X-Git-Url: https://git.heureux-cyclage.org/?a=blobdiff_plain;f=index.php;h=bc527799cb0f7cce6f7384ae266ed0813c0d3bd8;hb=3ee18afd7166dd9765d84bdc3166e5016375260f;hp=045b0a114ce87f1c7692b007d1e8ae0ac79b6ec6;hpb=67e6306a0edb75840a4ce3d2c604a748983980b0;p=lhc%2Fweb%2Fwiklou.git diff --git a/index.php b/index.php index 045b0a114c..bc527799cb 100644 --- a/index.php +++ b/index.php @@ -1,215 +1,118 @@ set the wiki up first!" ); +@ini_set( 'allow_url_fopen', 0 ); # For security... + +if ( isset( $_REQUEST['GLOBALS'] ) ) { + die( '$GLOBALS overwrite vulnerability'); } # Valid web server entry point, enable includes. -# Please don't move this line to includes/Defines.php. This line essentially defines -# a valid entry point. If you put it in includes/Defines.php, then any script that includes -# it becomes an entry point, thereby defeating its purpose. -define( "MEDIAWIKI", true ); +# Please don't move this line to includes/Defines.php. This line essentially +# defines a valid entry point. If you put it in includes/Defines.php, then +# any script that includes it becomes an entry point, thereby defeating +# its purpose. +define( 'MEDIAWIKI', true ); + +# Load up some global defines. +require_once( './includes/Defines.php' ); + +# LocalSettings.php is the per site customization file. If it does not exit +# the wiki installer need to be launched or the generated file moved from +# ./config/ to ./ +if( !file_exists( 'LocalSettings.php' ) ) { + $IP = '.'; + require_once( 'includes/DefaultSettings.php' ); # used for printing the version +?> + + + + MediaWiki <?php echo $wgVersion ?> + + + + + The MediaWiki logo + +

MediaWiki

+
+ config/LocalSettings.php to the parent directory.' ); + } else { + echo( 'Please setup the wiki first.' ); + } + ?> -wfProfileIn( "main-misc-setup" ); -OutputPage::setEncodings(); # Not really used yet +
+ + +getVal( "action", "view" ); +# Include this site setttings +require_once( './LocalSettings.php' ); +# Prepare MediaWiki +require_once( 'includes/Setup.php' ); -if( isset( $_SERVER['PATH_INFO'] ) && $wgUsePathInfo ) { - $title = substr( $_SERVER['PATH_INFO'], 1 ); -} else { - $title = $wgRequest->getVal( "title" ); -} +# Initialize MediaWiki base class +require_once( "includes/Wiki.php" ); +$mediaWiki = new MediaWiki(); -# Placeholders in case of DB error -$wgTitle = Title::newFromText( wfMsg( "badtitle" ) ); -$wgArticle = new Article($wgTitle); +wfProfileIn( 'main-misc-setup' ); +OutputPage::setEncodings(); # Not really used yet -$action = strtolower( trim( $action ) ); -if ($wgRequest->getVal( "printable" ) == "yes") { - $wgOut->setPrintable(); -} +# Query string fields +$action = $wgRequest->getVal( 'action', 'view' ); +$title = $wgRequest->getVal( 'title' ); -if ( "" == $title && "delete" != $action ) { - $wgTitle = Title::newFromText( wfMsg( "mainpage" ) ); -} elseif ( $curid = $wgRequest->getInt( 'curid' ) ) { - # URLs like this are generated by RC, because rc_title isn't always accurate - $wgTitle = Title::newFromID( $curid ); -} else { - $wgTitle = Title::newFromURL( $title ); -} -wfProfileOut( "main-misc-setup" ); - -# If the user is not logged in, the Namespace:title of the article must be in -# the Read array in order for the user to see it. (We have to check here to -# catch special pages etc. We check again in Article::view()) -if ( !is_null( $wgTitle ) && !$wgTitle->userCanRead() ) { - $wgOut->loginToUse(); - $wgOut->output(); - exit; +$wgTitle = $mediaWiki->checkInitialQueries( $title,$action,$wgOut, $wgRequest, $wgContLang ); +if ($wgTitle == NULL) { + unset( $wgTitle ); } -wfProfileIn( "main-action" ); -$search = $wgRequest->getText( 'search' ); -if( !is_null( $search ) && $search !