Bootswatch, Summernote, and Captcheck mods for Mods for HESK (mods-for-hesk.com). In use at support.netsyms.com.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

index.php 20KB


  1. <?php
  2. /**
  3. *
  4. * This file is part of HESK - PHP Help Desk Software.
  5. *
  6. * (c) Copyright Klemen Stirn. All rights reserved.
  7. * https://www.hesk.com
  8. *
  9. * For the full copyright and license agreement information visit
  10. * https://www.hesk.com/eula.php
  11. *
  12. */
  13. define('IN_SCRIPT', 1);
  14. define('HESK_PATH', '../');
  15. define('PAGE_TITLE', 'LOGIN');
  16. /* Get all the required files and functions */
  17. require(HESK_PATH . 'hesk_settings.inc.php');
  18. require(HESK_PATH . 'inc/common.inc.php');
  19. require(HESK_PATH . 'inc/admin_functions.inc.php');
  20. hesk_load_database_functions();
  21. hesk_session_start();
  22. hesk_dbConnect();
  23. $modsForHesk_settings = mfh_getSettings();
  24. /* What should we do? */
  25. $action = hesk_REQUEST('a');
  26. switch ($action) {
  27. case 'do_login':
  28. do_login();
  29. break;
  30. case 'login':
  31. print_login();
  32. break;
  33. case 'logout':
  34. logout();
  35. break;
  36. default:
  37. hesk_autoLogin();
  38. print_login();
  39. }
  40. exit();
  41. /*** START FUNCTIONS ***/
  42. function do_login()
  43. {
  44. global $hesk_settings, $hesklang, $modsForHesk_settings;
  45. $hesk_error_buffer = array();
  46. $user = hesk_input(hesk_POST('user'));
  47. if (empty($user)) {
  48. $myerror = $hesk_settings['list_users'] ? $hesklang['select_username'] : $hesklang['enter_username'];
  49. $hesk_error_buffer['user'] = $myerror;
  50. }
  51. define('HESK_USER', $user);
  52. $pass = hesk_input(hesk_POST('pass'));
  53. if (empty($pass)) {
  54. $hesk_error_buffer['pass'] = $hesklang['enter_pass'];
  55. }
  56. if ($hesk_settings['secimg_use'] == 2 && !isset($_SESSION['img_a_verified'])) {
  57. // Using ReCaptcha?
  58. if ($hesk_settings['recaptcha_use']) {
  59. require(HESK_PATH . 'inc/recaptcha/recaptchalib_v2.php');
  60. $resp = null;
  61. $reCaptcha = new ReCaptcha($hesk_settings['recaptcha_private_key']);
  62. // Was there a reCAPTCHA response?
  63. if (isset($_POST["g-recaptcha-response"])) {
  64. $resp = $reCaptcha->verifyResponse(hesk_getClientIP(), hesk_POST("g-recaptcha-response"));
  65. }
  66. if ($resp != null && $resp->success) {
  67. $_SESSION['img_a_verified'] = true;
  68. } else {
  69. $hesk_error_buffer['mysecnum'] = $hesklang['recaptcha_error'];
  70. }
  71. } // Using PHP generated image
  72. else {
  73. $mysecnum = intval(hesk_POST('mysecnum', 0));
  74. if (empty($mysecnum)) {
  75. $hesk_error_buffer['mysecnum'] = $hesklang['sec_miss'];
  76. } else {
  77. require(HESK_PATH . 'inc/secimg.inc.php');
  78. $sc = new PJ_SecurityImage($hesk_settings['secimg_sum']);
  79. if (isset($_SESSION['checksum']) && $sc->checkCode($mysecnum, $_SESSION['checksum'])) {
  80. $_SESSION['img_a_verified'] = true;
  81. } else {
  82. $hesk_error_buffer['mysecnum'] = $hesklang['sec_wrng'];
  83. }
  84. }
  85. }
  86. }
  87. /* Any missing fields? */
  88. if (count($hesk_error_buffer) != 0) {
  89. $_SESSION['a_iserror'] = array_keys($hesk_error_buffer);
  90. $tmp = '';
  91. foreach ($hesk_error_buffer as $error) {
  92. $tmp .= "<li>$error</li>\n";
  93. }
  94. $hesk_error_buffer = $tmp;
  95. $hesk_error_buffer = $hesklang['pcer'] . '<br /><br /><ul>' . $hesk_error_buffer . '</ul>';
