2004-11-18 20:01:12 +00:00
|
|
|
<?php
|
2008-08-05 22:43:14 +00:00
|
|
|
// This file is part of BOINC.
|
|
|
|
// http://boinc.berkeley.edu
|
|
|
|
// Copyright (C) 2008 University of California
|
|
|
|
//
|
|
|
|
// BOINC is free software; you can redistribute it and/or modify it
|
|
|
|
// under the terms of the GNU Lesser General Public License
|
|
|
|
// as published by the Free Software Foundation,
|
|
|
|
// either version 3 of the License, or (at your option) any later version.
|
|
|
|
//
|
|
|
|
// BOINC is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
|
|
|
|
// See the GNU Lesser General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Lesser General Public License
|
|
|
|
// along with BOINC. If not, see <http://www.gnu.org/licenses/>.
|
2004-11-18 20:01:12 +00:00
|
|
|
|
2007-07-23 20:30:30 +00:00
|
|
|
// email-related utilities.
|
|
|
|
// Don't put specific message text here.
|
|
|
|
|
2004-11-18 20:01:12 +00:00
|
|
|
require_once("../inc/util.inc");
|
2018-04-17 23:21:57 +00:00
|
|
|
require_once("../inc/token.inc");
|
2004-11-18 20:01:12 +00:00
|
|
|
require_once("../project/project.inc");
|
2018-04-23 20:34:11 +00:00
|
|
|
require_once("../inc/token.inc");
|
2004-11-18 20:01:12 +00:00
|
|
|
|
2009-04-08 17:46:47 +00:00
|
|
|
// send an email, using PHPMailer or not.
|
2006-07-01 20:03:48 +00:00
|
|
|
//
|
2018-04-16 22:23:38 +00:00
|
|
|
function send_email($user, $subject, $body, $body_html=null, $email_addr=null) {
|
2014-04-30 17:36:04 +00:00
|
|
|
if (function_exists("make_php_mailer")) {
|
2018-05-07 23:15:51 +00:00
|
|
|
if (file_exists("../inc/PHPMailer/src/PHPMailer.php") && file_exists("../inc/PHPMailer/src/SMTP.php")) {
|
2018-05-02 18:36:16 +00:00
|
|
|
require_once("../inc/PHPMailer/src/PHPMailer.php");
|
|
|
|
require_once("../inc/PHPMailer/src/SMTP.php");
|
|
|
|
} else if (file_exists("../inc/phpmailer/class.phpmailer.php")) {
|
|
|
|
require_once("../inc/phpmailer/class.phpmailer.php");
|
|
|
|
} else {
|
|
|
|
echo "PHPMailer not installed";
|
|
|
|
return false;
|
|
|
|
}
|
2014-04-30 17:36:04 +00:00
|
|
|
$mail = make_php_mailer();
|
2018-05-07 23:15:51 +00:00
|
|
|
if ($email_addr) {
|
2018-04-16 22:23:38 +00:00
|
|
|
$mail->AddAddress($email_addr, $user->name);
|
|
|
|
} else {
|
|
|
|
$mail->AddAddress($user->email_addr, $user->name);
|
|
|
|
}
|
2005-08-29 23:51:38 +00:00
|
|
|
$mail->Subject = $subject;
|
2006-07-05 21:38:08 +00:00
|
|
|
if ($body_html) {
|
|
|
|
$mail->AltBody = $body;
|
|
|
|
$mail->Body = $body_html;
|
2019-03-13 21:49:45 +00:00
|
|
|
$mail->IsHTML(true);
|
2006-07-05 21:38:08 +00:00
|
|
|
} else {
|
|
|
|
$mail->Body = $body;
|
|
|
|
}
|
2007-12-24 03:45:20 +00:00
|
|
|
if (!$mail->Send()) {
|
2008-05-27 21:26:49 +00:00
|
|
|
echo $mail->ErrorInfo;
|
2007-12-24 03:45:20 +00:00
|
|
|
return false;
|
|
|
|
} else {
|
|
|
|
return true;
|
|
|
|
}
|
2005-08-29 23:51:38 +00:00
|
|
|
} else {
|
2008-04-15 22:42:23 +00:00
|
|
|
$headers ="";
|
|
|
|
if (defined('EMAIL_FROM') && defined('EMAIL_FROM_NAME')) {
|
|
|
|
$headers = "From: ".EMAIL_FROM_NAME." <".EMAIL_FROM.">";
|
|
|
|
} else if (defined('EMAIL_FROM')) {
|
2005-08-29 23:51:38 +00:00
|
|
|
$headers = "From: ". EMAIL_FROM;
|
|
|
|
}
|
2019-03-13 21:49:45 +00:00
|
|
|
if (!$email_addr) {
|
|
|
|
$email_addr = $user->email_addr;
|
|
|
|
}
|
|
|
|
if ($body_html) {
|
2019-03-14 19:10:59 +00:00
|
|
|
$body = "<html><body>\n";
|
2019-05-13 06:39:58 +00:00
|
|
|
$body .= $body_html;
|
2019-03-14 19:10:59 +00:00
|
|
|
$body .= "\n</body></html>\n";
|
2019-04-16 22:59:51 +00:00
|
|
|
$headers .= 'Content-type: text/html; charset=UTF-8' . "\r\n";
|
2018-05-15 19:32:07 +00:00
|
|
|
}
|
2019-03-13 21:49:45 +00:00
|
|
|
return mail($email_addr, $subject, $body, $headers);
|
2005-08-29 23:51:38 +00:00
|
|
|
}
|
|
|
|
}
|
2005-12-19 07:42:40 +00:00
|
|
|
|
2006-07-01 20:03:48 +00:00
|
|
|
// Send an email describing an account to the user.
