The ~24 legit Cadline customizations on the Joomla core (audit sec.16.1): reCAPTCHA anti-spam (registration/reset/remind/login flow, captcha rule), content view tweaks, mod_login template, phpversioncheck. build-baseline.sh overlays these live versions onto the official-package core so the baseline matches live for the legit mods, while the 3 trojanized core files stay clean. NOTE: com_users/controllers/registration.php carries a hardcoded reCAPTCHA secret (redacted; rotate on cleanup) — see malware-iocs.md. Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8
945 lines
27 KiB
PHP
945 lines
27 KiB
PHP
<?php
|
|
|
|
/**
|
|
* @package Joomla.Site
|
|
* @subpackage com_users
|
|
*
|
|
* @copyright Copyright (C) 2005 - 2018 Open Source Matters, Inc. All rights reserved.
|
|
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
|
*/
|
|
|
|
defined('_JEXEC') or die;
|
|
|
|
/**
|
|
* Registration model class for Users.
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
class UsersModelRegistration extends JModelForm
|
|
{
|
|
/**
|
|
* @var object The user registration data.
|
|
* @since 1.6
|
|
*/
|
|
protected $data;
|
|
|
|
/**
|
|
* Constructor
|
|
*
|
|
* @param array $config An array of configuration options (name, state, dbo, table_path, ignore_request).
|
|
*
|
|
* @since 3.6
|
|
*
|
|
* @throws Exception
|
|
*/
|
|
public function __construct($config = array())
|
|
{
|
|
$config = array_merge(
|
|
array(
|
|
'events_map' => array('validate' => 'user')
|
|
),
|
|
$config
|
|
);
|
|
|
|
parent::__construct($config);
|
|
}
|
|
|
|
/**
|
|
* Method to activate a user account.
|
|
*
|
|
* @param string $token The activation token.
|
|
*
|
|
* @return mixed False on failure, user object on success.
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
public function activate($token)
|
|
{
|
|
$config = JFactory::getConfig();
|
|
$userParams = JComponentHelper::getParams('com_users');
|
|
$db = $this->getDbo();
|
|
|
|
// Get the user id based on the token.
|
|
$query = $db->getQuery(true);
|
|
$query->select($db->quoteName('id'))
|
|
->from($db->quoteName('#__users'))
|
|
->where($db->quoteName('activation') . ' = ' . $db->quote($token))
|
|
->where($db->quoteName('block') . ' = ' . 1)
|
|
->where($db->quoteName('lastvisitDate') . ' = ' . $db->quote($db->getNullDate()));
|
|
$db->setQuery($query);
|
|
|
|
try {
|
|
$userId = (int) $db->loadResult();
|
|
} catch (RuntimeException $e) {
|
|
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
|
|
|
return false;
|
|
}
|
|
|
|
// Check for a valid user id.
|
|
if (!$userId) {
|
|
$this->setError(JText::_('COM_USERS_ACTIVATION_TOKEN_NOT_FOUND'));
|
|
|
|
return false;
|
|
}
|
|
|
|
// Load the users plugin group.
|
|
JPluginHelper::importPlugin('user');
|
|
|
|
// Activate the user.
|
|
$user = JFactory::getUser($userId);
|
|
|
|
// Admin activation is on and user is verifying their email
|
|
if (($userParams->get('useractivation') == 2) && !$user->getParam('activate', 0)) {
|
|
$uri = JUri::getInstance();
|
|
|
|
// Compile the admin notification mail values.
