PageRenderTime 48ms CodeModel.GetById 14ms RepoModel.GetById 1ms app.codeStats 0ms

/includes/ucp/ucp_register.php

https://github.com/Vexilurz/phpbb_forum
PHP | 526 lines | 388 code | 83 blank | 55 comment | 72 complexity | 119eb991ddac96b33944ddd1f94fead1 MD5 | raw file
Possible License(s): AGPL-1.0
  1. <?php
  2. /**
  3. *
  4. * @package ucp
  5. * @version $Id$
  6. * @copyright (c) 2005 phpBB Group
  7. * @license http://opensource.org/licenses/gpl-license.php GNU Public License
  8. *
  9. */
  10. /**
  11. * @ignore
  12. */
  13. if (!defined('IN_PHPBB'))
  14. {
  15. exit;
  16. }
  17. /**
  18. * ucp_register
  19. * Board registration
  20. * @package ucp
  21. */
  22. class ucp_register
  23. {
  24. var $u_action;
  25. function main($id, $mode)
  26. {
  27. global $config, $db, $user, $auth, $template, $phpbb_root_path, $phpEx;
  28. //
  29. if ($config['require_activation'] == USER_ACTIVATION_DISABLE)
  30. {
  31. trigger_error('UCP_REGISTER_DISABLE');
  32. }
  33. include($phpbb_root_path . 'includes/functions_profile_fields.' . $phpEx);
  34. // START Anti-Spam ACP
  35. antispam::ucp_preregister();
  36. // END Anti-Spam ACP
  37. $coppa = (isset($_REQUEST['coppa'])) ? ((!empty($_REQUEST['coppa'])) ? 1 : 0) : false;
  38. $agreed = (!empty($_POST['agreed'])) ? 1 : 0;
  39. $submit = (isset($_POST['submit'])) ? true : false;
  40. $change_lang = request_var('change_lang', '');
  41. $user_lang = request_var('lang', $user->lang_name);
  42. if ($agreed)
  43. {
  44. add_form_key('ucp_register');
  45. }
  46. else
  47. {
  48. add_form_key('ucp_register_terms');
  49. }
  50. if ($change_lang || $user_lang != $config['default_lang'])
  51. {
  52. $use_lang = ($change_lang) ? basename($change_lang) : basename($user_lang);
  53. if (!validate_language_iso_name($use_lang))
  54. {
  55. if ($change_lang)
  56. {
  57. $submit = false;
  58. // Setting back agreed to let the user view the agreement in his/her language
  59. $agreed = (empty($_GET['change_lang'])) ? 0 : $agreed;
  60. }
  61. $user->lang_name = $user_lang = $use_lang;
  62. $user->lang = array();
  63. $user->data['user_lang'] = $user->lang_name;
  64. $user->add_lang(array('common', 'ucp'));
  65. }
  66. else
  67. {
  68. $change_lang = '';
  69. $user_lang = $user->lang_name;
  70. }
  71. }
  72. $cp = new custom_profile();
  73. $error = $cp_data = $cp_error = array();
  74. if (!$agreed || ($coppa === false && $config['coppa_enable']) || ($coppa && !$config['coppa_enable']))
  75. {
  76. $add_lang = ($change_lang) ? '&amp;change_lang=' . urlencode($change_lang) : '';
  77. $add_coppa = ($coppa !== false) ? '&amp;coppa=' . $coppa : '';
  78. $s_hidden_fields = array(
  79. 'change_lang' => $change_lang,
  80. );
  81. // If we change the language, we want to pass on some more possible parameter.
