This commit is contained in:
+13
-60
@@ -25,65 +25,18 @@
|
|||||||
* International Registered Trademark & Property of PrestaShop SA
|
* International Registered Trademark & Property of PrestaShop SA
|
||||||
*/
|
*/
|
||||||
|
|
||||||
define('_PS_ADMIN_DIR_', dirname(__FILE__));
|
define('_PS_ADMIN_DIR_', getcwd());
|
||||||
|
require(dirname(__FILE__).'/../config/config.inc.php');
|
||||||
include(_PS_ADMIN_DIR_.'/../config/config.inc.php');
|
require(dirname(__FILE__).'/functions.php');
|
||||||
include(_PS_ADMIN_DIR_.'/functions.php');
|
|
||||||
|
|
||||||
|
|
||||||
include(_PS_ADMIN_DIR_.'/init.php');
|
|
||||||
|
|
||||||
if (empty($tab) and !sizeof($_POST))
|
|
||||||
{
|
|
||||||
$tab = 'AdminHome';
|
|
||||||
$_POST['tab'] = 'AdminHome';
|
|
||||||
$_POST['token'] = Tools::getAdminTokenLite($tab);
|
|
||||||
}
|
|
||||||
if ($adminObj = checkingTab($tab))
|
|
||||||
{
|
|
||||||
$isoUser = Context::getContext()->language->iso_code;
|
|
||||||
|
|
||||||
if (Validate::isLoadedObject($adminObj))
|
|
||||||
{
|
|
||||||
$adminObj->ajax = true;
|
|
||||||
if ($adminObj->checkToken())
|
|
||||||
{
|
|
||||||
// the differences with index.php is here
|
|
||||||
|
|
||||||
$adminObj->ajaxPreProcess();
|
|
||||||
$action = Tools::getValue('action');
|
|
||||||
|
|
||||||
// no need to use displayConf() here
|
|
||||||
|
|
||||||
if (!empty($action) AND method_exists($adminObj, 'ajaxProcess'.Tools::toCamelCase($action)) )
|
|
||||||
$adminObj->{'ajaxProcess'.Tools::toCamelCase($action)}();
|
|
||||||
else
|
|
||||||
$adminObj->ajaxProcess();
|
|
||||||
|
|
||||||
// @TODO We should use a displayAjaxError
|
|
||||||
$adminObj->displayErrors();
|
|
||||||
if (!empty($action) AND method_exists($adminObj, 'displayAjax'.Tools::toCamelCase($action)) )
|
|
||||||
$adminObj->{'displayAjax'.$action}();
|
|
||||||
else
|
|
||||||
$adminObj->displayAjax();
|
|
||||||
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
// If this is an XSS attempt, then we should only display a simple, secure page
|
|
||||||
ob_clean();
|
|
||||||
|
|
||||||
// ${1} in the replacement string of the regexp is required, because the token may begin with a number and mix up with it (e.g. $17)
|
|
||||||
$url = preg_replace('/([&?]token=)[^&]*(&.*)?$/', '${1}'.$adminObj->token.'$2', $_SERVER['REQUEST_URI']);
|
|
||||||
if (false === strpos($url, '?token=') AND false === strpos($url, '&token='))
|
|
||||||
$url .= '&token='.$adminObj->token;
|
|
||||||
|
|
||||||
// we can display the correct url
|
|
||||||
// die(Tools::jsonEncode(array(translate('Invalid security token'),$url)));
|
|
||||||
die(Tools::jsonEncode(translate('Invalid security token')));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
|
// For retrocompatibility with "tab" parameter
|
||||||
|
if (!isset($_GET['controller']) && isset($_GET['tab']))
|
||||||
|
$_GET['controller'] = strtolower($_GET['tab']);
|
||||||
|
if (!isset($_POST['controller']) && isset($_POST['tab']))
|
||||||
|
$_POST['controller'] = strtolower($_POST['tab']);
|
||||||
|
if (!isset($_REQUEST['controller']) && isset($_REQUEST['tab']))
|
||||||
|
$_REQUEST['controller'] = strtolower($_REQUEST['tab']);
|
||||||
|
|
||||||
|
Dispatcher::getInstance()->setControllerDirectories(array(_PS_ADMIN_DIR_.'/tabs/', _PS_ADMIN_CONTROLLER_DIR_));
|
||||||
|
Dispatcher::getInstance()->dispatch();
|
||||||
|
|
||||||
|
|||||||
+116
-71
@@ -239,6 +239,7 @@ function checkingTab($tab)
|
|||||||
$controllers = Dispatcher::getControllers(_PS_ADMIN_DIR_.'/tabs/');
|
$controllers = Dispatcher::getControllers(_PS_ADMIN_DIR_.'/tabs/');
|
||||||
|
|
||||||