|
|
$data = $user->getProperties();
|
|
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
|
|
$user->set('activation', $data['activation']);
|
|
$data['siteurl'] = JUri::base();
|
|
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
|
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
|
|
|
// Remove administrator/ from activate URL in case this method is called from admin
|
|
if (JFactory::getApplication()->isClient('administrator')) {
|
|
$adminPos = strrpos($data['activate'], 'administrator/');
|
|
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
|
}
|
|
|
|
$data['fromname'] = $config->get('fromname');
|
|
$data['mailfrom'] = $config->get('mailfrom');
|
|
$data['sitename'] = $config->get('sitename');
|
|
$user->setParam('activate', 1);
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_SUBJECT',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACTIVATE_WITH_ADMIN_ACTIVATION_BODY',
|
|
$data['sitename'],
|
|
$data['name'],
|
|
$data['email'],
|
|
$data['username'],
|
|
$data['activate']
|
|
);
|
|
|
|
// Get all admin users
|
|
$query->clear()
|
|
->select($db->quoteName(array('name', 'email', 'sendEmail', 'id')))
|
|
->from($db->quoteName('#__users'))
|
|
->where($db->quoteName('sendEmail') . ' = 1')
|
|
->where($db->quoteName('block') . ' = 0');
|
|
|
|
$db->setQuery($query);
|
|
|
|
try {
|
|
$rows = $db->loadObjectList();
|
|
} catch (RuntimeException $e) {
|
|
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
|
|
|
return false;
|
|
}
|
|
|
|
// Send mail to all users with users creating permissions and receiving system emails
|
|
foreach ($rows as $row) {
|
|
$usercreator = JFactory::getUser($row->id);
|
|
|
|
if ($usercreator->authorise('core.create', 'com_users')) {
|
|
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBody);
|
|
|
|
// Check for an error.
|
|
if ($return !== true) {
|
|
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
|
|
|
return false;
|
|
}
|
|
}
|
|
}
|
|
}
|
|
// Admin activation is on and admin is activating the account
|
|
elseif (($userParams->get('useractivation') == 2) && $user->getParam('activate', 0)) {
|
|
$user->set('activation', '');
|
|
$user->set('block', '0');
|
|
|
|
// Compile the user activated notification mail values.
|
|
$data = $user->getProperties();
|
|
$user->setParam('activate', 0);
|
|
$data['fromname'] = $config->get('fromname');
|
|
$data['mailfrom'] = $config->get('mailfrom');
|
|
$data['sitename'] = $config->get('sitename');
|
|
$data['siteurl'] = JUri::base();
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_SUBJECT',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACTIVATED_BY_ADMIN_ACTIVATION_BODY',
|
|
$data['name'],
|
|
$data['siteurl'],
|
|
$data['username']
|
|
);
|
|
|
|
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
|
|
|
|
// Check for an error.
|
|
if ($return !== true) {
|
|
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
|
|
|
return false;
|
|
}
|
|
} else {
|
|
$user->set('activation', '');
|
|
$user->set('block', '0');
|
|
|
|
$query = $db->getQuery(true);
|
|
$query->select('a.nUserID')->from('cl_hlusers.u_emails AS a')->where('a.email = "' . $user->email . '"');
|
|
$db->setQuery($query);
|
|
$existingUser = $db->loadObjectList();
|
|
|
|
$query = $db->getQuery(true);
|
|
$query->select('j.phone, j.profession, j.old_db, j.country, j.zip, j.city, j.address')->from('jml_jsn_users AS j')->where('j.id = "' . $userId . '"');
|
|
$db->setQuery($query);
|
|
$storeData = $db->loadObject();
|
|
|
|
if (count($existingUser) > 0) {
|
|
foreach ($existingUser as $users) {
|
|
$nUserID = $users->nUserID;
|
|
}
|
|
|
|
$query = $db->getQuery(true);
|
|
$query->select('u.old_db')->from('cl_hlusers.users AS u')->where('u.nUserID = "' . $nUserID . '"');
|
|
$db->setQuery($query);
|
|
$userDb = $db->loadObject();
|
|
|
|
if ($userDb->old_db == 'clusers') {
|
|
$old_db = "clusers";
|
|
$info = "Weben regisztrált";