  82. if ($change_lang)
  83. {
  84. // We do not include the password
  85. $s_hidden_fields = array_merge($s_hidden_fields, array(
  86. 'username' => utf8_normalize_nfc(request_var('username', '', true)),
  87. 'email' => strtolower(request_var('email', '')),
  88. 'email_confirm' => strtolower(request_var('email_confirm', '')),
  89. 'lang' => $user->lang_name,
  90. 'tz' => request_var('tz', (float) $config['board_timezone']),
  91. //-- begin mod: Anti Bot Question -------------------------------------------//
  92. 'AB_Question' => strtolower(utf8_normalize_nfc(request_var('AB_Question', '', true))),
  93. //-- end mod: Anti Bot Question -------------------------------------------//
  94. ));
  95. }
  96. // Checking amount of available languages
  97. $sql = 'SELECT lang_id
  98. FROM ' . LANG_TABLE;
  99. $result = $db->sql_query($sql);
  100. $lang_row = array();
  101. while ($row = $db->sql_fetchrow($result))
  102. {
  103. $lang_row[] = $row;
  104. }
  105. $db->sql_freeresult($result);
  106. if ($coppa === false && $config['coppa_enable'])
  107. {
  108. $now = getdate();
  109. $coppa_birthday = $user->format_date(mktime($now['hours'] + $user->data['user_dst'], $now['minutes'], $now['seconds'], $now['mon'], $now['mday'] - 1, $now['year'] - 13), $user->lang['DATE_FORMAT']);
  110. unset($now);
  111. $template->assign_vars(array(
  112. 'S_LANG_OPTIONS' => (sizeof($lang_row) > 1) ? language_select($user_lang) : '',
  113. 'L_COPPA_NO' => sprintf($user->lang['UCP_COPPA_BEFORE'], $coppa_birthday),
  114. 'L_COPPA_YES' => sprintf($user->lang['UCP_COPPA_ON_AFTER'], $coppa_birthday),
  115. 'U_COPPA_NO' => append_sid("{$phpbb_root_path}ucp.$phpEx", 'mode=register&amp;coppa=0' . $add_lang),
  116. 'U_COPPA_YES' => append_sid("{$phpbb_root_path}ucp.$phpEx", 'mode=register&amp;coppa=1' . $add_lang),
  117. 'S_SHOW_COPPA' => true,
  118. 'S_HIDDEN_FIELDS' => build_hidden_fields($s_hidden_fields),
  119. 'S_UCP_ACTION' => append_sid("{$phpbb_root_path}ucp.$phpEx", 'mode=register' . $add_lang),
  120. ));
  121. }
  122. else
  123. {
  124. $template->assign_vars(array(
  125. 'S_LANG_OPTIONS' => (sizeof($lang_row) > 1) ? language_select($user_lang) : '',
  126. 'L_TERMS_OF_USE' => sprintf($user->lang['TERMS_OF_USE_CONTENT'], $config['sitename'], generate_board_url()),
  127. 'S_SHOW_COPPA' => false,
  128. 'S_REGISTRATION' => true,
  129. 'S_HIDDEN_FIELDS' => build_hidden_fields($s_hidden_fields),
  130. 'S_UCP_ACTION' => append_sid("{$phpbb_root_path}ucp.$phpEx", 'mode=register' . $add_lang . $add_coppa),
  131. )
  132. );
  133. }
  134. unset($lang_row);
  135. $this->tpl_name = 'ucp_agreement';
  136. return;
  137. }
  138. // The CAPTCHA kicks in here. We can't help that the information gets lost on language change.
  139. if ($config['enable_confirm'])
  140. {
  141. include($phpbb_root_path . 'includes/captcha/captcha_factory.' . $phpEx);
  142. $captcha =& phpbb_captcha_factory::get_instance($config['captcha_plugin']);
  143. $captcha->init(CONFIRM_REG);
  144. }
  145. $is_dst = $config['board_dst'];
  146. $timezone = $config['board_timezone'];
  147. $data = array(
  148. 'username' => utf8_normalize_nfc(request_var('username', '', true)),
  149. 'new_password' => request_var('new_password', '', true),
  150. 'password_confirm' => request_var('password_confirm', '', true),
  151. 'email' => strtolower(request_var('email', '')),
  152. 'email_confirm' => strtolower(request_var('email_confirm', '')),
  153. 'lang' => basename(request_var('lang', $user->lang_name)),
  154. 'tz' => request_var('tz', (float) $timezone),
  155. );
  156. // Check and initialize some variables if needed
  157. if ($submit)
  158. {
  159. $error = validate_data($data, array(
  160. 'username' => array(
  161. array('string', false, $config['min_name_chars'], $config['max_name_chars']),
  162. array('username', '')),
  163. 'new_password' => array(
  164. array('string', false, $config['min_pass_chars'], $config['max_pass_chars']),
  165. array('password')),
  166. 'password_confirm' => array('string', false, $config['min_pass_chars'], $config['max_pass_chars']),
  167. 'email' => array(
  168. array('string', false, 6, 60),
