getValues([ ['site.name:s', 'Misuzu'], 'site.desc:s', 'site.url:s', 'eeprom.path:s', 'eeprom.app:s', ['csrf.secret:s', 'soup'], ]); Template::init($msz, $twigCache ?? null, MSZ_DEBUG); Template::set('globals', [ 'site_name' => $globals['site.name'], 'site_description' => $globals['site.desc'], 'site_url' => $globals['site.url'], 'eeprom' => [ 'path' => $globals['eeprom.path'], 'app' => $globals['eeprom.app'], ], ]); $mszAssetsInfo = json_decode(file_get_contents(MSZ_ASSETS . '/current.json')); if(!empty($mszAssetsInfo)) Template::set('assets', $mszAssetsInfo); unset($mszAssetsInfo); Template::addPath(MSZ_TEMPLATES); $tokenPacker = $msz->createAuthTokenPacker(); if(filter_has_var(INPUT_COOKIE, 'msz_auth')) $tokenInfo = $tokenPacker->unpack(filter_input(INPUT_COOKIE, 'msz_auth')); elseif(filter_has_var(INPUT_COOKIE, 'msz_uid') && filter_has_var(INPUT_COOKIE, 'msz_sid')) { $tokenBuilder = new AuthTokenBuilder; $tokenBuilder->setUserId((string)filter_input(INPUT_COOKIE, 'msz_uid', FILTER_SANITIZE_NUMBER_INT)); $tokenBuilder->setSessionToken((string)filter_input(INPUT_COOKIE, 'msz_sid')); $tokenInfo = $tokenBuilder->toInfo(); $tokenBuilder = null; } else $tokenInfo = AuthTokenInfo::empty(); $userInfo = null; $sessionInfo = null; $userInfoReal = null; if($tokenInfo->hasUserId() && $tokenInfo->hasSessionToken()) { $users = $msz->getUsers(); $sessions = $msz->getSessions(); $tokenBuilder = new AuthTokenBuilder($tokenInfo); try { $sessionInfo = $sessions->getSession(sessionToken: $tokenInfo->getSessionToken()); if($sessionInfo->hasExpired()) { $tokenBuilder->removeUserId(); $tokenBuilder->removeSessionToken(); } elseif($sessionInfo->getUserId() === $tokenInfo->getUserId()) { $userInfo = $users->getUser($tokenInfo->getUserId(), 'id'); if($userInfo->isDeleted()) { $tokenBuilder->removeUserId(); $tokenBuilder->removeSessionToken(); } else { $users->recordUserActivity($userInfo, remoteAddr: $_SERVER['REMOTE_ADDR']); $sessions->recordSessionActivity(sessionInfo: $sessionInfo, remoteAddr: $_SERVER['REMOTE_ADDR']); if($sessionInfo->shouldBumpExpires()) $tokenBuilder->setEdited(); if($tokenInfo->hasImpersonatedUserId()) { $allowToImpersonate = $userInfo->isSuperUser(); $impersonatedUserId = $tokenInfo->getImpersonatedUserId(); if(!$allowToImpersonate) { $allowImpersonateUsers = $cfg->getArray(sprintf('impersonate.allow.u%s', $userInfo->getId())); $allowToImpersonate = in_array((string)$impersonatedUserId, $allowImpersonateUsers, true); } if($allowToImpersonate) { $userInfoReal = $userInfo; try { $userInfo = $users->getUser($impersonatedUserId, 'id'); } catch(RuntimeException $ex) { $userInfo = $userInfoReal; $userInfoReal = null; $tokenBuilder->removeImpersonatedUserId(); } } else $tokenBuilder->removeImpersonatedUserId(); } } } } catch(RuntimeException $ex) { $tokenBuilder->removeUserId(); $tokenBuilder->removeSessionToken(); $tokenBuilder->removeImpersonatedUserId(); $userInfo = null; $sessionInfo = null; $userInfoReal = null; } if($tokenBuilder->isEdited()) { $tokenInfo = $tokenBuilder->toInfo(); AuthTokenCookie::apply($tokenPacker->pack($tokenInfo)); } } $msz->getAuthInfo()->setInfo($tokenInfo, $userInfo, $sessionInfo, $userInfoReal); if(!empty($userInfo)) $userInfo = $users->getUser((string)$userInfo->getId(), 'id'); if(!empty($userInfoReal)) $userInfoReal = $users->getUser((string)$userInfoReal->getId(), 