Rev 866 | Rev 974 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed
Rev | Author | Line No. | Line |
---|---|---|---|
2 | daniel-mar | 1 | <?php |
2 | |||
3 | /* |
||
4 | * OIDplus 2.0 |
||
773 | daniel-mar | 5 | * Copyright 2019 - 2022 Daniel Marschall, ViaThinkSoft |
2 | daniel-mar | 6 | * |
7 | * Licensed under the Apache License, Version 2.0 (the "License"); |
||
8 | * you may not use this file except in compliance with the License. |
||
9 | * You may obtain a copy of the License at |
||
10 | * |
||
11 | * http://www.apache.org/licenses/LICENSE-2.0 |
||
12 | * |
||
13 | * Unless required by applicable law or agreed to in writing, software |
||
14 | * distributed under the License is distributed on an "AS IS" BASIS, |
||
15 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
||
16 | * See the License for the specific language governing permissions and |
||
17 | * limitations under the License. |
||
18 | */ |
||
19 | |||
207 | daniel-mar | 20 | header('Content-Type:text/html; charset=UTF-8'); |
2 | daniel-mar | 21 | |
207 | daniel-mar | 22 | require_once __DIR__ . '/includes/oidplus.inc.php'; |
23 | |||
366 | daniel-mar | 24 | set_exception_handler(array('OIDplusGui', 'html_exception_handler')); |
240 | daniel-mar | 25 | |
207 | daniel-mar | 26 | ob_start(); // allow cookie headers to be sent |
27 | |||
120 | daniel-mar | 28 | OIDplus::init(true); |
29 | |||
30 | $static_node_id = isset($_REQUEST['goto']) ? $_REQUEST['goto'] : 'oidplus:system'; |
||
773 | daniel-mar | 31 | |
946 | daniel-mar | 32 | if (isset($_REQUEST['h404'])) { |
33 | $handled = false; |
||
34 | $plugins = OIDplus::getPagePlugins(); |
||
35 | foreach ($plugins as $plugin) { |
||
36 | if ($plugin->handle404($_REQUEST['h404'])) $handled = true; |
||
37 | } |
||
38 | if (!$handled) { |
||
39 | header('Location:'.OIDplus::webpath().'?goto='.urlencode('oidplus:err:'.$_REQUEST['h404'])); |
||
40 | die(); |
||
41 | } |
||
42 | } |
||
43 | |||
775 | daniel-mar | 44 | $static_node_id = OIDplus::prefilterQuery($static_node_id, false); |
773 | daniel-mar | 45 | |
558 | daniel-mar | 46 | $static = OIDplus::gui()->generateContentPage($static_node_id); |
120 | daniel-mar | 47 | $static_title = $static['title']; |
48 | $static_icon = $static['icon']; |
||
49 | $static_content = $static['text']; |
||
50 | |||
564 | daniel-mar | 51 | if (!isset($_COOKIE['csrf_token'])) { |
866 | daniel-mar | 52 | // TODO: It is possible that you receive a "Missing or wrong CSRF Token" warning, |
53 | // if you open a page that had a HTTPS cookie using HTTP. |
||
54 | // Chrome will then block "Set-Cookie" since the HTTP cookie would |
||
55 | // overwrite the HTTPS cookie. |
||
564 | daniel-mar | 56 | // This is the main CSRF token used for AJAX. |
57 | $token = OIDplus::authUtils()->genCSRFToken(); |
||
58 | OIDplus::cookieUtils()->setcookie('csrf_token', $token, 0, false); |
||
59 | unset($token); |
||
60 | } |
||
61 | |||
62 | if (!isset($_COOKIE['csrf_token_weak'])) { |
||
63 | // This CSRF token is created with SameSite=Lax and must be used |
||
64 | // for OAuth 2.0 redirects or similar purposes. |
||