  96. hesk_process_messages($hesk_error_buffer, 'NOREDIRECT');
  97. print_login();
  98. exit();
  99. } elseif (isset($_SESSION['img_a_verified'])) {
  100. unset($_SESSION['img_a_verified']);
  101. }
  102. /* User entered all required info, now lets limit brute force attempts */
  103. hesk_limitBfAttempts();
  104. $result = hesk_dbQuery("SELECT * FROM `" . hesk_dbEscape($hesk_settings['db_pfix']) . "users` WHERE `user` = '" . hesk_dbEscape($user) . "' LIMIT 1");
  105. if (hesk_dbNumRows($result) != 1) {
  106. hesk_session_stop();
  107. $_SESSION['a_iserror'] = array('user', 'pass');
  108. hesk_process_messages($hesklang['wrong_user'], 'NOREDIRECT');
  109. print_login();
  110. exit();
  111. }
  112. $res = hesk_dbFetchAssoc($result);
  113. foreach ($res as $k => $v) {
  114. $_SESSION[$k] = $v;
  115. }
  116. /* Check password */
  117. if (hesk_Pass2Hash($pass) != $_SESSION['pass']) {
  118. hesk_session_stop();
  119. $_SESSION['a_iserror'] = array('pass');
  120. hesk_process_messages($hesklang['wrong_pass'], 'NOREDIRECT');
  121. print_login();
  122. exit();
  123. }
  124. $pass_enc = hesk_Pass2Hash($_SESSION['pass'].hesk_mb_strtolower($user).$_SESSION['pass']);
  125. /* Check if default password */
  126. if ($_SESSION['pass'] == '499d74967b28a841c98bb4baaabaad699ff3c079') {
  127. hesk_process_messages($hesklang['chdp'], 'NOREDIRECT', 'NOTICE');
  128. }
  129. // Set a tag that will be used to expire sessions after username or password change
  130. $_SESSION['session_verify'] = hesk_activeSessionCreateTag($user, $_SESSION['pass']);
  131. // We don't need the password hash anymore
  132. unset($_SESSION['pass']);
  133. /* Login successful, clean brute force attempts */
  134. hesk_cleanBfAttempts();
  135. /* Make sure our user is active */
  136. if (!$_SESSION['active']) {
  137. hesk_session_stop();
  138. $_SESSION['a_iserror'] = array('active');
  139. hesk_process_messages($hesklang['inactive_user'], 'NOREDIRECT');
  140. print_login();
  141. exit();
  142. }
  143. /* Regenerate session ID (security) */
  144. hesk_session_regenerate_id();
  145. /* Remember username? */
  146. if ($hesk_settings['autologin'] && hesk_POST('remember_user') == 'AUTOLOGIN') {
  147. hesk_setcookie('hesk_username', "$user", strtotime('+1 year'));
  148. hesk_setcookie('hesk_p', "$pass_enc", strtotime('+1 year'));
  149. } elseif (hesk_POST('remember_user') == 'JUSTUSER') {
  150. hesk_setcookie('hesk_username', "$user", strtotime('+1 year'));
  151. hesk_setcookie('hesk_p', '');
  152. } else {
  153. // Expire cookie if set otherwise
  154. hesk_setcookie('hesk_username', '');
  155. hesk_setcookie('hesk_p', '');
  156. }
  157. /* Close any old tickets here so Cron jobs aren't necessary */
  158. if ($hesk_settings['autoclose']) {
  159. $dt = date('Y-m-d H:i:s', time() - $hesk_settings['autoclose'] * 86400);
  160. $closedStatusRs = hesk_dbQuery('SELECT `ID`, `Closable` FROM `' . hesk_dbEscape($hesk_settings['db_pfix']) . 'statuses` WHERE `IsDefaultStaffReplyStatus` = 1');
  161. $closedStatus = hesk_dbFetchAssoc($closedStatusRs);
  162. // Are we allowed to close tickets in this status?
  163. if ($closedStatus['Closable'] == 'yes' || $closedStatus['Closable'] == 'sonly') {
  164. $result = hesk_dbQuery("SELECT * FROM `" . $hesk_settings['db_pfix'] . "tickets` WHERE `status` = " . $closedStatus['ID'] . " AND `lastchange` <= '" . hesk_dbEscape($dt) . "' ");
  165. if (hesk_dbNumRows($result) > 0) {
  166. global $ticket;
  167. // Load required functions?