|
|
$topic = 362;
|
|
} else {
|
|
$old_db = "clusers_eng";
|
|
$info = "Web registration";
|
|
$topic = 219;
|
|
}
|
|
} else {
|
|
$query = $db->getQuery(false);
|
|
if ($storeData->old_db == 'hu') {
|
|
$old_db = "clusers";
|
|
$info = "Weben regisztrált";
|
|
$topic = 362;
|
|
} else {
|
|
$old_db = "clusers_eng";
|
|
$info = "Web registration";
|
|
$topic = 219;
|
|
}
|
|
|
|
$query = 'INSERT INTO cl_hlusers.users(strName, strTel, nUserProf, nManagerID, old_db, strEmail, dateInsert, nUserType, strStreet, strCity, strZip)
|
|
VALUES("' . $user->name . '", "' . $storeData->phone . '", "' . $storeData->profession . '", 36, "' . $old_db . '", "' . $user->email . '",
|
|
' . time() . ', 0, "' . $storeData->address . '", "' . $storeData->city . '", "' . $storeData->zip . '")';
|
|
|
|
$db->setQuery($query);
|
|
$db->execute();
|
|
$nUserID = $db->insertid();
|
|
|
|
if ($storeData->country == null)
|
|
$storeData->country = 0;
|
|
|
|
$query = $db->getQuery(true);
|
|
$query->update("cl_hlusers.users");
|
|
$query->set('users.nCtrID = ' . $storeData->country);
|
|
$query->where('users.nUserID = ' . $nUserID);
|
|
$db->setQuery($query);
|
|
$db->execute();
|
|
|
|
$query = "INSERT INTO cl_hlusers.u_emails(email, nUserID)
|
|
VALUES('" . $user->email . "', '" . $nUserID . "')";
|
|
$db->setQuery($query);
|
|
$db->execute();
|
|
|
|
$query = $db->getQuery(true);
|
|
$query->update("cl_hlusers.u_emails");
|
|
$query->set('u_emails.default = 1');
|
|
$query->set('u_emails.newsletter = 1');
|
|
$query->where('nUserID = ' . $nUserID);
|
|
$db->setQuery($query);
|
|
$db->execute();
|
|
}
|
|
|
|
$query = $db->getQuery(false);
|
|
$query = "INSERT INTO cl_hlusers.u_history(nUserID, nTopicID, dateEvent, strPlace, strInfo, nManagerID, insertDate)
|
|
VALUES(" . $nUserID . ", " . $topic . ", '" . date("Y-m-d", time()) . "', 'web', '" . $info . "', 36, '" . date("Y-m-d H:i:s", time()) . "')";
|
|
$db->setQuery($query);
|
|
$db->execute();
|
|
|
|
|
|
$user->set('username', $user->email);
|
|
$user->set('nUserID', $nUserID);
|
|
}
|
|
|
|
// Store the user object.
|
|
if (!$user->save()) {
|
|
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_ACTIVATION_SAVE_FAILED', $user->getError()));
|
|
|
|
return false;
|
|
}
|
|
|
|
return $user;
|
|
}
|
|
|
|
/**
|
|
* Method to get the registration form data.
|
|
*
|
|
* The base form data is loaded and then an event is fired
|
|
* for users plugins to extend the data.
|
|
*
|
|
* @return mixed Data object on success, false on failure.
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
public function getData()
|
|
{
|
|
if ($this->data === null) {
|
|
$this->data = new stdClass;
|
|
$app = JFactory::getApplication();
|
|
$params = JComponentHelper::getParams('com_users');
|
|
|
|
// Override the base user data with any data in the session.
|
|
$temp = (array) $app->getUserState('com_users.registration.data', array());
|
|
|
|
// Don't load the data in this getForm call, or we'll call ourself
|
|
$form = $this->getForm(array(), false);
|
|
|
|
foreach ($temp as $k => $v) {
|
|
// Here we could have a grouped field, let's check it
|
|
if (is_array($v)) {
|
|
$this->data->$k = new stdClass;
|
|
|
|
foreach ($v as $key => $val) {
|
|
if ($form->getField($key, $k) !== false) {
|
|
$this->data->$k->$key = $val;
|
|
}
|
|
}
|
|
}
|
|
// Only merge the field if it exists in the form.
|
|
elseif ($form->getField($k) !== false) {
|
|
$this->data->$k = $v;
|
|
}
|
|
}
|
|
|
|
// Get the groups the user should be added to after registration.
|
|
$this->data->groups = array();
|
|
|
|
// Get the default new user group, Registered if not specified.
|
|
$system = $params->get('new_usertype', 2);
|
|
|
|
$this->data->groups[] = $system;
|
|
|
|
// Unset the passwords.
|
|
unset($this->data->password1, $this->data->password2);
|
|
|
|
// Get the dispatcher and load the users plugins.