|
|
|
|
// There are a few scenarios:
|
|
|
|
//
|
|
|
|
// 1) the account was created by user via web.
|
|
|
|
// In this case they're currently looking at the "validate account" page
|
|
|
|
// (account_created.php), although they might have strayed
|
|
|
|
// so we need to give them a link.
|
|
|
|
// 2) the account was created administratively
|
|
|
|
// 3) the user requested account key for existing account
|
|
|
|
//
|
2008-09-25 22:03:56 +00:00
|
|
|
function send_auth_email($user) {
|
2004-12-06 22:41:19 +00:00
|
|
|
$body = "";
|
|
|
|
|
2008-09-25 22:03:56 +00:00
|
|
|
$now = time();
|
|
|
|
$x = md5($user->id.$user->authenticator.$now);
|
|
|
|
$x = substr($x, 0, 16);
|
|
|
|
$subject = PROJECT." account information";
|
2009-04-08 17:46:47 +00:00
|
|
|
$body = "This email was sent in response to a request on the ".PROJECT." web site.
|
2004-11-18 20:01:12 +00:00
|
|
|
|
2007-11-20 00:23:02 +00:00
|
|
|
To log in to your ".PROJECT." account, visit:
|
2015-11-30 08:36:29 +00:00
|
|
|
".secure_url_base()."login_action.php?id=$user->id&t=$now&h=$x
|
2007-11-20 03:08:35 +00:00
|
|
|
(This link is valid for 1 day).
|
2007-11-20 00:23:02 +00:00
|
|
|
After logging in, you can change your account's password or email address.
|
2004-12-06 22:41:19 +00:00
|
|
|
";
|
2004-11-18 20:01:12 +00:00
|
|
|
|
2004-12-06 22:41:19 +00:00
|
|
|
$body .= "
|
2007-11-20 00:23:02 +00:00
|
|
|
For further information and assistance with ".PROJECT.", visit
|
2015-11-30 08:36:29 +00:00
|
|
|
".secure_url_base()."
|
2004-11-18 20:01:12 +00:00
|
|
|
";
|
2011-11-03 02:35:04 +00:00
|
|
|
|
2005-08-29 23:51:38 +00:00
|
|
|
return send_email($user, $subject, $body);
|
2004-11-18 20:01:12 +00:00
|
|
|
}
|
|
|
|
|
2018-04-16 22:23:38 +00:00
|
|
|
function send_changed_email($user) {
|
2018-04-23 19:21:01 +00:00
|
|
|
$duration = TOKEN_DURATION_ONE_WEEK;
|
|
|
|
|
|
|
|
$token = create_token($user->id, TOKEN_TYPE_CHANGE_EMAIL, $duration);
|
|
|
|
|
2018-04-16 22:23:38 +00:00
|
|
|
$subject = PROJECT." email address change.";
|
2018-05-07 23:15:51 +00:00
|
|
|
|
|
|
|
// Body for the new email address to explain how quickly
|
|
|
|
// they can do another email change.
|
|
|
|
//
|
2018-04-16 22:23:38 +00:00
|
|
|
$body_new = "Your email address was changed from ".$user->previous_email_addr.
|
2018-04-19 16:54:33 +00:00
|
|
|
" to ".$user->email_addr." on ".date('F j \a\t g:i a T', $user->email_addr_change_time).
|
2018-04-23 19:21:01 +00:00
|
|
|
". You will not be able to change your email address again until ".date('F j \a\t g:i a T', $user->email_addr_change_time + $duration).
|
2018-04-16 22:23:38 +00:00
|
|
|
". If you need to undo this immediately, please look for an email from us at your ".$user->previous_email_addr." address.";
|
|
|
|
|
2018-05-07 23:15:51 +00:00
|
|
|
// We need to send a different version of the email to the old address.