$tab = trim($tab);
|
$tab = trim($tab);
|
||||||
|
$tab_lowercase = strtolower($tab);
|
||||||
if (!Validate::isTabName($tab))
|
if (!Validate::isTabName($tab))
|
||||||
return false;
|
return false;
|
||||||
$row = Db::getInstance(_PS_USE_SQL_SLAVE_)->getRow('SELECT id_tab, module FROM `'._DB_PREFIX_.'tab` WHERE class_name = \''.pSQL($tab).'\'');
|
$row = Db::getInstance(_PS_USE_SQL_SLAVE_)->getRow('SELECT id_tab, module FROM `'._DB_PREFIX_.'tab` WHERE class_name = \''.pSQL($tab).'\'');
|
||||||
@@ -249,10 +250,10 @@ function checkingTab($tab)
|
|||||||
echo sprintf(Tools::displayError('Tab %s cannot be found.'),$tab);
|
echo sprintf(Tools::displayError('Tab %s cannot be found.'),$tab);
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
if ($row['module'] AND file_exists(_PS_MODULE_DIR_.'/'.$row['module'].'/'.$controllers[$tab].'.php'))
|
if ($row['module'] AND file_exists(_PS_MODULE_DIR_.'/'.$row['module'].'/'.$controllers[$tab_lowercase].'.php'))
|
||||||
include_once(_PS_MODULE_DIR_.'/'.$row['module'].'/'.$controllers[$tab].'.php');
|
include_once(_PS_MODULE_DIR_.'/'.$row['module'].'/'.$controllers[$tab_lowercase].'.php');
|
||||||
elseif (file_exists(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$tab].'.php'))
|
elseif (file_exists(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$tab_lowercase].'.php'))
|
||||||
include_once(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$tab].'.php');
|
include_once(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$tab_lowercase].'.php');
|
||||||
if (!class_exists($tab, false) OR !$row['id_tab'])
|
if (!class_exists($tab, false) OR !$row['id_tab'])
|
||||||
{
|
{
|
||||||
echo sprintf(Tools::displayError('Tab file %s cannot be found.'),$tab);
|
echo sprintf(Tools::displayError('Tab file %s cannot be found.'),$tab);
|
||||||
@@ -427,8 +428,10 @@ function generateShopList()
|
|||||||
*
|
*
|
||||||
* @return void
|
* @return void
|
||||||
*/
|
*/
|
||||||
function runAdminTab()
|
function runAdminTab($ajaxMode = false)
|
||||||
{
|
{
|
||||||
|
$ajaxMode = (bool)$ajaxMode;
|
||||||
|
|
||||||
require_once(_PS_ADMIN_DIR_.'/init.php');
|
require_once(_PS_ADMIN_DIR_.'/init.php');
|
||||||
$cookie = Context::getContext()->cookie;
|
$cookie = Context::getContext()->cookie;
|
||||||
if (empty($tab) and !sizeof($_POST))
|
if (empty($tab) and !sizeof($_POST))
|
||||||
@@ -448,7 +451,8 @@ function runAdminTab()
|
|||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
require_once(_PS_ADMIN_DIR_.'/header.inc.php');
|
if (!$ajaxMode)
|
||||||
|
require_once(_PS_ADMIN_DIR_.'/header.inc.php');
|
||||||
$isoUser = Context::getContext()->language->id;
|
$isoUser = Context::getContext()->language->id;
|
||||||
$tabs = array();
|
$tabs = array();
|
||||||
$tabs = Tab::recursiveTab($adminObj->id, $tabs);
|
$tabs = Tab::recursiveTab($adminObj->id, $tabs);
|
||||||
@@ -466,31 +470,31 @@ function runAdminTab()
|
|||||||
}
|
}
|
||||||
|
|
||||||
// @TODO : a way to desactivate this feature
|
// @TODO : a way to desactivate this feature
|
||||||
echo'<script type="text/javascript">
|
if (!$ajaxMode)
|
||||||
|
echo'<script type="text/javascript">
|
||||||
|
|
||||||
$(function() {
|
$(function() {
|
||||||
$.ajax({
|
$.ajax({
|
||||||
type: \'POST\',
|
type: \'POST\',
|
||||||
url: \'ajax.php\',
|
url: \'ajax.php\',
|
||||||
data: \'helpAccess=1&item='.$item['class_name'].'&isoUser='.$isoUser.'&country='.Context::getContext()->country->iso_code.'&version='._PS_VERSION_.'\',
|
data: \'helpAccess=1&item='.$item['class_name'].'&isoUser='.$isoUser.'&country='.Context::getContext()->country->iso_code.'&version='._PS_VERSION_.'\',
