Merge branch 'MDL-51261-master-upgradekey' of git://github.com/mudrd8mz/moodle
This commit is contained in:
@@ -256,6 +256,10 @@ function install_generate_configphp($database, $cfg) {
|
||||
}
|
||||
$configphp .= '$CFG->directorypermissions = ' . $chmod . ';' . PHP_EOL . PHP_EOL;
|
||||
|
||||
if (isset($cfg->upgradekey) and $cfg->upgradekey !== '') {
|
||||
$configphp .= '$CFG->upgradekey = ' . var_export($cfg->upgradekey, true) . ';' . PHP_EOL . PHP_EOL;
|
||||
}
|
||||
|
||||
$configphp .= 'require_once(dirname(__FILE__) . \'/lib/setup.php\');' . PHP_EOL . PHP_EOL;
|
||||
$configphp .= '// There is no php closing tag in this file,' . PHP_EOL;
|
||||
$configphp .= '// it is intentional because it prevents trailing whitespace problems!' . PHP_EOL;
|
||||
|
||||
@@ -2342,3 +2342,32 @@ function upgrade_minmaxgrade() {
|
||||
}
|
||||
$rs->close();
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Assert the upgrade key is provided, if it is defined.
|
||||
*
|
||||
* The upgrade key can be defined in the main config.php as $CFG->upgradekey. If
|
||||
* it is defined there, then its value must be provided every time the site is
|
||||
* being upgraded, regardless the administrator is logged in or not.
|
||||
*
|
||||
* This is supposed to be used at certain places in /admin/index.php only.
|
||||
*
|
||||
* @param string|null $upgradekeyhash the SHA-1 of the value provided by the user
|
||||
*/
|
||||
function check_upgrade_key($upgradekeyhash) {
|
||||
global $CFG, $PAGE;
|
||||
|
||||
if (isset($CFG->config_php_settings['upgradekey'])) {
|
||||
if ($upgradekeyhash === null or $upgradekeyhash !== sha1($CFG->config_php_settings['upgradekey'])) {
|
||||
if (!$PAGE->headerprinted) {
|
||||
$output = $PAGE->get_renderer('core', 'admin');
|
||||
echo $output->upgradekey_form_page(new moodle_url('/admin/index.php', array('cache' => 0)));
|
||||
die();
|
||||
} else {
|
||||
// This should not happen.
|
||||
die('Upgrade locked');
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user