Merge branch 'develop' of https://github.com/xpressengine/xe-core into develop

# By bnu (17) and khongchi (5)
# Via khongchi
* 'develop' of https://github.com/xpressengine/xe-core: (22 commits)
  #270 비밀번호 보안수준 설정 기능 추가 (보완)
  version update 1.7.4-beta.6
  #270 비밀번호 보안수준 설정 기능 추가
  #279 이메일을 체크할 때 항상 대소문자 구분 없이 체크하도록 변경
  #278 getModuleExtraVars()의 잘못 된 처리 수정.
  #278 25ca3e1 에서 query 호출 시점을 잘못 잡는 문제 수정.
  #278 debug 환경 개선. - query 목록에 query id와 파일 및 메소드명 표시 - 실행 중 중단 시 중단 시점의 파일과 메소드명 표시
  NOISSUE syntax error;;
  #242 module_part_config 초기화 문제로 인해 되돌림.
  Revert "NOISSUE point 모듈에서 modulePartConfig 변수를 잘못 사용하는 문제 수정."
  #62 잘못 설정한 rule 제거.
  NOISSUE 불필요 제거.
  #242 캐시 사용 시 columnList 초기화.
  NOISSUE point 모듈에서 modulePartConfig 변수를 잘못 사용하는 문제 수정.
  #62 nick_name 글자 제한 추가.
  #242 member_info 캐시 초기화 빠진 부분 추가.
  #242 member_info 캐시는 file cache에서 제외.
  NOISSUE php 버전 호환성 문제 고침.
  #242 문서 사용자 정의 필드 설정이 갱신 안 되는 문제 수정.
  NOISSUE cache/module_info 파일이 없을 때 문제 수정. include.
  ...
This commit is contained in:
largeden 2014-01-11 10:18:44 +09:00
commit ca0c232448
24 changed files with 316 additions and 147 deletions

View file

@ -1696,15 +1696,15 @@
<item name="about_password_strength" type="array">
<item name="low">
<value xml:lang="ko"><![CDATA[비밀번호는 4~20자로 되어야 합니다.]]></value>
<value xml:lang="ko"><![CDATA[비밀번호는 4자 이상이어야 합니다.]]></value>
<value xml:lang="en"><![CDATA[the password must be at least 4]]></value>
</item>
<item name="normal">
<value xml:lang="ko"><![CDATA[비밀번호는 6자리 이상이고, 영문과 숫자를 반드시 포함해야 합니다.]]></value>
<value xml:lang="ko"><![CDATA[비밀번호는 6자리 이상이어야 하며 영문과 숫자를 반드시 포함해야 합니다.]]></value>
<value xml:lang="en"><![CDATA[the password must be at least 6, and must have at least one alpha character and numeric characters]]></value>
</item>
<item name="high">
<value xml:lang="ko"><![CDATA[비밀번호는 8자리 이상이 영문과 숫자, 특수문자를 반드시 포함해야 합니다.]]></value>
<value xml:lang="ko"><![CDATA[비밀번호는 8자리 이상이어야 하며 영문과 숫자, 특수문자를 반드시 포함해야 합니다.]]></value>
<value xml:lang="en"><![CDATA[the password must be at least 8, and must have at least one alpha character, numeric character and special character ]]></value>
</item>
</item>

View file

@ -487,6 +487,10 @@ class memberAdminController extends member
{
$fields[] = sprintf('<field name="%s" required="true" rule="userid" length="3:20" />', $formInfo->name);
}
else if($formInfo->name == 'nick_name')
{
$fields[] = sprintf('<field name="%s" required="true" length="2:20" />', $formInfo->name);
}
else if(strpos($formInfo->name, 'image') !== false)
{
$fields[] = sprintf('<field name="%s"><if test="$act != \'procMemberAdminInsert\' &amp;&amp; $__%s_exist != \'true\'" attr="required" value="true" /></field>', $formInfo->name, $formInfo->name);
@ -823,6 +827,7 @@ class memberAdminController extends member
{
$args->denied = $var->denied;
$output = executeQuery('member.updateMemberDeniedInfo', $args);
$this->_clearMemberCache($args->member_srl);
if(!$output->toBool())
{
$oDB->rollback();
@ -938,6 +943,9 @@ class memberAdminController extends member
}
}
$oDB->commit();
$this->_deleteMemberGroupCache();
$this->setMessage('success_updated');
if(!in_array(Context::getRequestMethod(),array('XMLRPC','JSON')))

