add more security settings (allow_admin_panel, core_install_access_domains)

+ small fixes
This commit is contained in:
RainLoop Team 2013-11-19 01:33:57 +04:00
parent 6ffa712a05
commit df1c369a9d
9 changed files with 26 additions and 25 deletions

View file

@ -2256,7 +2256,10 @@ class Actions
private function rainLoopCoreAccess()
{
return $this->Http()->CheckLocalhost(APP_SITE) || APP_SITE === APP_CORE_INSTALL_ACCESS_SITE;
$sCoreAccess = \strtolower(\preg_replace('/[\s,;]+/', ' ',
$this->Config()->Get('security', 'core_install_access_domains', '')));
return '' === $sCoreAccess || APP_SITE === $sCoreAccess;
}
private function getRepositoryDataByUrl($sRepo, &$bReal = false)

View file

@ -87,7 +87,9 @@ class Application extends \RainLoop\Config\AbstractConfig
'custom_server_signature' => array('RainLoop'),
'admin_login' => array('admin', 'Login and password for web admin panel'),
'admin_password' => array('12345')
'admin_password' => array('12345'),
'allow_admin_panel' => array(true, 'Access settings'),
'core_install_access_domains' => array('')
),
'login' => array(

View file

@ -94,11 +94,11 @@ class Service
$this->oActions->ParseQueryAuthString();
if (defined('APP_INSTALLED_START') && defined('APP_INSTALLED_VERSION') && APP_INSTALLED_START &&
if (defined('APP_INSTALLED_START') && defined('APP_INSTALLED_VERSION') &&
APP_INSTALLED_START && !APP_INSTALLED_VERSION &&
$this->oActions->Config()->Get('labs', 'usage_statistics', true))
{
$this->oActions->KeenIO(APP_INSTALLED_VERSION ? 'Upgrade' : 'Install',
APP_INSTALLED_VERSION ? array('previos-version' => APP_INSTALLED_VERSION) : array());
$this->oActions->KeenIO('Install');
}
$bCached = false;
@ -115,6 +115,13 @@ class Service
$this->oActions->Plugins()->RunHook('filter.http-paths', array(&$aPaths));
$bAdmin = !empty($aPaths[0]) && \in_array(\strtolower($aPaths[0]), array('admin', 'cp'));
if ($bAdmin && !$this->oActions->Config()->Get('security', 'allow_admin_panel', true))
{
echo $this->oActions->ErrorTemplates('Access Denied.',
'Access to the RainLoop Webmail Admin Panel is not allowed!', true);
return $this;
}
if (0 < \count($aPaths) && !empty($aPaths[0]) && !$bAdmin)
{