|
|
$dispatcher = JEventDispatcher::getInstance();
|
|
JPluginHelper::importPlugin('user');
|
|
|
|
// Trigger the data preparation event.
|
|
$results = $dispatcher->trigger('onContentPrepareData', array('com_users.registration', $this->data));
|
|
|
|
// Check for errors encountered while preparing the data.
|
|
if (count($results) && in_array(false, $results, true)) {
|
|
$this->setError($dispatcher->getError());
|
|
$this->data = false;
|
|
}
|
|
}
|
|
|
|
return $this->data;
|
|
}
|
|
|
|
/**
|
|
* Method to get the registration form.
|
|
*
|
|
* The base form is loaded from XML and then an event is fired
|
|
* for users plugins to extend the form with extra fields.
|
|
*
|
|
* @param array $data An optional array of data for the form to interogate.
|
|
* @param boolean $loadData True if the form is to load its own data (default case), false if not.
|
|
*
|
|
* @return JForm A JForm object on success, false on failure
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
public function getForm($data = array(), $loadData = true)
|
|
{
|
|
// Get the form.
|
|
$form = $this->loadForm('com_users.registration', 'registration', array('control' => 'jform', 'load_data' => $loadData));
|
|
|
|
if (empty($form)) {
|
|
return false;
|
|
}
|
|
|
|
// When multilanguage is set, a user's default site language should also be a Content Language
|
|
if (JLanguageMultilang::isEnabled()) {
|
|
$form->setFieldAttribute('language', 'type', 'frontend_language', 'params');
|
|
}
|
|
|
|
return $form;
|
|
}
|
|
|
|
/**
|
|
* Method to get the data that should be injected in the form.
|
|
*
|
|
* @return mixed The data for the form.
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
protected function loadFormData()
|
|
{
|
|
$data = $this->getData();
|
|
|
|
if (JLanguageMultilang::isEnabled() && empty($data->language)) {
|
|
$data->language = JFactory::getLanguage()->getTag();
|
|
}
|
|
|
|
$this->preprocessData('com_users.registration', $data);
|
|
|
|
return $data;
|
|
}
|
|
|
|
/**
|
|
* Override preprocessForm to load the user plugin group instead of content.
|
|
*
|
|
* @param JForm $form A JForm object.
|
|
* @param mixed $data The data expected for the form.
|
|
* @param string $group The name of the plugin group to import (defaults to "content").
|
|
*
|
|
* @return void
|
|
*
|
|
* @since 1.6
|
|
* @throws Exception if there is an error in the form event.
|
|
*/
|
|
protected function preprocessForm(JForm $form, $data, $group = 'user')
|
|
{
|
|
$userParams = JComponentHelper::getParams('com_users');
|
|
|
|
// Add the choice for site language at registration time
|
|
if ($userParams->get('site_language') == 1 && $userParams->get('frontend_userparams') == 1) {
|
|
$form->loadFile('sitelang', false);
|
|
}
|
|
|
|
parent::preprocessForm($form, $data, $group);
|
|
}
|
|
|
|
/**
|
|
* Method to auto-populate the model state.
|
|
*
|
|
* Note. Calling getState in this method will result in recursion.
|
|
*
|
|
* @return void
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
protected function populateState()
|
|
{
|
|
// Get the application object.
|
|
$app = JFactory::getApplication();
|
|
$params = $app->getParams('com_users');
|
|
|
|
// Load the parameters.
|
|
$this->setState('params', $params);
|
|
}
|
|
|
|
/**
|
|
* Method to save the form data.
|
|
*
|
|
* @param array $temp The form data.
|
|
*
|
|
* @return mixed The user id on success, false on failure.
|
|
*
|
|
* @since 1.6
|
|
*/
|
|
public function register($temp)
|
|
{
|
|
$params = JComponentHelper::getParams('com_users');
|
|
|
|
// Initialise the table with JUser.
|
|
$user = new JUser;
|
|
$data = (array) $this->getData();
|
|
|
|
// Merge in the registration data.
|
|
foreach ($temp as $k => $v) {
|
|
$data[$k] = $v;
|
|
}
|
|
|
|
// Prepare the data for the user object.
