golden hour
/home/doctorbruno/public_html/taeionline.com/support/include
⬆️ Go Up
Upload
File/Folder
Size
Actions
.MANIFEST
194.97 KB
Del
OK
.htaccess
14 B
Del
OK
JSON.php
33.13 KB
Del
OK
PasswordHash.php
6.92 KB
Del
OK
Spyc.php
31.74 KB
Del
OK
UniversalClassLoader.php
8.61 KB
Del
OK
ajax.admin.php
7.29 KB
Del
OK
ajax.config.php
4.61 KB
Del
OK
ajax.content.php
9.76 KB
Del
OK
ajax.draft.php
13.03 KB
Del
OK
ajax.email.php
2.33 KB
Del
OK
ajax.export.php
1006 B
Del
OK
ajax.filter.php
874 B
Del
OK
ajax.forms.php
13.84 KB
Del
OK
ajax.i18n.php
5.1 KB
Del
OK
ajax.kbase.php
2.93 KB
Del
OK
ajax.note.php
2.05 KB
Del
OK
ajax.orgs.php
11.73 KB
Del
OK
ajax.plugins.php
2.15 KB
Del
OK
ajax.schedule.php
4.29 KB
Del
OK
ajax.search.php
12.72 KB
Del
OK
ajax.sequence.php
3.2 KB
Del
OK
ajax.staff.php
11.62 KB
Del
OK
ajax.tasks.php
33.87 KB
Del
OK
ajax.thread.php
8.81 KB
Del
OK
ajax.tickets.php
79.7 KB
Del
OK
ajax.tips.php
1.66 KB
Del
OK
ajax.upgrader.php
2.24 KB
Del
OK
ajax.users.php
18.33 KB
Del
OK
api.cron.php
1.06 KB
Del
OK
api.tickets.php
10.36 KB
Del
OK
class.2fa.php
7.76 KB
Del
OK
class.ajax.php
1.45 KB
Del
OK
class.api.php
15.31 KB
Del
OK
class.app.php
1.49 KB
Del
OK
class.attachment.php
6.95 KB
Del
OK
class.auth.php
50.73 KB
Del
OK
class.avatar.php
6.44 KB
Del
OK
class.banlist.php
2.58 KB
Del
OK
class.base32.php
4.07 KB
Del
OK
class.businesshours.php
7.08 KB
Del
OK
class.canned.php
9.05 KB
Del
OK
class.captcha.php
1.73 KB
Del
OK
class.category.php
11.14 KB
Del
OK
class.charset.php
3.41 KB
Del
OK
class.cli.php
9.48 KB
Del
OK
class.client.php
15.39 KB
Del
OK
class.collaborator.php
5.65 KB
Del
OK
class.company.php
2.65 KB
Del
OK
class.config.php
60.36 KB
Del
OK
class.controller.php
1.15 KB
Del
OK
class.cron.php
3.6 KB
Del
OK
class.crypto.php
18.92 KB
Del
OK
class.csrf.php
2.38 KB
Del
OK
class.dept.php
33.21 KB
Del
OK
class.dispatcher.php
7.12 KB
Del
OK
class.draft.php
6.23 KB
Del
OK
class.dynamic_forms.php
64.98 KB
Del
OK
class.email.php
49 KB
Del
OK
class.error.php
1.69 KB
Del
OK
class.export.php
32.92 KB
Del
OK
class.faq.php
15.05 KB
Del
OK
class.file.php
34.59 KB
Del
OK
class.filter.php
31.9 KB
Del
OK
class.filter_action.php
23.67 KB
Del
OK
class.format.php
44.3 KB
Del
OK
class.forms.php
195.58 KB
Del
OK
class.http.php
7.16 KB
Del
OK
class.i18n.php
24.28 KB
Del
OK
class.import.php
6.9 KB
Del
OK
class.json.php
2.71 KB
Del
OK
class.knowledgebase.php
5.8 KB
Del
OK
class.list.php
42 KB
Del
OK
class.lock.php
4.05 KB
Del
OK
class.log.php
1.55 KB
Del
OK
class.mail.php
35.76 KB
Del
OK
class.mailer.php
25.75 KB
Del
OK
class.mailfetch.php
9.72 KB
Del
OK
class.mailparse.php
30.99 KB
Del
OK
class.message.php
6.42 KB
Del
OK
class.migrater.php
5.2 KB
Del
OK
class.misc.php
7.5 KB
Del
OK
class.model.php
2.3 KB
Del
OK
class.nav.php
14.15 KB
Del
OK
class.note.php
2.39 KB
Del
OK
class.oauth2.php
4.04 KB
Del
OK
class.organization.php
22.45 KB
Del
OK
class.orm.php
120.9 KB
Del
OK
class.osticket.php
20.64 KB
Del
OK
class.ostsession.php
21.86 KB
Del
OK
class.page.php
10.59 KB
Del
OK
class.pagenate.php
5.53 KB
Del
OK
class.passwd.php
1.21 KB
Del
OK
class.pdf.php
3.83 KB
Del
OK
class.plugin.php
36.13 KB
Del
OK
class.priority.php
1.81 KB
Del
OK
class.queue.php
103.51 KB
Del
OK
class.report.php
11.76 KB
Del
OK
class.role.php
11.27 KB
Del
OK
class.schedule.php
46.28 KB
Del
OK
class.search.php
61.66 KB
Del
OK
class.sequence.php
7.27 KB
Del
OK
class.session.php
19.25 KB
Del
OK
class.setup.php
3.55 KB
Del
OK
class.signal.php
4.16 KB
Del
OK
class.sla.php
9.11 KB
Del
OK
class.staff.php
60.21 KB
Del
OK
class.task.php
56.21 KB