  168. if (!function_exists('hesk_notifyCustomer')) {
  169. require(HESK_PATH . 'inc/email_functions.inc.php');
  170. }
  171. while ($ticket = hesk_dbFetchAssoc($result)) {
  172. $ticket['dt'] = hesk_date($ticket['dt'], true);
  173. $ticket['lastchange'] = hesk_date($ticket['lastchange'], true);
  174. $ticket = hesk_ticketToPlain($ticket, 1, 0);
  175. mfh_insert_audit_trail_record($ticket['id'], 'TICKET', 'audit_automatically_closed', hesk_date(), array());
  176. // Notify customer of closed ticket?
  177. if ($hesk_settings['notify_closed']) {
  178. // Get list of tickets
  179. hesk_notifyCustomer($modsForHesk_settings, 'ticket_closed');
  180. }
  181. }
  182. }
  183. // Update ticket statuses and history in database if we're allowed to do so
  184. $defaultCloseRs = hesk_dbQuery('SELECT `ID` FROM `' . hesk_dbEscape($hesk_settings['db_pfix']) . 'statuses` WHERE `IsAutocloseOption` = 1');
  185. $defaultCloseStatus = hesk_dbFetchAssoc($defaultCloseRs);
  186. hesk_dbQuery("UPDATE `" . $hesk_settings['db_pfix'] . "tickets` SET `status`=" . intval($defaultCloseStatus['ID']) . ", `closedat`=NOW(), `closedby`='-1' WHERE `status` = " . $closedStatus['ID'] . " AND `lastchange` <= '" . hesk_dbEscape($dt) . "' ");
  187. }
  188. }
  189. /* Redirect to the destination page */
  190. header('Location: ' . hesk_verifyGoto());
  191. exit();
  192. } // End do_login()
  193. function print_login()
  194. {
  195. global $hesk_settings, $hesklang, $modsForHesk_settings;
  196. // Tell header to load reCaptcha API if needed
  197. if ($hesk_settings['recaptcha_use'])
  198. {
  199. define('RECAPTCHA',1);
  200. }
  201. $hesk_settings['tmp_title'] = $hesk_settings['hesk_title'] . ' - ' .$hesklang['admin_login'];
  202. require_once(HESK_PATH . 'inc/headerAdmin.inc.php');
  203. if ( hesk_isREQUEST('notice') )
  204. {
  205. hesk_process_messages($hesklang['session_expired'],'NOREDIRECT');
  206. }
  207. if (!isset($_SESSION['a_iserror']))
  208. {
  209. $_SESSION['a_iserror'] = array();
  210. }
  211. ?>
  212. <div class="login-box">
  213. <div class="login-box-container">
  214. <div class="login-box-background"></div>
  215. <div class="login-box-body">
  216. <div class="loginError">
  217. <?php
  218. /* This will handle error, success and notice messages */
  219. hesk_handle_messages();
  220. // Service messages
  221. $service_messages = mfh_get_service_messages('STAFF_LOGIN');
  222. foreach ($service_messages as $sm) {
  223. hesk_service_message($sm);
  224. }
  225. ?>
  226. </div>
  227. <div class="login-logo">
  228. <?php if ($modsForHesk_settings['login_box_header'] == 'image'): ?>
  229. <img src="<?php echo HESK_PATH . $hesk_settings['cache_dir'] . '/lbh_' . $modsForHesk_settings['login_box_header_image']; ?>"
  230. style="height: 75px">
  231. <?php else:
  232. echo $hesk_settings['hesk_title'];
  233. endif; ?>
  234. </div>
  235. <h4 class="login-box-msg">
  236. <?php echo $hesklang['staff_login_title']; ?>
  237. </h4>
  238. <form class="form-horizontal" role="form" action="index.php" method="post" name="form1" id="form1">
  239. <?php
  240. $has_error = '';
  241. if (in_array('pass',$_SESSION['a_iserror'])) {
  242. $has_error = 'has-error';
  243. }
  244. ?>
  245. <div class="form-group <?php echo $has_error; ?>">
  246. <label for="user" class="col-sm-4 control-label">
  247. <?php echo $hesklang['username']; ?>
  248. </label>
  249. <div class="col-sm-8">
  250. <?php
  251. if (defined('HESK_USER')) {