|
|
$data['email'] = JStringPunycode::emailToPunycode($data['email1']);
|
|
$data['name'] = $data['firstname']; // N.M. Az új registration form miatt kellett. Az emailben kiküldött név nem úgy jelent meg, ahogy kéne
|
|
$data['name'] .= ' ';
|
|
$data['name'] .= $data['lastname'];
|
|
$data['password'] = $data['password1'];
|
|
$useractivation = $params->get('useractivation');
|
|
$sendpassword = $params->get('sendpassword', 1);
|
|
|
|
// Check if the user needs to activate their account.
|
|
if (($useractivation == 1) || ($useractivation == 2)) {
|
|
$data['activation'] = JApplicationHelper::getHash(JUserHelper::genRandomPassword());
|
|
$data['block'] = 1;
|
|
}
|
|
|
|
// Bind the data.
|
|
if (!$user->bind($data)) {
|
|
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_BIND_FAILED', $user->getError()));
|
|
|
|
return false;
|
|
}
|
|
|
|
// Load the users plugin group.
|
|
JPluginHelper::importPlugin('user');
|
|
|
|
// Store the data.
|
|
if (!$user->save()) {
|
|
$this->setError(JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError()));
|
|
|
|
return false;
|
|
}
|
|
|
|
$config = JFactory::getConfig();
|
|
$db = $this->getDbo();
|
|
$query = $db->getQuery(true);
|
|
|
|
// Compile the notification mail values.
|
|
$data = $user->getProperties();
|
|
$data['fromname'] = $config->get('fromname');
|
|
$data['mailfrom'] = $config->get('mailfrom');
|
|
$data['sitename'] = $config->get('sitename');
|
|
$data['siteurl'] = JUri::root();
|
|
|
|
// Handle account activation/confirmation emails.
|
|
if ($useractivation == 2) {
|
|
// Set the link to confirm the user email.
|
|
$uri = JUri::getInstance();
|
|
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
|
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
|
|
|
// Remove administrator/ from activate URL in case this method is called from admin
|
|
if (JFactory::getApplication()->isClient('administrator')) {
|
|
$adminPos = strrpos($data['activate'], 'administrator/');
|
|
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
|
}
|
|
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
if ($sendpassword) {
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['activate'],
|
|
$data['siteurl'],
|
|
$data['username'],
|
|
$data['password_clear']
|
|
);
|
|
} else {
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_WITH_ADMIN_ACTIVATION_BODY_NOPW',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['activate'],
|
|
$data['siteurl'],
|
|
$data['username']
|
|
);
|
|
}
|
|
} elseif ($useractivation == 1) {
|
|
// Set the link to activate the user account.
|
|
$uri = JUri::getInstance();
|
|
$base = $uri->toString(array('scheme', 'user', 'pass', 'host', 'port'));
|
|
$data['activate'] = $base . JRoute::_('index.php?option=com_users&task=registration.activate&token=' . $data['activation'], false);
|
|
|
|
// Remove administrator/ from activate URL in case this method is called from admin
|
|
if (JFactory::getApplication()->isClient('administrator')) {
|
|
$adminPos = strrpos($data['activate'], 'administrator/');
|
|
$data['activate'] = substr_replace($data['activate'], '', $adminPos, 14);
|
|
}
|
|
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
if ($sendpassword) {
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['activate'],
|
|
$data['siteurl'],
|
|
$data['username'],
|
|
$data['password_clear']
|
|
);
|
|
} else {
|
|
// $data['username'] valtozot ki kell cserelni az emailre, mert false adatot kuldunk ki
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_WITH_ACTIVATION_BODY_NOPW',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['activate'],
|
|
$data['siteurl'],
|
|
$data['username']
|
|
);
|
|
}
|
|
} else {
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
if ($sendpassword) {
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_BODY',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['siteurl'],
|
|
$data['username'],
|
|
$data['password_clear']
|
|
);
|
|
} else {
|
|
$emailBody = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_BODY_NOPW',
|
|
$data['name'],
|
|
$data['sitename'],
|
|
$data['siteurl']
|
|
);
|
|
}
|
|
}
|
|
|
|
// Send the registration email.