  169. array('email')),
  170. 'email_confirm' => array('string', false, 6, 60),
  171. //-- begin mod: Anti Bot Question -------------------------------------------//
  172. 'AB_Question' => array('string', !$config['abanswer']),
  173. //-- end mod: Anti Bot Question -------------------------------------------//
  174. 'tz' => array('num', false, -14, 14),
  175. 'lang' => array('language_iso_name'),
  176. ));
  177. if (!check_form_key('ucp_register'))
  178. {
  179. $error[] = $user->lang['FORM_INVALID'];
  180. }
  181. // Replace "error" strings with their real, localised form
  182. $error = preg_replace('#^([A-Z_]+)$#e', "(!empty(\$user->lang['\\1'])) ? \$user->lang['\\1'] : '\\1'", $error);
  183. if ($config['enable_confirm'])
  184. {
  185. $vc_response = $captcha->validate($data);
  186. if ($vc_response !== false)
  187. {
  188. $error[] = $vc_response;
  189. }
  190. if ($config['max_reg_attempts'] && $captcha->get_attempt_count() > $config['max_reg_attempts'])
  191. {
  192. $error[] = $user->lang['TOO_MANY_REGISTERS'];
  193. }
  194. }
  195. // DNSBL check
  196. if ($config['check_dnsbl'])
  197. {
  198. if (($dnsbl = $user->check_dnsbl('register')) !== false)
  199. {
  200. $error[] = sprintf($user->lang['IP_BLACKLISTED'], $user->ip, $dnsbl[1]);
  201. }
  202. }
  203. // validate custom profile fields
  204. $cp->submit_cp_field('register', $user->get_iso_lang_id(), $cp_data, $error);
  205. if (!sizeof($error))
  206. {
  207. if ($data['new_password'] != $data['password_confirm'])
  208. {
  209. $error[] = $user->lang['NEW_PASSWORD_ERROR'];
  210. }
  211. if ($data['email'] != $data['email_confirm'])
  212. {
  213. $error[] = $user->lang['NEW_EMAIL_ERROR'];
  214. }
  215. //-- begin mod: Anti Bot Question -------------------------------------------//
  216. if ($config['enable_abquestion'])
  217. {
  218. if ($data['AB_Question'] == '')
  219. {
  220. $error[] = $user->lang['AB_NO_ANSWER'];
  221. }
  222. else if ($data['AB_Question'] != strtolower($config['abanswer']) && $data['AB_Question'] != strtolower($config['abanswer2']))
  223. {
  224. $error[] = $user->lang['AB_QUESTION_ERROR'];
  225. }
  226. }
  227. //-- end mod: Anti Bot Question -------------------------------------------//
  228. }
  229. // START Anti-Spam ACP
  230. antispam::ucp_register($data, $error);
  231. // END Anti-Spam ACP
  232. if (!sizeof($error))
  233. {
  234. $server_url = generate_board_url();
  235. // Which group by default?
  236. $group_name = ($coppa) ? 'REGISTERED_COPPA' : 'REGISTERED';
  237. $sql = 'SELECT group_id
  238. FROM ' . GROUPS_TABLE . "
  239. WHERE group_name = '" . $db->sql_escape($group_name) . "'
  240. AND group_type = " . GROUP_SPECIAL;
  241. $result = $db->sql_query($sql);
  242. $row = $db->sql_fetchrow($result);
  243. $db->sql_freeresult($result);
  244. if (!$row)
  245. {
  246. trigger_error('NO_GROUP');
  247. }
  248. $group_id = $row['group_id'];
  249. if (($coppa ||
  250. $config['require_activation'] == USER_ACTIVATION_SELF ||
  251. $config['require_activation'] == USER_ACTIVATION_ADMIN) && $config['email_enable'])
  252. {
  253. $user_actkey = gen_rand_string(mt_rand(6, 10));
  254. $user_type = USER_INACTIVE;
  255. $user_inactive_reason = INACTIVE_REGISTER;
  256. $user_inactive_time = time();
  257. }
  258. else
  259. {
  260. $user_type = USER_NORMAL;
  261. $user_actkey = '';
  262. $user_inactive_reason = 0;
  263. $user_inactive_time = 0;
  264. }
  265. $user_row = array(
  266. 'username' => $data['username'],
  267. 'user_password' => phpbb_hash($data['new_password']),
  268. 'user_email' => $data['email'],
  269. 'group_id' => (int) $group_id,
  270. 'user_timezone' => (float) $data['tz'],
  271. 'user_dst' => $is_dst,
  272. 'user_lang' => $data['lang'],
  273. 'user_type' => $user_type,
  274. 'user_actkey' => $user_actkey,
  275. 'user_ip' => $user->ip,
  276. 'user_regdate' => time(),
  277. 'user_inactive_reason' => $user_inactive_reason,
  278. 'user_inactive_time' => $user_inactive_time,
  279. );
  280. if ($config['new_member_post_limit'])
  281. {
  282. $user_row['user_new'] = 1;
  283. }
  284. // Register user...