  252. $savedUser = HESK_USER;
  253. } else {
  254. $savedUser = hesk_htmlspecialchars(hesk_COOKIE('hesk_username'));
  255. }
  256. $is_1 = '';
  257. $is_2 = '';
  258. $is_3 = '';
  259. $remember_user = hesk_POST('remember_user');
  260. if ($hesk_settings['autologin'] && (isset($_COOKIE['hesk_p']) || $remember_user == 'AUTOLOGIN')) {
  261. $is_1 = 'checked';
  262. } elseif (isset($_COOKIE['hesk_username']) || $remember_user == 'JUSTUSER') {
  263. $is_2 = 'checked';
  264. } else {
  265. $is_3 = 'checked';
  266. }
  267. if ($hesk_settings['list_users']) :
  268. $res = hesk_dbQuery("SELECT `user` FROM `" . hesk_dbEscape($hesk_settings['db_pfix']) . "users` WHERE `active` = '1' ORDER BY `user` ASC");
  269. ?>
  270. <select class="form-control" name="user">
  271. <?php
  272. while ($row = hesk_dbFetchAssoc($res)):
  273. $sel = (hesk_mb_strtolower($savedUser) == hesk_mb_strtolower($row['user'])) ? 'selected="selected"' : '';
  274. ?>
  275. <option value="<?php echo $row['user']; ?>" <?php echo $sel; ?>>
  276. <?php echo $row['user']; ?>
  277. </option>
  278. <?php endwhile; ?>
  279. </select>
  280. <?php else: ?>
  281. <input class="form-control" type="text" name="user" size="35"
  282. placeholder="<?php echo htmlspecialchars($hesklang['username']); ?>"
  283. value="<?php echo $savedUser; ?>">
  284. <?php endif; ?>
  285. </div>
  286. </div>
  287. <?php
  288. $has_error = '';
  289. if (in_array('pass',$_SESSION['a_iserror'])) {
  290. $has_error = 'has-error';
  291. }
  292. ?>
  293. <div class="form-group <?php echo $has_error; ?>">
  294. <label for="pass" class="col-sm-4 control-label">
  295. <?php echo $hesklang['pass']; ?>
  296. </label>
  297. <div class="col-sm-8">
  298. <input type="password" class="form-control" id="pass" name="pass" size="35" placeholder="<?php echo htmlspecialchars($hesklang['pass']); ?>">
  299. </div>
  300. </div>
  301. <?php
  302. if ($hesk_settings['secimg_use'] == 2 && $hesk_settings['recaptcha_use'] != 1)
  303. {
  304. // SPAM prevention verified for this session
  305. if (isset($_SESSION['img_a_verified']))
  306. {
  307. echo '<img src="'.HESK_PATH.'img/success.png" width="16" height="16" border="0" alt="" style="vertical-align:text-bottom" /> '.$hesklang['vrfy'];
  308. }
  309. // Use reCaptcha API v2?
  310. elseif ($hesk_settings['recaptcha_use'] == 2)
  311. {
  312. ?>
  313. <div class="form-group">
  314. <div class="col-md-8 col-md-offset-4">
  315. <div class="g-recaptcha" data-sitekey="<?php echo $hesk_settings['recaptcha_public_key']; ?>"></div>
  316. </div>
  317. </div>
  318. <?php
  319. }
  320. // At least use some basic PHP generated image (better than nothing)
  321. else
  322. {
  323. echo '<div class="form-group"><div class="col-md-8 col-md-offset-4">';
  324. $cls = in_array('mysecnum',$_SESSION['a_iserror']) ? ' class="isError" ' : '';
  325. echo $hesklang['sec_enter'].'<br><br><img src="'.HESK_PATH.'print_sec_img.php?'.rand(10000,99999).'" width="150" height="40" alt="'.$hesklang['sec_img'].'" title="'.$hesklang['sec_img'].'" border="1" name="secimg" style="vertical-align:text-bottom"> '.
  326. '<a href="javascript:void(0)" onclick="javascript:document.form1.secimg.src=\''.HESK_PATH.'print_sec_img.php?\'+ ( Math.floor((90000)*Math.random()) + 10000);"><img src="'.HESK_PATH.'img/reload.png" height="24" width="24" alt="'.$hesklang['reload'].'" title="'.$hesklang['reload'].'" border="0" style="vertical-align:text-bottom"></a>'.