|
|
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $data['email'], $emailSubject, $emailBody);
|
|
|
|
// Send Notification mail to administrators
|
|
if (($params->get('useractivation') < 2) && ($params->get('mail_to_admin') == 1)) {
|
|
$emailSubject = JText::sprintf(
|
|
'COM_USERS_EMAIL_ACCOUNT_DETAILS',
|
|
$data['name'],
|
|
$data['sitename']
|
|
);
|
|
|
|
$emailBodyAdmin = JText::sprintf(
|
|
'COM_USERS_EMAIL_REGISTERED_NOTIFICATION_TO_ADMIN_BODY',
|
|
$data['name'],
|
|
$data['username'],
|
|
$data['siteurl']
|
|
);
|
|
|
|
// Get all admin users
|
|
$query->clear()
|
|
->select($db->quoteName(array('name', 'email', 'sendEmail')))
|
|
->from($db->quoteName('#__users'))
|
|
->where($db->quoteName('sendEmail') . ' = 1')
|
|
->where($db->quoteName('block') . ' = 0');
|
|
|
|
$db->setQuery($query);
|
|
|
|
try {
|
|
$rows = $db->loadObjectList();
|
|
} catch (RuntimeException $e) {
|
|
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
|
|
|
return false;
|
|
}
|
|
|
|
// Send mail to all superadministrators id
|
|
foreach ($rows as $row) {
|
|
$return = JFactory::getMailer()->sendMail($data['mailfrom'], $data['fromname'], $row->email, $emailSubject, $emailBodyAdmin);
|
|
|
|
// Check for an error.
|
|
if ($return !== true) {
|
|
$this->setError(JText::_('COM_USERS_REGISTRATION_ACTIVATION_NOTIFY_SEND_MAIL_FAILED'));
|
|
|
|
return false;
|
|
}
|
|
}
|
|
}
|
|
|
|
// Check for an error.
|
|
if ($return !== true) {
|
|
$this->setError(JText::_('COM_USERS_REGISTRATION_SEND_MAIL_FAILED'));
|
|
|
|
// Send a system message to administrators receiving system mails
|
|
$db = $this->getDbo();
|
|
$query->clear()
|
|
->select($db->quoteName('id'))
|
|
->from($db->quoteName('#__users'))
|
|
->where($db->quoteName('block') . ' = ' . (int) 0)
|
|
->where($db->quoteName('sendEmail') . ' = ' . (int) 1);
|
|
$db->setQuery($query);
|
|
|
|
try {
|
|
$userids = $db->loadColumn();
|
|
} catch (RuntimeException $e) {
|
|
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
|
|
|
return false;
|
|
}
|
|
|
|
if (count($userids) > 0) {
|
|
$jdate = new JDate;
|
|
|
|
// Build the query to add the messages
|
|
foreach ($userids as $userid) {
|
|
$values = array(
|
|
$db->quote($userid),
|
|
$db->quote($userid),
|
|
$db->quote($jdate->toSql()),
|
|
$db->quote(JText::_('COM_USERS_MAIL_SEND_FAILURE_SUBJECT')),
|
|
$db->quote(JText::sprintf('COM_USERS_MAIL_SEND_FAILURE_BODY', $return, $data['username']))
|
|
);
|
|
$query->clear()
|
|
->insert($db->quoteName('#__messages'))
|
|
->columns($db->quoteName(array('user_id_from', 'user_id_to', 'date_time', 'subject', 'message')))
|
|
->values(implode(',', $values));
|
|
$db->setQuery($query);
|
|
|
|
try {
|
|
$db->execute();
|
|
} catch (RuntimeException $e) {
|
|
$this->setError(JText::sprintf('COM_USERS_DATABASE_ERROR', $e->getMessage()), 500);
|
|
|
|
return false;
|
|
}
|
|
}
|
|
}
|
|
|
|
return false;
|
|
}
|
|
|
|