Del
OK
class.team.php
12.31 KB
Del
OK
class.template.php
23.45 KB
Del
OK
class.thread.php
108.96 KB
Del
OK
class.thread_actions.php
17.08 KB
Del
OK
class.ticket.php
167.39 KB
Del
OK
class.timezone.php
21.94 KB
Del
OK
class.topic.php
20.06 KB
Del
OK
class.translation.php
34.79 KB
Del
OK
class.upgrader.php
13.76 KB
Del
OK
class.user.php
43.4 KB
Del
OK
class.usersession.php
7.55 KB
Del
OK
class.util.php
10.07 KB
Del
OK
class.validator.php
12.94 KB
Del
OK
class.variable.php
11.93 KB
Del
OK
class.xml.php
3.23 KB
Del
OK
class.yaml.php
1.15 KB
Del
OK
cli
-
Del
OK
client
-
Del
OK
config
-
Del
OK
fpdf
-
Del
OK
htmLawed.php
53.53 KB
Del
OK
html2text.php
33.71 KB
Del
OK
i18n
-
Del
OK
index.php
37 B
Del
OK
laminas-mail
-
Del
OK
mpdf
-
Del
OK
mysqli.php
9.55 KB
Del
OK
ost-config.php
5.63 KB
Del
OK
ost-sampleconfig.php
6.24 KB
Del
OK
pear
-
Del
OK
plugins
-
Del
OK
staff
-
Del
OK
tnef_decoder.php
19.82 KB
Del
OK
upgrader
-
Del
OK
Edit: class.validator.php
<?php /********************************************************************* class.validator.php Input validation helper. This class contains collection of functions used for data validation. Peter Rotich <peter@osticket.com> Copyright (c) 2006-2013 osTicket http://www.osticket.com Released under the GNU General Public License WITHOUT ANY WARRANTY. See LICENSE.TXT for details. vim: expandtab sw=4 ts=4 sts=4: **********************************************************************/ class Validator { var $input=array(); var $fields=array(); var $errors=array(); function __construct($fields=null) { $this->setFields($fields); } function setFields(&$fields){ if($fields && is_array($fields)): $this->fields=$fields; return (true); endif; return (false); } function validate($source,$userinput=true){ $this->errors=array(); //Check the input and make sure the fields are specified. if(!$source || !is_array($source)) $this->errors['err']=__('Invalid input'); elseif(!$this->fields || !is_array($this->fields)) $this->errors['err']=__('No fields set up'); //Abort on error if($this->errors) return false; //if magic quotes are enabled - then try cleaning up inputs before validation... if($userinput && function_exists('get_magic_quotes_gpc') && get_magic_quotes_gpc()) $source=Format::strip_slashes($source); $this->input=$source; //Do the do. foreach($this->fields as $k=>$field){ if(!$field['required'] && !$this->input[$k]) //NOT required...and no data provided... continue; if($field['required'] && !isset($this->input[$k]) || (!$this->input[$k] && $field['type']!='int')){ //Required...and no data provided... $this->errors[$k]=$field['error']; continue; } //We don't care about the type. if ($field['type'] == '*') continue; //Do the actual validation based on the type. switch(strtolower($field['type'])): case 'integer': case 'int': if(!is_numeric($this->input[$k])) $this->errors[$k]=$field['error']; elseif ($field['min'] && $this->input[$k] < $field['min']) $this->errors[$k]=$field['error']; break; case 'double': if(!is_numeric($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'text': case 'string': if(!is_string($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'array': if(!$this->input[$k] || !is_array($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'radio': if(!isset($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'date': //TODO...make sure it is really in GNU date format.. if(strtotime($this->input[$k])===false) $this->errors[$k]=$field['error']; break; case 'time': //TODO...make sure it is really in GNU time format.. break; case 'phone': case 'fax': if(!self::is_phone($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'email': if(!self::is_email($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'url': if(!self::is_url($this->input[$k])) $this->errors[$k]=$field['error']; break; case 'password': if(strlen($this->input[$k])<6) $this->errors[$k]=$field['error'].' '.