View file

@ -107,6 +107,8 @@ class memberController extends member
if($config->after_logout_url)
$output->redirect_url = $config->after_logout_url;
$this->_clearMemberCache($args->member_srl);
return $output;
}
@ -248,7 +250,7 @@ class memberController extends member
{
if (Context::getRequestMethod () == "GET") return new Object (-1, "msg_invalid_request");
$oMemberModel = &getModel ('member');
$config = $oMemberModel->getMemberConfig ();
$config = $oMemberModel->getMemberConfig();
// call a trigger (before)
$trigger_output = ModuleHandler::triggerCall ('member.procMemberInsert', 'before', $config);
@ -286,6 +288,13 @@ class memberController extends member
if($args->password1) $args->password = $args->password1;
// check password strength
if(!$oMemberModel->checkPasswordStrength($args->password, $config->password_strength))
{
$message = Context::getLang('about_password_strength');
return new Object(-1, $message[$config->password_strength]);
}
// Remove some unnecessary variables from all the vars
$all_args = Context::getRequestVars();
unset($all_args->module);
@ -380,6 +389,8 @@ class memberController extends member
}
}
$this->_clearMemberCache($args->member_srl);
$this->setRedirectUrl($returnUrl);
}
@ -523,8 +534,12 @@ class memberController extends member
// Save Signature
$signature = Context::get('signature');
$this->putSignature($args->member_srl, $signature);
// Get user_id information
$this->memberInfo = $oMemberModel->getMemberInfoByMemberSrl($args->member_srl);
$this->_clearMemberCache($args->member_srl);
// Call a trigger after successfully log-in (after)
$trigger_output = ModuleHandler::triggerCall('member.procMemberModifyInfo', 'after', $this->memberInfo);
if(!$trigger_output->toBool()) return $trigger_output;
@ -556,16 +571,7 @@ class memberController extends member
$oMemberModel = getModel('member');
// Get information of member_srl
$columnList = array('member_srl', 'password');
// check password strength
$config = $oMemberModel->getMemberConfig();
if(!$oMemberModel->checkPasswordStrength($password, $config->password_strength))
{
$message = Context::getLang('about_password_strength');
return new Object(-1, $message[$config->password_strength]);
}
$member_info = $oMemberModel->getMemberInfoByMemberSrl($member_srl, 0, $columnList);
// Verify the cuttent password
if(!$oMemberModel->isValidPassword($member_info->password, $current_password, $member_srl)) return new Object(-1, 'invalid_password');
@ -619,6 +625,8 @@ class memberController extends member
// Return success message
$this->setMessage('success_leaved');
$this->_clearMemberCache($member_srl);
$returnUrl = Context::get('success_return_url') ? Context::get('success_return_url') : getNotEncodedUrl('', 'mid', Context::get('mid'), 'act', '');
$this->setRedirectUrl($returnUrl);
}
@ -1071,6 +1079,9 @@ class memberController extends member
if(!$output->toBool()) return $this->stop($output->getMessage());
// Remove all values having the member_srl from authentication table
executeQuery('member.deleteAuthMail',$args);
$this->_clearMemberCache($args->member_srl);
// Notify the result
Context::set('is_register', $is_register);
$this->setTemplatePath($this->module_path.'tpl');
@ -1251,6 +1262,7 @@ class memberController extends member
list($args->email_id, $args->email_host) = explode('@', $newEmail);
$output = executeQuery('member.updateMemberEmailAddress', $args);
$this->_clearMemberCache($args->member_srl);
if(!$output->toBool())
{
return $this->stop($output->getMessage());
@ -1367,6 +1379,7 @@ class memberController extends member
$output = executeQuery('member.deleteMembersGroup', $args);
if(!$output->toBool()) return $output;
$this->setMessage('success_deleted');
$this->_clearMemberCache($args->member_srl);
}
/**
@ -1467,13 +1480,13 @@ class memberController extends member
$oCacheHandler = CacheHandler::getInstance('object', null, true);
if($oCacheHandler->isSupport())
{
$object_key = 'member_groups:' . getNumberingPath($args->member_srl) . $args->member_srl . '_'.$args->site_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
$oCacheHandler->invalidateGroupKey('member');
}
$object_key = 'member_info:' . getNumberingPath($args->member_srl) . $args->member_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
$oCacheHandler = CacheHandler::getInstance('object');
if($oCacheHandler->isSupport())
{
$oCacheHandler->invalidateGroupKey('member');
}
return $output;
@ -1514,20 +1527,9 @@ class memberController extends member
$output = executeQuery('member.addMemberToGroup', $obj);
if(!$output->toBool()) return $output;
$oCacheHandler = CacheHandler::getInstance('object', null, true);
if($oCacheHandler->isSupport())
{
$object_key = 'member_groups:' . getNumberingPath($args->member_srl) . $args->member_srl . '_' . $args->site_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
$object_key = 'member_info:' . getNumberingPath($args->member_srl) . $args->member_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
}
$this->_clearMemberCache($args->member_srl);
}
return new Object();
}
@ -1704,6 +1706,8 @@ class memberController extends member
$args->member_srl = $this->memberInfo->member_srl;
$output = executeQuery('member.updateLastLogin', $args);
$this->_clearMemberCache($args->member_srl);
