154. G::$Cache->decrement_value(self::CACHE_KEY_NAME, count($IDs));
  155. }
  156. /**
  157. * Unresolve a discarded request
  158. *
  159. * @param int $ID The request ID
  160. */
  161. public static function unresolve_request($ID) {
  162. $ID = (int) $ID;
  163. if (empty($ID)) {
  164. error(404);
  165. }
  166. G::$DB->query("
  167. SELECT UserID
  168. FROM users_enable_requests
  169. WHERE Outcome = '" . self::DISCARDED . "'
  170. AND ID = '$ID'");
  171. if (!G::$DB->has_results()) {
  172. error(404);
  173. } else {
  174. list($UserID) = G::$DB->next_record();
  175. }
  176. G::$DB->query("
  177. SELECT Username
  178. FROM users_main
  179. WHERE ID = '" . G::$LoggedUser['ID'] . "'");
  180. list($StaffUser) = G::$DB->next_record();
  181. Tools::update_user_notes($UserID, sqltime() . " - Enable request $ID unresolved by [user]" . $StaffUser . '[/user]' . "\n\n");
  182. G::$DB->query("
  183. UPDATE users_enable_requests
  184. SET Outcome = NULL, HandledTimestamp = NULL, CheckedBy = NULL
  185. WHERE ID = '$ID'");
  186. G::$Cache->increment_value(self::CACHE_KEY_NAME);
  187. }
  188. /**
  189. * Get the corresponding outcome string for a numerical value
  190. *
  191. * @param int $Outcome The outcome integer
  192. * @return string The formatted output string
  193. */
  194. public static function get_outcome_string($Outcome) {
  195. if ($Outcome == self::APPROVED) {
  196. $String = "Approved";
  197. } else if ($Outcome == self::DENIED) {
  198. $String = "Rejected";
  199. } else if ($Outcome == self::DISCARDED) {
  200. $String = "Discarded";
  201. } else {
  202. $String = "---";
  203. }
  204. return $String;
  205. }
  206. /**
  207. * Handle a user's request to enable an account
  208. *
  209. * @param string $Token The token
  210. * @return string The error output, or an empty string
  211. */
  212. public static function handle_token($Token) {
  213. $Token = db_string($Token);
  214. G::$DB->query("
  215. SELECT uer.UserID, uer.HandledTimestamp, um.torrent_pass, um.Visible, um.IP
  216. FROM users_enable_requests AS uer
  217. LEFT JOIN users_main AS um ON uer.UserID = um.ID
  218. WHERE Token = '$Token'");
  219. if (G::$DB->has_results()) {
  220. list($UserID, $Timestamp, $TorrentPass, $Visible, $IP) = G::$DB->next_record();
  221. G::$DB->query("UPDATE users_enable_requests SET Token = NULL WHERE Token = '$Token'");
  222. if ($Timestamp < time_minus(3600 * 48)) {
  223. // Old request
  224. Tools::update_user_notes($UserID, sqltime() . " - Tried to use an expired enable token from ".$_SERVER['REMOTE_ADDR']."\n\n");
  225. $Err = "Token has expired. Please visit ".BOT_DISABLED_CHAN." on ".BOT_SERVER." to discuss this with staff.";
  226. } else {
  227. // Good request, decrement cache value and enable account
  228. G::$Cache->decrement_value(AutoEnable::CACHE_KEY_NAME);
  229. $VisibleTrIP = ($Visible && DBCrypt::decrypt($IP) != '127.0.0.1') ? '1' : '0';
  230. Tracker::update_tracker('add_user', array('id' => $UserID, 'passkey' => $TorrentPass, 'visible' => $VisibleTrIP));
  231. G::$DB->query("UPDATE users_main SET Enabled = '1', can_leech = '1' WHERE ID = '$UserID'");
  232. G::$DB->query("UPDATE users_info SET BanReason = '0' WHERE UserID = '$UserID'");
  233. G::$Cache->delete_value('user_info_'.$UserID);
  234. $Err = "Your account has been enabled. You may now log in.";
  235. }
  236. } else {
  237. $Err = "Invalid token.";
  238. }
  239. return $Err;
  240. }
  241. /**
  242. * Build the search query, from the searchbox inputs
  243. *
  244. * @param int $UserID The user ID
  245. * @param string $IP The IP
  246. * @param string $SubmittedTimestamp The timestamp representing when the request was submitted
  247. * @param int $HandledUserID The ID of the user that handled the request
  248. * @param string $HandledTimestamp The timestamp representing when the request was handled
  249. * @param int $OutcomeSearch The outcome of the request
  250. * @param boolean $Checked Should checked requests be included?
  251. * @return array The WHERE conditions for the query
  252. */
  253. public static function build_search_query($Username, $IP, $SubmittedBetween, $SubmittedTimestamp1, $SubmittedTimestamp2, $HandledUsername, $HandledBetween, $HandledTimestamp1, $HandledTimestamp2, $OutcomeSearch, $Checked) {
  254. $Where = array();
  255. if (!empty($Username)) {
  256. $Where[] = "um1.Username = '$Username'";
  257. }
  258. if (!empty($IP)) {
  259. // TODO: make this work with encrypted IPs
  260. $Where[] = "uer.IP = '$IP'";
  261. }
  262. if (!empty($SubmittedTimestamp1)) {
  263. switch($SubmittedBetween) {
  264. case 'on':
  265. $Where[] = "DATE(uer.Timestamp) = DATE('$SubmittedTimestamp1')";
  266. break;
  267. case 'before':
  268. $Where[] = "DATE(uer.Timestamp) < DATE('$SubmittedTimestamp1')";
  269. break;
  270. case 'after':
  271. $Where[] = "DATE(uer.Timestamp) > DATE('$SubmittedTimestamp1')";
  272. break;
  273. case 'between':
  274. if (!empty($SubmittedTimestamp2)) {
  275. $Where[] = "DATE(uer.Timestamp) BETWEEN DATE('$SubmittedTimestamp1') AND DATE('$SubmittedTimestamp2')";
  276. }
  277. break;
  278. default:
  279. break;
  280. }
  281. }
  282. if (!empty($HandledTimestamp1)) {
  283. switch($HandledBetween) {
  284. case 'on':
  285. $Where[] = "DATE(uer.HandledTimestamp) = DATE('$HandledTimestamp1')";
  286. break;
  287. case 'before':
  288. $Where[] = "DATE(uer.HandledTimestamp) < DATE('$HandledTimestamp1')";
  289. break;
  290. case 'after':
  291. $Where[] = "DATE(uer.HandledTimestamp) > DATE('$HandledTimestamp1')";
  292. break;
  293. case 'between':
  294. if (!empty($HandledTimestamp2)) {
  295. $Where[] = "DATE(uer.HandledTimestamp) BETWEEN DATE('$HandledTimestamp1') AND DATE('$HandledTimestamp2')";
  296. }
  297. break;
  298. default:
  299. break;
  300. }
  301. }
  302. if (!empty($HandledUsername)) {
  303. $Where[] = "um2.Username = '$HandledUsername'";
  304. }
  305. if (!empty($OutcomeSearch)) {
  306. $Where[] = "uer.Outcome = '$OutcomeSearch'";
  307. }
  308. if ($Checked) {
  309. // This is to skip the if statement in enable_requests.php
  310. $Where[] = "(uer.Outcome IS NULL OR uer.Outcome IS NOT NULL)";
  311. }
  312. return $Where;
  313. }
  314. }