65 | $token = OIDplus::authUtils()->genCSRFToken(); |
||
66 | OIDplus::cookieUtils()->setcookie('csrf_token_weak', $token, 0, false, 'Lax'); |
||
67 | unset($token); |
||
68 | } |
||
69 | |||
362 | daniel-mar | 70 | OIDplus::handleLangArgument(); |
71 | |||
120 | daniel-mar | 72 | function combine_systemtitle_and_pagetitle($systemtitle, $pagetitle) { |
309 | daniel-mar | 73 | // Please also change the function in oidplus_base.js |
120 | daniel-mar | 74 | if ($systemtitle == $pagetitle) { |
75 | return $systemtitle; |
||
76 | } else { |
||
309 | daniel-mar | 77 | return $pagetitle . ' - ' . $systemtitle; |
120 | daniel-mar | 78 | } |
5 | daniel-mar | 79 | } |
120 | daniel-mar | 80 | |
819 | daniel-mar | 81 | // Get theme color (color of title bar) |
82 | $design_plugin = OIDplus::getActiveDesignPlugin(); |
||
83 | $theme_color = is_null($design_plugin) ? '' : $design_plugin->getThemeColor(); |
||
142 | daniel-mar | 84 | |
819 | daniel-mar | 85 | $head_elems = array(); |
86 | $head_elems[] = '<meta http-equiv="Content-Type" content="text/html; charset=utf-8">'; |
||
87 | $head_elems[] = '<meta name="OIDplus-SystemTitle" content="'.htmlentities(OIDplus::config()->getValue('system_title')).'">'; // Do not remove. This meta tag is acessed by oidplus_base.js |
||
821 | daniel-mar | 88 | if ($theme_color != '') $head_elems[] = '<meta name="theme-color" content="'.htmlentities($theme_color).'">'; |
819 | daniel-mar | 89 | $head_elems[] = '<meta name="viewport" content="width=device-width, initial-scale=1.0">'; |
90 | $head_elems[] = '<title>'.htmlentities(combine_systemtitle_and_pagetitle(OIDplus::config()->getValue('system_title'), $static_title)).'</title>'; |
||
91 | $head_elems[] = '<script src="polyfill.min.js.php"></script>'; |
||
92 | $head_elems[] = OIDplus::getActiveCaptchaPlugin()->captchaDomHead(); |
||
93 | $head_elems[] = '<script src="oidplus.min.js.php"></script>'; |
||
94 | $head_elems[] = '<link rel="stylesheet" href="oidplus.min.css.php">'; |
||
95 | $head_elems[] = '<link rel="shortcut icon" type="image/x-icon" href="favicon.ico.php">'; |
||
821 | daniel-mar | 96 | $head_elems[] = '<link rel="canonical" href="'.htmlentities(OIDplus::canonicalURL()).'">'; |
819 | daniel-mar | 97 | |
98 | $plugins = OIDplus::getPagePlugins(); |
||
767 | daniel-mar | 99 | foreach ($plugins as $plugin) { |
819 | daniel-mar | 100 | $plugin->htmlHeaderUpdate($head_elems); |
767 | daniel-mar | 101 | } |
102 | |||
819 | daniel-mar | 103 | // --- |
120 | daniel-mar | 104 | |
820 | daniel-mar | 105 | echo "<!DOCTYPE html>\n"; |
120 | daniel-mar | 106 | |
820 | daniel-mar | 107 | echo "<html lang=\"".substr(OIDplus::getCurrentLang(),0,2)."\">\n"; |
108 | echo "<head>\n"; |
||
109 | echo "\t".implode("\n\t",$head_elems)."\n"; |
||
110 | echo "</head>\n"; |
||
120 | daniel-mar | 111 | |
820 | daniel-mar | 112 | echo "<body>\n"; |
113 | |||
819 | daniel-mar | 114 | echo '<div id="loading" style="display:none">Loading…</div>'; |
215 | daniel-mar | 115 | |
819 | daniel-mar | 116 | echo '<div id="frames">'; |
117 | echo '<div id="content_window" class="borderbox">'; |
||
120 | daniel-mar | 118 | |