// Check if there is recoding table.
$oDB = &DB::getInstance();
if($oDB->isTableExists('member_count_history') && $config->enable_login_fail_report != 'N')
@ -1901,7 +1905,19 @@ class memberController extends member
if($args->blog && !preg_match("/^[a-z]+:\/\//i",$args->blog)) $args->blog = 'http://'.$args->blog;
// Create a model object
$oMemberModel = getModel('member');
// ID check is prohibited
if($args->password && !$password_is_hashed)
{
// check password strength
if(!$oMemberModel->checkPasswordStrength($args->password, $config->password_strength))
{
$message = Context::getLang('about_password_strength');
return new Object(-1, $message[$config->password_strength]);
}
$args->password = md5($args->password);
}
elseif(!$args->password) unset($args->password);
if($oMemberModel->isDeniedID($args->user_id)) return new Object(-1,'denied_user_id');
// ID, nickname, email address of the redundancy check
$member_srl = $oMemberModel->getMemberSrlByUserID($args->user_id);
@ -1918,20 +1934,19 @@ class memberController extends member
$member_srl = $oMemberModel->getMemberSrlByEmailAddress($args->email_address);
if($member_srl) return new Object(-1,'msg_exists_email_address');
$oDB = &DB::getInstance();
$oDB->begin();
// Insert data into the DB
$args->list_order = -1 * $args->member_srl;
$args->nick_name = htmlspecialchars($args->nick_name, ENT_COMPAT | ENT_HTML401, 'UTF-8', false);
$args->homepage = htmlspecialchars($args->homepage, ENT_COMPAT | ENT_HTML401, 'UTF-8', false);
$args->blog = htmlspecialchars($args->blog, ENT_COMPAT | ENT_HTML401, 'UTF-8', false);
if($args->password && !$password_is_hashed) $args->password = md5($args->password);
elseif(!$args->password) unset($args->password);
if(!$args->user_id) $args->user_id = 't'.$args->member_srl;
if(!$args->user_name) $args->user_name = $args->member_srl;
$oDB = &DB::getInstance();
$oDB->begin();
$output = executeQuery('member.insertMember', $args);
if(!$output->toBool())
{
@ -2081,7 +2096,17 @@ class memberController extends member
$oDB->begin();
// DB in the update
if($args->password) $args->password = md5($args->password);
if($args->password)
{
// check password strength
if(!$oMemberModel->checkPasswordStrength($args->password, $config->password_strength))
{
$message = Context::getLang('about_password_strength');
return new Object(-1, $message[$config->password_strength]);
}
$args->password = md5($args->password);
}
else $args->password = $orgMemberInfo->password;
if(!$args->user_name) $args->user_name = $orgMemberInfo->user_name;
if(!$args->user_id) $args->user_id = $orgMemberInfo->user_id;
@ -2090,6 +2115,7 @@ class memberController extends member
if(!$args->birthday) $args->birthday = '';
$output = executeQuery('member.updateMember', $args);
$this->_clearMemberCache($args->member_srl);
if(!$output->toBool())
{
$oDB->rollback();
@ -2138,8 +2164,10 @@ class memberController extends member
$oDB->commit();
$this->_clearMemberCache($args->member_srl);
//remove from cache
$oCacheHandler = CacheHandler::getInstance('object', null, true);
$oCacheHandler = CacheHandler::getInstance('object');
if($oCacheHandler->isSupport())
{
$object_key = 'member_info:' . getNumberingPath($args->member_srl) . $args->member_srl;
@ -2161,17 +2189,20 @@ class memberController extends member
function updateMemberPassword($args)
{
$output = executeQuery('member.updateChangePasswordDate', $args);
//remove from cache
$oCacheHandler = CacheHandler::getInstance('object', null, true);
if($oCacheHandler->isSupport())
{
$object_key = 'member_info:' . getNumberingPath($args->member_srl) . $args->member_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
}
if($args->password)
{
// check password strength
$oMemberModel = getModel('member');
$config = $oMemberModel->getMemberConfig();
if(!$oMemberModel->checkPasswordStrength($args->password, $config->password_strength))
{
$message = Context::getLang('about_password_strength');
return new Object(-1, $message[$config->password_strength]);
}
if($this->useSha1)
{
$args->password = md5(sha1(md5($args->password)));
@ -2186,7 +2217,11 @@ class memberController extends member
$args->password = $args->hashed_password;
}
return executeQuery('member.updateMemberPassword', $args);
$output = executeQuery('member.updateMemberPassword', $args);;
$this->_clearMemberCache($args->member_srl);
return $output;
}
/**
@ -2568,7 +2603,11 @@ class memberController extends member
$args->description .= Context::getLang('cmd_spammer') . "[" . date("Y-m-d H:i:s") . " from:" . $logged_info->user_id . " info:" . $spam_description . " docuemnts count:" . $total_count . "]";
return $this->updateMember($args, true);
$output = $this->updateMember($args, true);
$this->_clearMemberCache($args->member_srl);
return $output;
}
/**
@ -2613,6 +2652,17 @@ class memberController extends member
return array();
}
function _clearMemberCache($member_srl)
{
$oCacheHandler = CacheHandler::getInstance('object');
if($oCacheHandler->isSupport())
{
$object_key = 'member_info:' . getNumberingPath($member_srl) . $member_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$oCacheHandler->delete($cache_key);
}
}
}
/* End of file member.controller.php */
/* Location: ./modules/member/member.controller.php */