|
||||||
async : true,
|
async : true,
|
||||||
success: function(msg) {
|
success: function(msg) {
|
||||||
$("#help-button").html(msg);
|
$("#help-button").html(msg);
|
||||||
$("#help-button").fadeIn("slow");
|
$("#help-button").fadeIn("slow");
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});</script>';
|
});</script>';
|
||||||
|
|
||||||
echo '<div class="path_bar">
|
if (!$ajaxMode)
|
||||||
|
echo '<div class="path_bar">
|
||||||
<div id="help-button" class="floatr" style="display: none; font-family: Verdana; font-size: 10px; margin-right: 4px; margin-top: 4px;">
|
<div id="help-button" class="floatr" style="display: none; font-family: Verdana; font-size: 10px; margin-right: 4px; margin-top: 4px;">
|
||||||
</div>
|
</div>
|
||||||
<a href="?token='.Tools::getAdminToken($tab.intval(Tab::getIdFromClassName($tab)).(int)Context::getContext()->employee->id).'">'.translate('Back Office').'</a>
|
<a href="?token='.Tools::getAdminToken($tab.intval(Tab::getIdFromClassName($tab)).(int)Context::getContext()->employee->id).'">'.translate('Back Office').'</a>
|
||||||
'.$bread;
|
'.$bread.'</div>';
|
||||||
echo '
|
|
||||||
</div>';
|
|
||||||
|
|
||||||
|
|
||||||
if (Shop::isMultiShopActivated() && Context::shop() != Shop::CONTEXT_ALL)
|
if (!$ajaxMode && Shop::isMultiShopActivated() && Context::shop() != Shop::CONTEXT_ALL)
|
||||||
{
|
{
|
||||||
echo '<div class="multishop_info">';
|
echo '<div class="multishop_info">';
|
||||||
if (Context::shop() == Shop::CONTEXT_GROUP)
|
if (Context::shop() == Shop::CONTEXT_GROUP)
|
||||||
@@ -499,65 +503,106 @@ function runAdminTab()
|
|||||||
printf(translate('You are configuring your store for shop %s'), '<b>'.Context::getContext()->shop->name.'</b>');
|
printf(translate('You are configuring your store for shop %s'), '<b>'.Context::getContext()->shop->name.'</b>');
|
||||||
echo '</div>';
|
echo '</div>';
|
||||||
}
|
}
|
||||||
|
|
||||||
if (Validate::isLoadedObject($adminObj))
|
if (Validate::isLoadedObject($adminObj))
|
||||||
{
|
{
|
||||||
if ($adminObj->checkToken())
|
if ($adminObj->checkToken())
|
||||||
{
|
{
|
||||||
/* Filter memorization */
|
if($ajaxMode)
|
||||||
if (isset($_POST) AND !empty($_POST) AND isset($adminObj->table))
|
{
|
||||||
foreach ($_POST AS $key => $value)
|
// the differences with index.php is here
|
||||||
if (is_array($adminObj->table))
|
$adminObj->ajaxPreProcess();
|
||||||
{
|
$action = Tools::getValue('action');
|
||||||
foreach ($adminObj->table AS $table)
|
// no need to use displayConf() here
|
||||||
if (strncmp($key, $table.'Filter_', 7) === 0 OR strncmp($key, 'submitFilter', 12) === 0)
|
|
||||||
$cookie->$key = !is_array($value) ? $value : serialize($value);
|
|
||||||
}
|
|
||||||
elseif (strncmp($key, $adminObj->table.'Filter_', 7) === 0 OR strncmp($key, 'submitFilter', 12) === 0)
|
|
||||||
$cookie->$key = !is_array($value) ? $value : serialize($value);
|
|
||||||
|
|
||||||
if (isset($_GET) AND !empty($_GET) AND isset($adminObj->table))
|
if (!empty($action) AND method_exists($adminObj, 'ajaxProcess'.Tools::toCamelCase($action)) )
|
||||||
foreach ($_GET AS $key => $value)
|
$adminObj->{'ajaxProcess'.Tools::toCamelCase($action)}();
|
||||||
if (is_array($adminObj->table))
|
else
|
||||||
{
|
$adminObj->ajaxProcess();
|
||||||
foreach ($adminObj->table AS $table)
|
|
||||||
if (strncmp($key, $table.'OrderBy', 7) === 0 OR strncmp($key, $table.'Orderway', 8) === 0)
|
// @TODO We should use a displayAjaxError
|
||||||
$cookie->$key = $value;
|
$adminObj->displayErrors();
|
||||||
}
|