__('(Six characters min)'); break; case 'username': $error = ''; if (!self::is_username($this->input[$k], $error)) $this->errors[$k]=$field['error'].": $error"; break; case 'zipcode': if(!is_numeric($this->input[$k]) || (strlen($this->input[$k])!=5)) $this->errors[$k]=$field['error']; break; case 'cs-domain': // Comma separated list of domains if($values=explode(',', $this->input[$k])) foreach($values as $v) if(!preg_match_all( '/^([a-z0-9|-]+\.)*[a-z0-9|-]+\.[a-z]+$/', ltrim($v))) $this->errors[$k]=$field['error']; break; case 'cs-url': // Comma separated list of urls if($values=explode(',', $this->input[$k])) foreach($values as $v) if(!preg_match_all( '/^(https?:\/\/)?((\*\.|\w+\.)?[\w-]+(\.[a-zA-Z]+)?(:([0-9]+|\*))?)+$/', ltrim($v))) $this->errors[$k]=$field['error']; break; case 'ipaddr': if($values=explode(',', $this->input[$k])){ foreach($values as $v) if(!preg_match_all('/^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$/', ltrim($v))) $this->errors[$k]=$field['error']; } break; default://If param type is not set...or handle..error out... $this->errors[$k]=$field['error'].' '.__('(type not set)'); endswitch; } return ($this->errors)?(FALSE):(TRUE); } function iserror(){ return $this->errors?true:false; } function errors(){ return $this->errors; } /*** Functions below can be called directly without class instance. Validator::func(var..); (nolint) ***/ static function is_email($email, $list=false, $verify=false) { require_once PEAR_DIR . 'Mail/RFC822.php'; require_once PEAR_DIR . 'PEAR.php'; $rfc822 = new Mail_RFC822(); if (!($mails = @$rfc822->parseAddressList($email)) || PEAR::isError($mails)) return false; if (!$list && count($mails) > 1) return false; foreach ($mails as $m) { if (!$m->mailbox) return false; if ($m->host == 'localhost') return false; } // According to RFC2821, the domain (A record) can be treated as an // MX if no MX records exist for the domain. Also, include a // full-stop trailing char so that the default domain of the server // is not added automatically if ($verify and !dns_get_record($m->host.'.', DNS_MX)) return (count(dns_get_record($m->host.'.', DNS_A|DNS_AAAA) ?: [])); return true; } static function is_emailish($email) { return (preg_match('/(.*@.{2,})|(.{2,}@.*)/', $email)); } static function is_numeric($number, &$error='') { if (!is_numeric($number)) $error = __('Enter a Number'); return $error == ''; } static function is_valid_email($email, &$error='') { global $cfg; // Default to FALSE for installation return self::is_email($email, false, $cfg && $cfg->verifyEmailAddrs()); } static function is_phone($phone, &$error='') { /* We're not really validating the phone number but just making sure it doesn't contain illegal chars and of acceptable len */ $stripped=preg_replace("(\(|\)|\-|\.|\+|[ ]+)","",$phone); return (!is_numeric($stripped) || ((strlen($stripped)<7) || (strlen($stripped)>16)))?false:true; } static function is_url($url) { //XXX: parse_url is not ideal for validating urls but it's ideal for basic checks. return ($url && ($info=parse_url($url)) && $info['host']); } static function is_ip($ip, &$error='') { return filter_var(trim($ip), FILTER_VALIDATE_IP) !