|
|
|
|
//
|
2018-04-16 22:23:38 +00:00
|
|
|
$body_old = "Your email address has been changed. If you did not take this action,
|
2018-05-08 03:54:28 +00:00
|
|
|
then please click on the link below to reverse this process and change your password.
|
2018-04-16 22:23:38 +00:00
|
|
|
|
2018-04-24 17:56:26 +00:00
|
|
|
".secure_url_base()."recover_email.php?id=".$user->id."&token=".$token."
|
|
|
|
|
|
|
|
Note: Your password will need to be recovered after clicking this link";
|
2018-04-16 22:23:38 +00:00
|
|
|
|
|
|
|
return send_email($user, $subject, $body_new) && send_email($user, $subject, $body_old, null, $user->previous_email_addr);
|
|
|
|
}
|
|
|
|
|
2006-07-01 20:03:48 +00:00
|
|
|
// a valid email address is of the form A@B.C
|
|
|
|
// where A, B, C are nonempty,
|
|
|
|
// A and B don't contain @ or .,
|
2006-10-20 20:33:15 +00:00
|
|
|
// and C doesn't contain @ and is at least 2 chars
|
2006-07-01 20:03:48 +00:00
|
|
|
//
|
2004-11-18 20:01:12 +00:00
|
|
|
function is_valid_email_addr($addr) {
|
2017-07-13 08:17:21 +00:00
|
|
|
if (defined("USE_STOPFORUMSPAM") && USE_STOPFORUMSPAM && array_key_exists('REMOTE_ADDR', $_SERVER)) {
|
2017-07-26 14:14:32 +00:00
|
|
|
$ip = $_SERVER['REMOTE_ADDR'];
|
|
|
|
// For obviously private IPs check just the email against SFS, otherwise check both IP and email
|
|
|
|
if (filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)) {
|
|
|
|
$x = @file_get_contents("https://www.stopforumspam.com/api?ip=".$ip."&email=".$addr);
|
|
|
|
} else {
|
|
|
|
$x = @file_get_contents("https://www.stopforumspam.com/api?email=".$addr);
|
|
|
|
}
|
2014-10-20 03:12:07 +00:00
|
|
|
if (substr_count($x, '<appears>yes</appears>')) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
2006-10-20 20:33:15 +00:00
|
|
|
$pattern = '/^([^@]+)@([^@\.]+)\.([^@]{2,})$/';
|
|
|
|
$match = preg_match($pattern, $addr);
|
|
|
|
return (bool) $match;
|
2004-11-18 20:01:12 +00:00
|
|
|
}
|
|
|
|
|
2018-04-17 23:21:57 +00:00
|
|
|
function send_confirm_delete_email($user) {
|
2018-04-30 19:33:53 +00:00
|
|
|
$token = create_token($user->id, TOKEN_TYPE_DELETE_ACCOUNT, TOKEN_DURATION_ONE_DAY);
|
2018-05-17 14:58:03 +00:00
|
|
|
if ($token === null) {
|
2018-04-17 23:21:57 +00:00
|
|
|
error_page("Error creating token. Please try again later.");
|
|
|
|
}
|
|
|
|
|
|
|
|
$subject = "Confirm your request to delete your account at ".PROJECT;
|
|
|
|
$body = "This email was sent in response to a request on the ".PROJECT." web site.
|
|
|
|
|
|
|
|
You have requested to delete your account at ".PROJECT.". In order to do this, use the following link to confirm your intent to delete your account. ".
|
|
|
|
"The link will take you to a web page where you will be asked to enter your password and complete the process of deleting your account.
|
|
|
|
|
|
|
|
".secure_url_base()."delete_account_confirm.php?id=$user->id&token=$token
|
|
|
|
|
|
|
|
This link is valid for 1 day.
|
|
|
|
|
|
|
|
For further information and assistance with ".PROJECT.", visit ".secure_url_base();
|
|
|
|
|
|
|
|
return send_email($user, $subject, $body);
|
|
|
|
}
|
|
|
|
|
2006-07-05 21:38:08 +00:00
|
|
|
function salted_key($key) {
|
|
|
|
return md5($key.'oogabooga');
|
|
|
|
}
|
|
|
|
|
2019-03-13 21:49:45 +00:00
|
|
|
function opt_out_url($user, $page="opt_out.php") {
|
|
|
|
return sprintf("%s%s?code=%s&userid=%d",
|
|
|
|
secure_url_base(),
|
|
|
|
$page,
|
|
|
|
salted_key($user->authenticator),
|
|
|
|
$user->id
|
|
|
|
);
|
2010-02-03 17:28:03 +00:00
|
|
|
}
|
2004-11-18 20:01:12 +00:00
|
|
|
?>
|