if (!empty($action) AND method_exists($adminObj, 'displayAjax'.Tools::toCamelCase($action)) )
|
||||||
elseif (strncmp($key, $adminObj->table.'OrderBy', 7) === 0 OR strncmp($key, $adminObj->table.'Orderway', 12) === 0)
|
$adminObj->{'displayAjax'.$action}();
|
||||||
$cookie->$key = $value;
|
else
|
||||||
$adminObj->displayConf();
|
$adminObj->displayAjax();
|
||||||
$adminObj->postProcess();
|
|
||||||
$adminObj->displayErrors();
|
|
||||||
$adminObj->display();
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
/* Filter memorization */
|
||||||
|
if (isset($_POST) AND !empty($_POST) AND isset($adminObj->table))
|
||||||
|
foreach ($_POST AS $key => $value)
|
||||||
|
if (is_array($adminObj->table))
|
||||||
|
{
|
||||||
|
foreach ($adminObj->table AS $table)
|
||||||
|
if (strncmp($key, $table.'Filter_', 7) === 0 OR strncmp($key, 'submitFilter', 12) === 0)
|
||||||
|
$cookie->$key = !is_array($value) ? $value : serialize($value);
|
||||||
|
}
|
||||||
|
elseif (strncmp($key, $adminObj->table.'Filter_', 7) === 0 OR strncmp($key, 'submitFilter', 12) === 0)
|
||||||
|
$cookie->$key = !is_array($value) ? $value : serialize($value);
|
||||||
|
|
||||||
|
if (isset($_GET) AND !empty($_GET) AND isset($adminObj->table))
|
||||||
|
foreach ($_GET AS $key => $value)
|
||||||
|
if (is_array($adminObj->table))
|
||||||
|
{
|
||||||
|
foreach ($adminObj->table AS $table)
|
||||||
|
if (strncmp($key, $table.'OrderBy', 7) === 0 OR strncmp($key, $table.'Orderway', 8) === 0)
|
||||||
|
$cookie->$key = $value;
|
||||||
|
}
|
||||||
|
elseif (strncmp($key, $adminObj->table.'OrderBy', 7) === 0 OR strncmp($key, $adminObj->table.'Orderway', 12) === 0)
|
||||||
|
$cookie->$key = $value;
|
||||||
|
$adminObj->displayConf();
|
||||||
|
$adminObj->postProcess();
|
||||||
|
$adminObj->displayErrors();
|
||||||
|
$adminObj->display();
|
||||||
|
include(_PS_ADMIN_DIR_.'/footer.inc.php');
|
||||||
|
}
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
// If this is an XSS attempt, then we should only display a simple, secure page
|
if($ajaxMode)
|
||||||
ob_clean();
|
{
|
||||||
|
// If this is an XSS attempt, then we should only display a simple, secure page
|
||||||
|
ob_clean();
|
||||||
|
|
||||||
// ${1} in the replacement string of the regexp is required, because the token may begin with a number and mix up with it (e.g. $17)
|
// ${1} in the replacement string of the regexp is required, because the token may begin with a number and mix up with it (e.g. $17)
|
||||||
$url = preg_replace('/([&?]token=)[^&]*(&.*)?$/', '${1}'.$adminObj->token.'$2', $_SERVER['REQUEST_URI']);
|
$url = preg_replace('/([&?]token=)[^&]*(&.*)?$/', '${1}'.$adminObj->token.'$2', $_SERVER['REQUEST_URI']);
|
||||||
if (false === strpos($url, '?token=') AND false === strpos($url, '&token='))
|
if (false === strpos($url, '?token=') AND false === strpos($url, '&token='))
|
||||||
$url .= '&token='.$adminObj->token;
|
$url .= '&token='.$adminObj->token;
|
||||||
|
|
||||||
$message = translate('Invalid security token');
|
|
||||||
echo '<html><head><title>'.$message.'</title></head><body style="font-family:Arial,Verdana,Helvetica,sans-serif;background-color:#EC8686">
|
// we can display the correct url
|
||||||
<div style="background-color:#FAE2E3;border:1px solid #000000;color:#383838;font-weight:700;line-height:20px;margin:0 0 10px;padding:10px 15px;width:500px">
|
// die(Tools::jsonEncode(array(translate('Invalid security token'),$url)));
|
||||||
<img src="../img/admin/error2.png" style="margin:-4px 5px 0 0;vertical-align:middle">
|
die(Tools::jsonEncode(translate('Invalid security token')));
|
||||||
'.$message.'