  327. '<br><br><input type="text" name="mysecnum" size="20" maxlength="5" '.$cls.'>';
  328. echo '</div></div>';
  329. }
  330. } // End if $hesk_settings['secimg_use'] == 2
  331. if ($hesk_settings['autologin'])
  332. {
  333. ?>
  334. <div class="form-group">
  335. <div class="col-md-offset-4 col-md-8">
  336. <div class="radio">
  337. <label><input type="radio" name="remember_user" value="AUTOLOGIN" <?php echo $is_1; ?>> <?php echo $hesklang['autologin']; ?></label>
  338. </div>
  339. <div class="radio">
  340. <label><input type="radio" name="remember_user" value="JUSTUSER" <?php echo $is_2; ?>> <?php echo $hesklang['just_user']; ?></label>
  341. </div>
  342. <div class="radio">
  343. <label><input type="radio" name="remember_user" value="NOTHANKS" <?php echo $is_3; ?>> <?php echo $hesklang['nothx']; ?></label>
  344. </div>
  345. </div>
  346. </div>
  347. <?php
  348. }
  349. else
  350. {
  351. ?>
  352. <div class="form-group">
  353. <div class="col-md-offset-4 col-md-8">
  354. <div class="checkbox">
  355. <label><input type="checkbox" name="remember_user" value="JUSTUSER" <?php echo $is_2; ?> /> <?php echo $hesklang['remember_user']; ?></label>
  356. </div>
  357. </div>
  358. </div>
  359. <?php
  360. } // End if $hesk_settings['autologin']
  361. ?>
  362. <div class="form-group">
  363. <div class="col-md-offset-4 col-md-8">
  364. <input type="submit" value="<?php echo $hesklang['click_login']; ?>" class="btn btn-default" id="recaptcha-submit">
  365. <input type="hidden" name="a" value="do_login">
  366. <?php
  367. if ( hesk_isREQUEST('goto') && $url=hesk_REQUEST('goto') )
  368. {
  369. echo '<input type="hidden" name="goto" value="'.$url.'">';
  370. }
  371. // Do we allow staff password reset?
  372. if ($hesk_settings['reset_pass'])
  373. {
  374. echo '<br><br><a href="password.php" class="smaller">'.$hesklang['fpass'].'</a>';
  375. }
  376. ?>
  377. </div>
  378. </div>
  379. <?php
  380. // Use Invisible reCAPTCHA?
  381. if ($hesk_settings['secimg_use'] == 2 && $hesk_settings['recaptcha_use'] == 1 && ! isset($_SESSION['img_a_verified'])) {
  382. ?>
  383. <div class="g-recaptcha" data-sitekey="<?php echo $hesk_settings['recaptcha_public_key']; ?>" data-bind="recaptcha-submit" data-callback="recaptcha_submitForm"></div>
  384. <?php
  385. }
  386. ?>
  387. </form>
  388. <a class="btn btn-default" href="<?php echo $hesk_settings['hesk_url']; ?>">
  389. <i class="fa fa-chevron-left"></i> <?php echo $hesklang['back']; ?>
  390. </a>
  391. </div>
  392. </div>
  393. </div>
  394. <?php
  395. hesk_cleanSessionVars('a_iserror');
  396. exit();
  397. } // End print_login()
  398. function logout()
  399. {
  400. global $hesk_settings, $hesklang;
  401. if (!hesk_token_check('GET', 0)) {
  402. print_login();
  403. exit();
  404. }
  405. /* Delete from Who's online database */
  406. if ($hesk_settings['online']) {
  407. require(HESK_PATH . 'inc/users_online.inc.php');
  408. hesk_setOffline($_SESSION['id']);
  409. }
  410. /* Destroy session and cookies */
  411. hesk_session_stop();
  412. /* If we're using the security image for admin login start a new session */
  413. if ($hesk_settings['secimg_use'] == 2) {
  414. hesk_session_start();
  415. }
  416. /* Show success message and reset the cookie */
  417. hesk_process_messages($hesklang['logout_success'], 'NOREDIRECT', 'SUCCESS');
  418. hesk_setcookie('hesk_p', '');
  419. /* Print the login form */
  420. print_login();
  421. exit();
  422. } // End logout()
  423. ?>