if ($useractivation == 1) {
|
|
return 'useractivate';
|
|
} elseif ($useractivation == 2) {
|
|
return 'adminactivate';
|
|
} else {
|
|
return $user->id;
|
|
}
|
|
}
|
|
|
|
private function checkCaptcha($response)
|
|
{
|
|
$secret = '';
|
|
|
|
if ($_SERVER['SERVER_NAME'] == 'www.archline.hu')
|
|
$secret = '6Lc8nh8TAAAAALeRGLDbjsr7Rh1qpQJkYXYO-P50';
|
|
else
|
|
$secret = '6LeqnB8TAAAAAJTatP1dt8npqwDfJLz4_i9-rbNg';
|
|
|
|
$post_data = http_build_query(
|
|
array(
|
|
'secret' => $secret,
|
|
'response' => $response,
|
|
'remoteip' => $_SERVER['REMOTE_ADDR']
|
|
)
|
|
);
|
|
|
|
$opts = array(
|
|
'http' =>
|
|
array(
|
|
'method' => 'POST',
|
|
'header' => 'Content-type: application/x-www-form-urlencoded',
|
|
'content' => $post_data
|
|
)
|
|
);
|
|
|
|
$context = stream_context_create($opts);
|
|
|
|
$response = file_get_contents('https://www.google.com/recaptcha/api/siteverify', false, $context);
|
|
$result = json_decode($response);
|
|
|
|
return $result->success;
|
|
}
|
|
|
|
private function phoneCorrect(&$phone)
|
|
{
|
|
$phone = str_replace('-', '', $phone);
|
|
$phone = str_replace(' ', '', $phone);
|
|
$phone = str_replace('+', '', $phone);
|
|
$phone = str_replace('/', '', $phone);
|
|
$phone = str_replace('.', '', $phone);
|
|
$phone = str_replace(' ', '', $phone);
|
|
|
|
return $phone;
|
|
}
|
|
|
|
public function registerWithARCHLine($temp, &$message)
|
|
{
|
|
if (!class_exists('crm_hardlock')) require_once(JPATH_BASE . "/common_cadline_libraries/crm_hardlock.class.php");
|
|
|
|
$resource = new Resource($temp['country']);
|
|
|
|
$captchaResult = $this->checkCaptcha($temp['captcha']);
|
|
|
|
$datetime = new \DateTime('');
|
|
$date = $datetime->format('c');
|
|
$ip = $_SERVER['REMOTE_ADDR'];
|
|
$browser = $_SERVER['HTTP_USER_AGENT'];
|
|
|
|
if (!$captchaResult) {
|
|
$message = $resource->getDlgString('10947');
|
|
|
|
$log = "{$date} capchaID: 'archline-registration-v2' verdict: 'FAILURE' IP: '{$ip}' Browser: '{$browser}'" . PHP_EOL;
|
|
error_log($log, 3, $_SERVER['DOCUMENT_ROOT'] . '/logs/captchaErrorLog.log');
|
|
return false;
|
|
}
|
|
|
|
$log = "{$date} capchaID: 'archline-registration-v2' verdict: 'SUCCESS' IP: '{$ip}' Browser: '{$browser}'" . PHP_EOL;
|
|
error_log($log, 3, $_SERVER['DOCUMENT_ROOT'] . '/logs/captchaErrorLog.log');
|
|
|
|
$query = "SELECT * FROM www_archline_hu.jml_users WHERE username = ? OR email = ?";
|
|
Database::getInstance()->query($query, array('ss', $temp['email'], $temp['email']));
|
|
$res = Database::getInstance()->fetchNext();
|
|
|
|
if (!empty($res)) {
|
|
$message = $resource->getDlgString('10789');
|
|
return false;
|
|
}
|
|
|
|
if ($temp['password'] != $temp['password2']) {
|
|
$message = $resource->getDlgString('10792');
|
|
return false;
|
|
}
|
|
|
|
// Initialise the table with JUser.
|
|
$user = new JUser;
|
|
$data = (array) $this->getData();
|
|
|
|
// Merge in the registration data.