== false; } static function is_username($username, &$error='') { if (strlen($username)<2) $error = __('Username must have at least two (2) characters'); elseif (is_numeric($username) || !preg_match('/^[\p{L}\d._-]+$/u', $username)) $error = __('Username contains invalid characters'); return $error == ''; } static function is_userid($userid, &$error='') { if (!self::is_username($userid) && !self::is_email($userid)) $error = __('Invalid User Id '); return $error == ''; } static function is_formula($text, &$error='') { if (!preg_match('/(^[^=\+@-].*$)|(^\+\d+$)/s', $text)) $error = __('Content cannot start with the following characters: = - + @'); return $error == ''; } static function check_passwd($passwd, &$error='') { try { PasswordPolicy::checkPassword($passwd, null); } catch (BadPassword $ex) { $error = $ex->getMessage(); } return $error == ''; } /* * check_ip * Checks if an IP (IPv4 or IPv6) address is contained in the list of given IPs or subnets. * * @credit - borrowed from Symfony project * */ public static function check_ip($ip, $ips) { if (!Validator::is_ip($ip)) return false; $method = substr_count($ip, ':') > 1 ? 'check_ipv6' : 'check_ipv4'; $ips = is_array($ips) ? $ips : array($ips); foreach ($ips as $_ip) { if (self::$method($ip, $_ip)) { return true; } } return false; } /** * check_ipv4 * Compares two IPv4 addresses. * In case a subnet is given, it checks if it contains the request IP. * * @credit - borrowed from Symfony project */ public static function check_ipv4($ip, $cidr) { if (false !== strpos($cidr, '/')) { list($address, $netmask) = explode('/', $cidr, 2); if ($netmask === '0') return filter_var($address, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4); if ($netmask < 0 || $netmask > 32) return false; } else { $address = $cidr; $netmask = 32; } return 0 === substr_compare( sprintf('%032b', ip2long($ip)), sprintf('%032b', ip2long($address)), 0, $netmask); } /** * Compares two IPv6 addresses. * In case a subnet is given, it checks if it contains the request IP. * * @credit - borrowed from Symfony project * @author David Soria Parra <dsp at php dot net> * * @see https://github.com/dsp/v6tools * */ public static function check_ipv6($ip, $cidr) { if (!((extension_loaded('sockets') && defined('AF_INET6')) || @inet_pton('::1'))) return false; if (false !== strpos($cidr, '/')) { list($address, $netmask) = explode('/', $cidr, 2); if ($netmask < 1 || $netmask > 128) return false; } else { $address = $cidr; $netmask = 128; } $bytesAddr = unpack('n*', @inet_pton($address)); $bytesTest = unpack('n*', @inet_pton($ip)); if (!$bytesAddr || !$bytesTest) return false; for ($i = 1, $ceil = ceil($netmask / 16); $i <= $ceil; ++$i) { $left = $netmask - 16 * ($i - 1); $left = ($left <= 16) ? $left : 16; $mask = ~(0xffff >> $left) & 0xffff; if (($bytesAddr[$i] & $mask) != ($bytesTest[$i] & $mask)) { return false; } } return true; } static function process($fields,$vars,&$errors){ $val = new Validator(); $val->setFields($fields); if(!$val->validate($vars)) $errors=array_merge($errors,$val->errors()); return (!$errors); } static function check_acl($backend) { global $cfg; $acl = $cfg->getACL(); if (empty($acl)) return true; $ip = osTicket::get_client_ip(); if (empty($ip)) return false; $aclbk = $cfg->getACLBackend(); switch($backend) { case 'client': if (in_array($aclbk, array(0,3)) || ($aclbk == 2 && StaffAuthenticationBackend::getUser())) return true; break; case 'staff': if (in_array($aclbk, array(0,2))) return true; break; default: return false; break; } if (!in_array($ip, $acl)) return false; return true; } } ?>
Save