  285. $user_id = user_add($user_row, $cp_data);
  286. // START Anti-Spam ACP
  287. antispam::ucp_postregister($user_id, $user_row);
  288. // END Anti-Spam ACP
  289. // This should not happen, because the required variables are listed above...
  290. if ($user_id === false)
  291. {
  292. trigger_error('NO_USER', E_USER_ERROR);
  293. }
  294. // Okay, captcha, your job is done.
  295. if ($config['enable_confirm'] && isset($captcha))
  296. {
  297. $captcha->reset();
  298. }
  299. if ($coppa && $config['email_enable'])
  300. {
  301. $message = $user->lang['ACCOUNT_COPPA'];
  302. $email_template = 'coppa_welcome_inactive';
  303. }
  304. else if ($config['require_activation'] == USER_ACTIVATION_SELF && $config['email_enable'])
  305. {
  306. $message = $user->lang['ACCOUNT_INACTIVE'];
  307. $email_template = 'user_welcome_inactive';
  308. }
  309. else if ($config['require_activation'] == USER_ACTIVATION_ADMIN && $config['email_enable'])
  310. {
  311. $message = $user->lang['ACCOUNT_INACTIVE_ADMIN'];
  312. $email_template = 'admin_welcome_inactive';
  313. }
  314. else
  315. {
  316. $message = $user->lang['ACCOUNT_ADDED'];
  317. $email_template = 'user_welcome';
  318. }
  319. if ($config['email_enable'])
  320. {
  321. include_once($phpbb_root_path . 'includes/functions_messenger.' . $phpEx);
  322. $messenger = new messenger(false);
  323. $messenger->template($email_template, $data['lang']);
  324. $messenger->to($data['email'], $data['username']);
  325. $messenger->anti_abuse_headers($config, $user);
  326. $messenger->assign_vars(array(
  327. 'WELCOME_MSG' => htmlspecialchars_decode(sprintf($user->lang['WELCOME_SUBJECT'], $config['sitename'])),
  328. 'USERNAME' => htmlspecialchars_decode($data['username']),
  329. 'PASSWORD' => htmlspecialchars_decode($data['new_password']),
  330. 'U_ACTIVATE' => "$server_url/ucp.$phpEx?mode=activate&u=$user_id&k=$user_actkey")
  331. );
  332. if ($coppa)
  333. {
  334. $messenger->assign_vars(array(
  335. 'FAX_INFO' => $config['coppa_fax'],
  336. 'MAIL_INFO' => $config['coppa_mail'],
  337. 'EMAIL_ADDRESS' => $data['email'])
  338. );
  339. }
  340. $messenger->send(NOTIFY_EMAIL);
  341. if ($config['require_activation'] == USER_ACTIVATION_ADMIN)
  342. {
  343. // Grab an array of user_id's with a_user permissions ... these users can activate a user
  344. $admin_ary = $auth->acl_get_list(false, 'a_user', false);
  345. $admin_ary = (!empty($admin_ary[0]['a_user'])) ? $admin_ary[0]['a_user'] : array();
  346. // Also include founders
  347. $where_sql = ' WHERE user_type = ' . USER_FOUNDER;
  348. if (sizeof($admin_ary))
  349. {
  350. $where_sql .= ' OR ' . $db->sql_in_set('user_id', $admin_ary);
  351. }
  352. $sql = 'SELECT user_id, username, user_email, user_lang, user_jabber, user_notify_type