|
|
foreach ($temp as $k => $v) {
|
|
$data[$k] = $v;
|
|
}
|
|
|
|
$user->bind($data);
|
|
|
|
if (!$user->save()) {
|
|
$message = JText::sprintf('COM_USERS_REGISTRATION_SAVE_FAILED', $user->getError());
|
|
return false;
|
|
}
|
|
|
|
$profile_phone = array(
|
|
'user_id' => $user->id,
|
|
'profile_key' => 'profile.phone',
|
|
'profile_value' => $temp['phone'],
|
|
'ordering' => 7
|
|
);
|
|
|
|
$profile_country = array(
|
|
'user_id' => $user->id,
|
|
'profile_key' => 'profile.country',
|
|
'profile_value' => $temp['country'],
|
|
'ordering' => 5
|
|
);
|
|
|
|
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_phone, 'issi');
|
|
Database::getInstance()->insert('www_archline_hu.jml_user_profiles', $profile_country, 'issi');
|
|
|
|
$query = "SELECT nUserID FROM cl_hlusers.u_emails WHERE email = ?";
|
|
Database::getInstance()->query($query, array('s', $user->email));
|
|
$existingUser = Database::getInstance()->fetchNext();
|
|
|
|
if (count($existingUser) > 0) {
|
|
$nUserID = $existingUser['nUserID'];
|
|
} else {
|
|
$query = "SELECT * FROM www_archline_hu.jml_jsn_users WHERE id = ?";
|
|
Database::getInstance()->query($query, array('i', $user->id));
|
|
$storeData = Database::getInstance()->fetchNext();
|
|
|
|
if ($storeData['old_db'] == 'hu') {
|
|
$old_db = "clusers";
|
|
$info = "Weben regisztrált";
|
|
$topic = 362;
|
|
} else {
|
|
$old_db = "clusers_eng";
|
|
$info = "Web registration";
|
|
$topic = 219;
|
|
}
|
|
|
|
$nUserID = Database::getInstance()->insert(
|
|
'cl_hlusers.users',
|
|
array(
|
|
"strName" => $user->name,
|
|
"strTel" => $storeData['phone'],
|
|
"nUserProf" => $storeData['profession'],
|
|
"nManagerID" => 36,
|
|
"strEmail" => $user->email,
|
|
"dateInsert" => time(),
|
|
"nUserType" => 0,
|
|
"strStreet" => $storeData['address'],
|
|
"strCity" => $storeData['city'],
|
|
"strZip" => $storeData['zip'],
|
|
"nCtrID" => $storeData['country'] == null ? 0 : $storeData['country'],
|
|
"old_db" => $old_db
|
|
),
|
|
'ssiisiisssis'
|
|
);
|
|
|
|
Database::getInstance()->insert(
|
|
'cl_hlusers.u_emails',
|
|
array(
|
|
"email" => $user->email,
|
|
"nUserID" => $nUserID,
|
|
"newsletter" => 1,
|
|
"default" => 1
|
|
),
|
|
'siii'
|
|
);
|
|
}
|
|
|
|
Database::getInstance()->update(
|
|
"www_archline_hu.jml_users",
|
|
array(
|
|
'nUserID' => $nUserID,
|
|
'username' => $user->email
|
|
),
|
|
array('id' => $user->id),
|
|
'isi'
|
|
);
|
|
|
|
Database::getInstance()->insert(
|
|
'cl_hlusers.u_history',
|
|
array(
|
|
"nUserID" => $nUserID,
|
|
"nTopicID" => $topic,
|
|
"dateEvent" => date("Y-m-d", time()),
|
|
"strPlace" => 'web',
|
|
"strInfo" => $info,
|
|
"nManagerID" => 36,
|
|
"insertDate" => date("Y-m-d H:i:s", time())
|
|
),
|
|
'iisssis'
|
|
);
|
|
|
|
$this->phoneCorrect($temp['phone']);
|
|
|
|
$query = "SELECT * FROM www_archline_hu.jml_users WHERE id = ?";
|
|
Database::getInstance()->query($query, array('i', $user->id));
|
|
$jmlUser = Database::getInstance()->fetchNext();
|
|
|
|
Database::getInstance()->update(
|
|
'cl_hlusers.users',
|
|
array(
|
|
'strTel' => $temp['phone'],
|
|
'nCtrID' => $temp['country']
|
|
),
|
|
array('nUserID' => $jmlUser['nUserID']),
|
|
'sii'
|
|
);
|
|
|
|
$message = $resource->getDlgString('10793');
|
|
return $user->id;
|
|
}
|
|
}
|