View file

@ -265,8 +265,19 @@ class memberModel extends member
if(!$email_address) return;
$args = new stdClass();
$args->email_address = $email_address;
$output = executeQuery('member.getMemberInfoByEmailAddress', $args);
$db_info = Context::getDBInfo ();
if($db_info->master_db['db_type'] == "cubrid")
{
$args->email_address = strtolower($email_address);
$output = executeQuery('member.getMemberInfoByEmailAddressForCubrid', $args);
}
else
{
$args->email_address = $email_address;
$output = executeQuery('member.getMemberInfoByEmailAddress', $args);
}
if(!$output->toBool()) return $output;
if(!$output->data) return;
@ -284,9 +295,10 @@ class memberModel extends member
//columnList size zero... get full member info
if(!$GLOBALS['__member_info__'][$member_srl] || count($columnList) == 0)
{
$oCacheHandler = CacheHandler::getInstance('object', null, true);
$oCacheHandler = CacheHandler::getInstance('object');
if($oCacheHandler->isSupport())
{
$columnList = array();
$object_key = 'member_info:' . getNumberingPath($member_srl) . $member_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$GLOBALS['__member_info__'][$member_srl] = $oCacheHandler->get($cache_key);
@ -507,6 +519,7 @@ class memberModel extends member
$oCacheHandler = CacheHandler::getInstance('object', null, true);
if($oCacheHandler->isSupport())
{
$columnList = array();
$object_key = 'default_group_' . $site_srl;
$cache_key = $oCacheHandler->getGroupKey('member', $object_key);
$default_group = $oCacheHandler->get($cache_key);
@ -1037,17 +1050,20 @@ class memberModel extends member
}
function checkPasswordStrength($password, $stength)
function checkPasswordStrength($password, $strength)
{
if($stength == NULL)
$logged_info = Context::get('logged_info');
if($logged_info->is_admin == 'Y') return true;
if($strength == NULL)
{
$config = $this->getMemberConfig();
$stength = $config->password_strength?$config->password_strength:'normal';
$strength = $config->password_strength?$config->password_strength:'normal';
}
$length = strlen($password);
switch ($stength) {
switch ($strength) {
case 'high':
if($length < 8 || !preg_match('/[^a-zA-Z0-9]/', $password)) return false;
/* no break */

