12 ]); if ($r === false) { throw new \RuntimeException("Could not hash password"); } return [ $version, $r ]; } function test_password(string $db_hash, string|int $version, string $input_password): bool { $version = (int)$version; if ($version < 2) { $ok = \hash_equals($db_hash, \crypt($input_password, $db_hash)); } else { $pre_hash = \hash('tiger160,3', $input_password, false); $ok = \password_verify($pre_hash, $db_hash); } return $ok; } function login(string $username, string $password): array|false { global $mod; $query = prepare("SELECT `id`, `type`, `boards`, `password`, `version` FROM ``mods`` WHERE BINARY `username` = :username"); $query->bindValue(':username', $username); $query->execute(); if ($user = $query->fetch(PDO::FETCH_ASSOC)) { $ok = test_password($user['password'], $user['version'], $password); if ($ok) { if ((int)$user['version'] < 2) { // It's time to upgrade the password hashing method! list ($user['version'], $user['password']) = crypt_password($password); $query = prepare("UPDATE ``mods`` SET `password` = :password, `version` = :version WHERE `id` = :id"); $query->bindValue(':password', $user['password']); $query->bindValue(':version', $user['version']); $query->bindValue(':id', $user['id']); $query->execute(); } return $mod = [ 'id' => $user['id'], 'type' => $user['type'], 'username' => $username, 'hash' => mkhash($username, $user['password']), 'boards' => explode(',', $user['boards']) ]; } } return false; } function setCookies(): void { global $mod, $config; if (!$mod) { error('setCookies() was called for a non-moderator!'); } $is_https = Net\is_connection_https(); setcookie($config['cookies']['mod'], $mod['username'] . // username ':' . $mod['hash'][0] . // password ':' . $mod['hash'][1], // salt time() + $config['cookies']['expire'], $config['cookies']['jail'] ? $config['cookies']['path'] : '/', null, $is_https, $config['cookies']['httponly']); } function destroyCookies(): void { global $config; $is_https = Net\is_connection_https(); // Delete the cookies setcookie($config['cookies']['mod'], 'deleted', time() - $config['cookies']['expire'], $config['cookies']['jail']?$config['cookies']['path'] : '/', null, $is_https, true); } function modLog(string $action, ?string $_board = null): void { global $mod, $board, $config; $query = prepare("INSERT INTO ``modlogs`` VALUES (:id, :ip, :board, :time, :text)"); $query->bindValue(':id', (isset($mod['id']) ? $mod['id'] : -1), PDO::PARAM_INT); $query->bindValue(':ip', $_SERVER['REMOTE_ADDR']); $query->bindValue(':time', time(), PDO::PARAM_INT); $query->bindValue(':text', $action); if (isset($_board)) $query->bindValue(':board', $_board); elseif (isset($board)) $query->bindValue(':board', $board['uri']); else $query->bindValue(':board', null, PDO::PARAM_NULL); $query->execute() or error(db_error($query)); if ($config['syslog']) { _syslog(LOG_INFO, '[mod/' . $mod['username'] . ']: ' . $action); } } function create_pm_header(): mixed { global $mod, $config; if ($config['cache']['enabled'] && ($header = cache::get('pm_unread_' . $mod['id'])) != false) { if ($header === true) { return false; } return $header; } $query = prepare("SELECT `id` FROM ``pms`` WHERE `to` = :id AND `unread` = 1"); $query->bindValue(':id', $mod['id'], PDO::PARAM_INT); $query->execute() or error(db_error($query)); if ($pm = $query->fetch(PDO::FETCH_ASSOC)) { $header = [ 'id' => $pm['id'], 'waiting' => $query->rowCount() - 1 ]; } else { $header = true; } if ($config['cache']['enabled']) { cache::set('pm_unread_' . $mod['id'], $header); } if ($header === true) { return false; } return $header; } function make_secure_link_token(string $uri): string { global $mod, $config; return substr(sha1($config['cookies']['salt'] . '-' . $uri . '-' . $mod['id']), 0, 8); } function check_login(Context $ctx, bool $prompt = false): void { global $config, $mod; // Validate session if (isset($_COOKIE[$config['cookies']['mod']])) { // Should be username:hash:salt $cookie = explode(':', $_COOKIE[$config['cookies']['mod']]); if (count($cookie) != 3) { // Malformed cookies destroyCookies(); if ($prompt) { mod_login($ctx); } exit; } $query = prepare("SELECT `id`, `type`, `boards`, `password` FROM ``mods`` WHERE `username` = :username"); $query->bindValue(':username', $cookie[0]); $query->execute() or error(db_error($query)); $user = $query->fetch(PDO::FETCH_ASSOC); // validate password hash if ($cookie[1] !== mkhash($cookie[0], $user['password'], $cookie[2])) { // Malformed cookies destroyCookies(); if ($prompt) { mod_login($ctx); } exit; } $mod = array( 'id' => (int)$user['id'], 'type' => (int)$user['type'], 'username' => $cookie[0], 'boards' => explode(',', $user['boards']) ); } }