'id'); CSRF::init( $globals['csrf.secret'], ($msz->isLoggedIn() ? $sessionInfo->getToken() : $_SERVER['REMOTE_ADDR']) ); if(!empty($userInfo)) { Template::set('current_user', $userInfo); Template::set('current_user_ban_info', $msz->tryGetActiveBan()); } if(!empty($userInfoReal)) { Template::set('current_user_real', $userInfoReal); Template::set('current_user_real_colour', $users->getUserColour($userInfoReal)); } $inManageMode = str_starts_with($_SERVER['REQUEST_URI'], '/manage'); Template::set('header_menu', $msz->getHeaderMenu($userInfo ?? null)); Template::set('user_menu', $msz->getUserMenu($userInfo ?? null, $inManageMode)); Template::set('display_debug_info', MSZ_DEBUG || (!empty($userInfo) && $userInfo->isSuperUser())); if($inManageMode) { $hasManageAccess = false; if($msz->isLoggedIn() && !$msz->hasActiveBan()) { $manageUser = $msz->getActiveUser(); $manageUserId = $manageUser->getId(); if(perms_check_user(MSZ_PERMS_GENERAL, $manageUserId, MSZ_PERM_GENERAL_CAN_MANAGE)) { $hasManageAccess = true; $manageMenu = [ 'General' => [ 'Overview' => url('manage-general-overview'), ], ]; if(perms_check_user(MSZ_PERMS_GENERAL, $manageUserId, MSZ_PERM_GENERAL_VIEW_LOGS)) $manageMenu['General']['Logs'] = url('manage-general-logs'); if(perms_check_user(MSZ_PERMS_GENERAL, $manageUserId, MSZ_PERM_GENERAL_MANAGE_EMOTES)) $manageMenu['General']['Emoticons'] = url('manage-general-emoticons'); if(perms_check_user(MSZ_PERMS_GENERAL, $manageUserId, MSZ_PERM_GENERAL_MANAGE_CONFIG)) $manageMenu['General']['Settings'] = url('manage-general-settings'); if(perms_check_user(MSZ_PERMS_USER, $manageUserId, MSZ_PERM_USER_MANAGE_USERS)) $manageMenu['Users & Roles']['Users'] = url('manage-users'); if(perms_check_user(MSZ_PERMS_USER, $manageUserId, MSZ_PERM_USER_MANAGE_ROLES)) $manageMenu['Users & Roles']['Roles'] = url('manage-roles'); if(perms_check_user(MSZ_PERMS_USER, $manageUserId, MSZ_PERM_USER_MANAGE_NOTES)) $manageMenu['Users & Roles']['Notes'] = url('manage-users-notes'); if(perms_check_user(MSZ_PERMS_USER, $manageUserId, MSZ_PERM_USER_MANAGE_WARNINGS)) $manageMenu['Users & Roles']['Warnings'] = url('manage-users-warnings'); if(perms_check_user(MSZ_PERMS_USER, $manageUserId, MSZ_PERM_USER_MANAGE_BANS)) $manageMenu['Users & Roles']['Bans'] = url('manage-users-bans'); if(perms_check_user(MSZ_PERMS_NEWS, $manageUserId, MSZ_PERM_NEWS_MANAGE_POSTS)) $manageMenu['News']['Posts'] = url('manage-news-posts'); if(perms_check_user(MSZ_PERMS_NEWS, $manageUserId, MSZ_PERM_NEWS_MANAGE_CATEGORIES)) $manageMenu['News']['Categories'] = url('manage-news-categories'); if(perms_check_user(MSZ_PERMS_FORUM, $manageUserId, MSZ_PERM_FORUM_MANAGE_FORUMS)) $manageMenu['Forum']['Permission Calculator'] = url('manage-forum-categories'); if(perms_check_user(MSZ_PERMS_FORUM, $manageUserId, MSZ_PERM_FORUM_TOPIC_REDIRS)) $manageMenu['Forum']['Topic Redirects'] = url('manage-forum-topic-redirs'); if(perms_check_user(MSZ_PERMS_CHANGELOG, $manageUserId, MSZ_PERM_CHANGELOG_MANAGE_CHANGES)) $manageMenu['Changelog']['Changes'] = url('manage-changelog-changes'); if(perms_check_user(MSZ_PERMS_CHANGELOG, $manageUserId, MSZ_PERM_CHANGELOG_MANAGE_TAGS)) $manageMenu['Changelog']['Tags'] = url('manage-changelog-tags'); Template::set('manage_menu', $manageMenu); } } if(!$hasManageAccess) { echo render_error(403); exit; } } $mszRequestPath = $request->getPath(); $mszLegacyPathPrefix = MSZ_PUBLIC . '-legacy/'; $mszLegacyPath = realpath($mszLegacyPathPrefix . $mszRequestPath); if(!empty($mszLegacyPath) && str_starts_with($mszLegacyPath, $mszLegacyPathPrefix)) { if(is_dir($mszLegacyPath)) $mszLegacyPath .= '/index.php'; if(is_file($mszLegacyPath)) { require_once $mszLegacyPath; return; } } $msz->setUpHttp(); $msz->dispatchHttp($request);