View file

@ -6,6 +6,6 @@
<column name="*" />
</columns>
<conditions>
<condition operation="like" column="email_address" var="email_address" notnull="notnull" />
<condition operation="equal" column="email_address" var="email_address" notnull="notnull" />
</conditions>
</query>

View file

@ -0,0 +1,11 @@
<query id="getMemberInfoByEmailAddress" action="select">
<tables>
<table name="member" />
</tables>
<columns>
<column name="*" />
</columns>
<conditions>
<condition operation="equal" column="lcase(email_address)" var="email_address" notnull="notnull" />
</conditions>
</query>

View file

@ -1,11 +1,6 @@
<load target="css/member.css" />
<load target="js/member.js" />
<div cond="$XE_VALIDATOR_MESSAGE && isset($validator_ids[$XE_VALIDATOR_ID])" class="message {$XE_VALIDATOR_MESSAGE_TYPE}">
<p>{$XE_VALIDATOR_MESSAGE}</p>
</div>
<section class="xm">
<ul class="nav nav-tabs" cond="$is_logged && $logged_info->menu_list && (!$member_srl || $member_srl == $logged_info->member_srl)">
<li loop="$logged_info->menu_list=>$key,$val" class="active"|cond="$key==$act">

View file

@ -4,12 +4,13 @@
<!--%load_js_plugin("ui.datepicker")-->
<include target="./common_header.html" />
<h1 style="border-bottom:1px solid #ccc">{$lang->cmd_signup}</h1>
<div cond="$XE_VALIDATOR_MESSAGE && $XE_VALIDATOR_ID == 'modules/member/skins/default/signup_form/1'" class="message {$XE_VALIDATOR_MESSAGE_TYPE}">
<div cond="$XE_VALIDATOR_MESSAGE && $XE_VALIDATOR_ID == 'modules/member/skins/default/modify_info/1'" class="message {$XE_VALIDATOR_MESSAGE_TYPE}">
<p>{$XE_VALIDATOR_MESSAGE}</p>
</div>
<form ruleset="@insertMember" id="fo_insert_member" action="./" method="post" enctype="multipart/form-data" class="form-horizontal">
<input type="hidden" name="act" value="procMemberInsert" />
<input type="hidden" name="xe_validator_id" value="modules/member/skins/default/signup_form/1" />
<input type="hidden" name="xe_validator_id" value="modules/member/skins/default/modify_info/1" />
<input type="hidden" name="success_return_url" value="{getUrl('act','dispMemberInfo')}" />
<div class="agreement" cond="$member_config->agreement">
<div class="text">
{$member_config->agreement}
@ -31,7 +32,7 @@
<label for="password" class="control-label"><em style="color:red">*</em> {$lang->password}</label>
<div class="controls">
<input type="password" name="password" id="password" value="" required />
<p class="help-inline">{$lang->about_password}</p>
<p class="help-inline">{$lang->about_password_strength[$member_config->password_strength]}</p>
</div>
</div>
<div class="control-group">