  353. FROM ' . USERS_TABLE . ' ' .
  354. $where_sql;
  355. $result = $db->sql_query($sql);
  356. while ($row = $db->sql_fetchrow($result))
  357. {
  358. $messenger->template('admin_activate', $row['user_lang']);
  359. $messenger->to($row['user_email'], $row['username']);
  360. $messenger->im($row['user_jabber'], $row['username']);
  361. $messenger->assign_vars(array(
  362. 'USERNAME' => htmlspecialchars_decode($data['username']),
  363. 'U_USER_DETAILS' => "$server_url/memberlist.$phpEx?mode=viewprofile&u=$user_id",
  364. 'U_ACTIVATE' => "$server_url/ucp.$phpEx?mode=activate&u=$user_id&k=$user_actkey")
  365. );
  366. $messenger->send($row['user_notify_type']);
  367. }
  368. $db->sql_freeresult($result);
  369. }
  370. }
  371. $message = $message . '<br /><br />' . sprintf($user->lang['RETURN_INDEX'], '<a href="' . append_sid("{$phpbb_root_path}index.$phpEx") . '">', '</a>');
  372. trigger_error($message);
  373. }
  374. }
  375. $s_hidden_fields = array(
  376. 'agreed' => 'true',
  377. 'change_lang' => 0,
  378. );
  379. if ($config['coppa_enable'])
  380. {
  381. $s_hidden_fields['coppa'] = $coppa;
  382. }
  383. if ($config['enable_confirm'])
  384. {
  385. $s_hidden_fields = array_merge($s_hidden_fields, $captcha->get_hidden_fields());
  386. }
  387. $s_hidden_fields = build_hidden_fields($s_hidden_fields);
  388. $confirm_image = '';
  389. // Visual Confirmation - Show images
  390. if ($config['enable_confirm'])
  391. {
  392. $template->assign_vars(array(
  393. 'CAPTCHA_TEMPLATE' => $captcha->get_template(),
  394. ));
  395. }
  396. //
  397. $l_reg_cond = '';
  398. switch ($config['require_activation'])
  399. {
  400. case USER_ACTIVATION_SELF:
  401. $l_reg_cond = $user->lang['UCP_EMAIL_ACTIVATE'];
  402. break;
  403. case USER_ACTIVATION_ADMIN:
  404. $l_reg_cond = $user->lang['UCP_ADMIN_ACTIVATE'];
  405. break;
  406. }
  407. $template->assign_vars(array(
  408. 'ERROR' => (sizeof($error)) ? implode('<br />', $error) : '',
  409. 'USERNAME' => $data['username'],
  410. 'PASSWORD' => $data['new_password'],
  411. 'PASSWORD_CONFIRM' => $data['password_confirm'],
  412. 'EMAIL' => $data['email'],
  413. 'EMAIL_CONFIRM' => $data['email_confirm'],
  414. //-- begin mod: Anti Bot Question -------------------------------------------//
  415. 'AB_QUESTION' => $data['AB_Question'],
  416. //-- end mod: Anti Bot Question -------------------------------------------//
  417. 'L_REG_COND' => $l_reg_cond,
  418. 'L_USERNAME_EXPLAIN' => sprintf($user->lang[$config['allow_name_chars'] . '_EXPLAIN'], $config['min_name_chars'], $config['max_name_chars']),
  419. 'L_PASSWORD_EXPLAIN' => sprintf($user->lang[$config['pass_complex'] . '_EXPLAIN'], $config['min_pass_chars'], $config['max_pass_chars']),
  420. //-- begin mod: Anti Bot Question -------------------------------------------//
  421. 'L_AB_QUESTION' => $config['abquestion'],
  422. //-- end mod: Anti Bot Question -------------------------------------------//
  423. 'S_LANG_OPTIONS' => language_select($data['lang']),
  424. 'S_TZ_OPTIONS' => tz_select($data['tz']),
  425. 'S_CONFIRM_REFRESH' => ($config['enable_confirm'] && $config['confirm_refresh']) ? true : false,
  426. //-- begin mod: Anti Bot Question -------------------------------------------//
  427. 'S_ABQ_CODE' => ($config['enable_abquestion'] == 1) ? true : false,
  428. //-- end mod: Anti Bot Question -------------------------------------------//
  429. 'S_REGISTRATION' => true,
  430. 'S_COPPA' => $coppa,
  431. 'S_HIDDEN_FIELDS' => $s_hidden_fields,
  432. 'S_UCP_ACTION' => append_sid("{$phpbb_root_path}ucp.$phpEx", 'mode=register'),
  433. ));
  434. //
  435. $user->profile_fields = array();
  436. // Generate profile fields -> Template Block Variable profile_fields
  437. $cp->generate_profile_fields('register', $user->get_iso_lang_id());
  438. //
  439. $this->tpl_name = 'ucp_register';
  440. $this->page_title = 'UCP_REGISTRATION';
  441. }
  442. }
  443. ?>