Merge pull request #1 from zered/solve_741

Solving the "Disallow public access to addons listed in the apps menu" h...
This commit is contained in:
Zered 2013-08-02 10:57:20 -07:00
commit a0a25d0fcb
2 changed files with 34 additions and 6 deletions

View file

@ -185,6 +185,21 @@ function call_hooks($name, &$data = null) {
} }
}} }}
//check if an app_menu hook exist for plugin $name.
//Return true if the plugin is an app
if(! function_exists('plugin_is_app')) {
function plugin_is_app($name) {
$a = get_app();
if(is_array($a->hooks) && (array_key_exists('app_menu',$a->hooks))) {
foreach($a->hooks['app_menu'] as $hook) {
if($hook[0] == 'addon/'.$name.'/'.$name.'.php')
return true;
}
}
return false;
}}
/* /*
* parse plugin comment in search of plugin infos. * parse plugin comment in search of plugin infos.

View file

@ -149,11 +149,16 @@ else {
nav_set_selected('nothing'); nav_set_selected('nothing');
$arr = array('app_menu' => $a->apps); //Don't populate apps_menu if apps are private
$privateapps = get_config('config','private_addons');
if((local_user()) || (! $privateapps === "1"))
{
$arr = array('app_menu' => $a->apps);
call_hooks('app_menu', $arr); call_hooks('app_menu', $arr);
$a->apps = $arr['app_menu']; $a->apps = $arr['app_menu'];
}
/** /**
* *
@ -186,11 +191,19 @@ if(strlen($a->module)) {
// Compatibility with the Android Diaspora client // Compatibility with the Android Diaspora client
if ($a->module == "stream") if ($a->module == "stream")
$a->module = "network"; $a->module = "network";
$privateapps = get_config('config','private_addons');
if(is_array($a->plugins) && in_array($a->module,$a->plugins) && file_exists("addon/{$a->module}/{$a->module}.php")) { if(is_array($a->plugins) && in_array($a->module,$a->plugins) && file_exists("addon/{$a->module}/{$a->module}.php")) {
include_once("addon/{$a->module}/{$a->module}.php"); //Check if module is an app and if public access to apps is allowed or not
if(function_exists($a->module . '_module')) if((!local_user()) && plugin_is_app($a->module) && $privateapps === "1") {
$a->module_loaded = true; info( t("You must be logged in to use addons. "));
}
else {
include_once("addon/{$a->module}/{$a->module}.php");
if(function_exists($a->module . '_module'))
$a->module_loaded = true;
}
} }
/** /**