|
}
|
||||||
</div>';
|
else
|
||||||
echo '<a href="'.htmlentities($url).'" method="get" style="float:left;margin:10px">
|
{
|
||||||
<input type="button" value="'.Tools::htmlentitiesUTF8(translate('I understand the risks and I really want to display this page')).'" style="height:30px;margin-top:5px" />
|
// If this is an XSS attempt, then we should only display a simple, secure page
|
||||||
</a>
|
ob_clean();
|
||||||
<a href="index.php" method="get" style="float:left;margin:10px">
|
|
||||||
<input type="button" value="'.Tools::htmlentitiesUTF8(translate('Take me out of here!')).'" style="height:40px" />
|
// ${1} in the replacement string of the regexp is required, because the token may begin with a number and mix up with it (e.g. $17)
|
||||||
</a>
|
$url = preg_replace('/([&?]token=)[^&]*(&.*)?$/', '${1}'.$adminObj->token.'$2', $_SERVER['REQUEST_URI']);
|
||||||
</body></html>';
|
if (false === strpos($url, '?token=') AND false === strpos($url, '&token='))
|
||||||
die;
|
$url .= '&token='.$adminObj->token;
|
||||||
|
|
||||||
|
$message = translate('Invalid security token');
|
||||||
|
echo '<html><head><title>'.$message.'</title></head><body style="font-family:Arial,Verdana,Helvetica,sans-serif;background-color:#EC8686">
|
||||||
|
<div style="background-color:#FAE2E3;border:1px solid #000000;color:#383838;font-weight:700;line-height:20px;margin:0 0 10px;padding:10px 15px;width:500px">
|
||||||
|
<img src="../img/admin/error2.png" style="margin:-4px 5px 0 0;vertical-align:middle">
|
||||||
|
'.$message.'
|
||||||
|
</div>';
|
||||||
|
echo '<a href="'.htmlentities($url).'" method="get" style="float:left;margin:10px">
|
||||||
|
<input type="button" value="'.Tools::htmlentitiesUTF8(translate('I understand the risks and I really want to display this page')).'" style="height:30px;margin-top:5px" />
|
||||||
|
</a>
|
||||||
|
<a href="index.php" method="get" style="float:left;margin:10px">
|
||||||
|
<input type="button" value="'.Tools::htmlentitiesUTF8(translate('Take me out of here!')).'" style="height:40px" />
|
||||||
|
</a>
|
||||||
|
</body></html>';
|
||||||
|
die;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
include(_PS_ADMIN_DIR_.'/footer.inc.php');
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -236,14 +236,15 @@ class DispatcherCore
|
|||||||
$this->getController();
|
$this->getController();
|
||||||
$controllers = Dispatcher::getControllers($this->controller_directories);
|
$controllers = Dispatcher::getControllers($this->controller_directories);
|
||||||
|
|
||||||
if (!$this->controller)
|
if (!$this->controller || $this->controller == 'index')
|
||||||
$this->controller = (defined('_PS_ADMIN_DIR_')) ? 'adminhome' : 'index';
|
$this->controller = (defined('_PS_ADMIN_DIR_')) ? 'adminhome' : 'index';
|
||||||
|
|
||||||
// For retrocompatibility with admin/tabs/ old system
|
// For retrocompatibility with admin/tabs/ old system
|
||||||
if (isset($controllers[$this->controller]) && defined('_PS_ADMIN_DIR_') && file_exists(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$this->controller].'.php'))
|
if (isset($controllers[$this->controller]) && defined('_PS_ADMIN_DIR_') && file_exists(_PS_ADMIN_DIR_.'/tabs/'.$controllers[$this->controller].'.php'))
|
||||||
{
|
{
|
||||||
require_once(_PS_ADMIN_DIR_.'/functions.php');
|
require_once(_PS_ADMIN_DIR_.'/functions.php');
|
||||||
runAdminTab();
|
$ajaxMode = !empty($_REQUEST['ajaxMode']);
|
||||||
|
runAdminTab($ajaxMode);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
else if (!isset($controllers[$this->controller]))
|
else if (!isset($controllers[$this->controller]))
|
||||||
|
|||||||
Reference in New Issue
Block a user