819 | daniel-mar | 119 | echo '<h1 id="real_title">'; |
120 | if ($static_icon != '') echo '<img src="'.htmlentities($static_icon).'" width="48" height="48" alt=""> '; |
||
121 | echo htmlentities($static_title).'</h1>'; |
||
122 | echo '<div id="real_content">'.$static_content.'</div>'; |
||
123 | if ((!isset($_SERVER['REQUEST_METHOD'])) || ($_SERVER['REQUEST_METHOD'] == 'GET')) { |
||
124 | echo '<br><p><img src="img/share.png" width="15" height="15" alt="'._L('Share').'"> <a href="?goto='.htmlentities($static_node_id).'" id="static_link" class="gray_footer_font">'._L('Static link to this page').'</a>'; |
||
125 | echo '</p>'; |
||
126 | } |
||
127 | echo '<br>'; |
||
532 | daniel-mar | 128 | |
819 | daniel-mar | 129 | echo '</div>'; |
126 | daniel-mar | 130 | |
819 | daniel-mar | 131 | echo '<div id="system_title_bar">'; |
126 | daniel-mar | 132 | |
819 | daniel-mar | 133 | echo '<div id="system_title_menu" onclick="mobileNavButtonClick(this)" onmouseenter="mobileNavButtonHover(this)" onmouseleave="mobileNavButtonHover(this)">'; |
134 | echo ' <div id="bar1"></div>'; |
||
135 | echo ' <div id="bar2"></div>'; |
||
136 | echo ' <div id="bar3"></div>'; |
||
137 | echo '</div>'; |
||
183 | daniel-mar | 138 | |
819 | daniel-mar | 139 | echo '<div id="system_title_text">'; |
140 | echo ' <a '.OIDplus::gui()->link('oidplus:system').' id="system_title_a">'; |
||
141 | echo ' <span id="system_title_logo"></span>'; |
||
822 | daniel-mar | 142 | echo ' <span id="system_title_1">'.htmlentities(OIDplus::getEditionInfo()['vendor'].' OIDplus 2.0').'</span><br>'; |
819 | daniel-mar | 143 | echo ' <span id="system_title_2">'.htmlentities(OIDplus::config()->getValue('system_title')).'</span>'; |
144 | echo ' </a>'; |
||
145 | echo '</div>'; |
||
355 | daniel-mar | 146 | |
819 | daniel-mar | 147 | echo '</div>'; |
186 | daniel-mar | 148 | |
819 | daniel-mar | 149 | echo OIDplus::gui()->getLanguageBox($static_node_id, true); |
120 | daniel-mar | 150 | |
819 | daniel-mar | 151 | echo '<div id="gotobox">'; |
152 | echo '<input type="text" name="goto" id="gotoedit" value="'.htmlentities($static_node_id).'">'; |
||
153 | echo '<input type="button" value="'._L('Go').'" onclick="gotoButtonClicked()" id="gotobutton">'; |
||
154 | echo '</div>'; |
||
120 | daniel-mar | 155 | |
819 | daniel-mar | 156 | echo '<div id="oidtree" class="borderbox">'; |
157 | //echo '<noscript>'; |
||
158 | //echo '<p><b>'._L('Please enable JavaScript to use all features').'</b></p>'; |
||
159 | //echo '</noscript>'; |
||
160 | OIDplus::menuUtils()->nonjs_menu(); |
||
161 | echo '</div>'; |
||
162 | |||
163 | echo '</div>'; |
||
164 | |||
820 | daniel-mar | 165 | echo "\n</body>\n"; |
166 | echo "</html>\n"; |
||
819 | daniel-mar | 167 | |
120 | daniel-mar | 168 | $cont = ob_get_contents(); |
169 | ob_end_clean(); |
||
170 | |||
639 | daniel-mar | 171 | OIDplus::invoke_shutdown(); |
172 | |||
821 | daniel-mar | 173 | $plugins = OIDplus::getPagePlugins(); |
174 | foreach ($plugins as $plugin) { |
||
175 | $plugin->htmlPostprocess($cont); |
||
176 | } |
||
177 | |||
366 | daniel-mar | 178 | echo $cont; |