== '' ) { - require_once( 'SearchEngine.php' ); - $wgTitle = Title::makeTitle( NS_SPECIAL, "Search" ); - $searchEngine = new SearchEngine( $search ); - if( $wgRequest->getVal( 'fulltext' ) || - !is_null( $wgRequest->getVal( 'offset' ) ) || - !is_null ($wgRequest->getVal( 'searchx' ) ) ) { - $searchEngine->showResults(); - } else { - $searchEngine->goResult(); - } -} else if( !$wgTitle or $wgTitle->getDBkey() == "" ) { - $wgTitle = Title::newFromText( wfMsg( "badtitle" ) ); - $wgOut->errorpage( "badtitle", "badtitletext" ); -} else if ( $wgTitle->getInterwiki() != "" ) { - $url = $wgTitle->getFullURL(); - # Check for a redirect loop - if ( !preg_match( "/^" . preg_quote( $wgServer, "/" ) . "/", $url ) && $wgTitle->isLocal() ) { - $wgOut->redirect( $url ); - } else { - $wgTitle = Title::newFromText( wfMsg( "badtitle" ) ); - $wgOut->errorpage( "badtitle", "badtitletext" ); - } -} else if ( ( $action == "view" ) && $wgTitle->getPrefixedDBKey() != $title && - !count( array_diff( array_keys( $_GET ), array( 'action', 'title' ) ) ) ) -{ - /* redirect to canonical url, make it a 301 to allow caching */ - $wgOut->redirect( $wgTitle->getFullURL(), '301'); -} else if ( Namespace::getSpecial() == $wgTitle->getNamespace() ) { - # actions that need to be made when we have a special pages - require_once( 'includes/SpecialPage.php' ); - if ( !$wgAllowSysopQueries ) {SpecialPage::removePage( 'Asksql' ); } - SpecialPage::executePath( $wgTitle ); -} else { - if ( Namespace::getMedia() == $wgTitle->getNamespace() ) { - $wgTitle = Title::makeTitle( NS_IMAGE, $wgTitle->getDBkey() ); - } - - switch( $wgTitle->getNamespace() ) { - case NS_IMAGE: - require_once( "includes/ImagePage.php" ); - $wgArticle = new ImagePage( $wgTitle ); - break; - case NS_CATEGORY: - if ( $wgUseCategoryMagic ) { - require_once( "includes/CategoryPage.php" ); - $wgArticle = new CategoryPage( $wgTitle ); - break; - } - # NO break if wgUseCategoryMagic is false, drop through to next (default). - # Don't insert other cases between NS_CATEGORY and default. - default: - $wgArticle = new Article( $wgTitle ); - } - - switch( $action ) { - case "view": - $wgOut->setSquidMaxage( $wgSquidMaxage ); - $wgArticle->view(); - break; - case "watch": - case "unwatch": - case "delete": - case "revert": - case "rollback": - case "protect": - case "unprotect": - case "validate": - case "info": - case "markpatrolled": - $wgArticle->$action(); - break; - case "print": - $wgArticle->view(); - break; - case "dublincore": - if( !$wgEnableDublinCoreRdf ) { - wfHttpError( 403, "Forbidden", wfMsg( "nodublincore" ) ); - } else { - require_once( "includes/Metadata.php" ); - wfDublinCoreRdf( $wgArticle ); - } - break; - case "creativecommons": - if( !$wgEnableCreativeCommonsRdf ) { - wfHttpError( 403, "Forbidden", wfMsg("nocreativecommons") ); - } else { - require_once( "includes/Metadata.php" ); - wfCreativeCommonsRdf( $wgArticle ); - } - break; - case "credits": - require_once( "includes/Credits.php" ); - showCreditsPage( $wgArticle ); - break; - case "edit": - case "submit": - if( !$wgCommandLineMode && !$wgRequest->checkSessionCookie() ) { - User::SetupSession(); - } - require_once( "includes/EditPage.php" ); - $editor = new EditPage( $wgArticle ); - $editor->submit(); - break; - case "history": - if ($_SERVER["REQUEST_URI"] == $wgTitle->getInternalURL('action=history')) { - $wgOut->setSquidMaxage( $wgSquidMaxage ); - } - require_once( "includes/PageHistory.php" ); - $history = new PageHistory( $wgArticle ); - $history->history(); - break; - case "raw": - require_once( "includes/RawPage.php" ); - $raw = new RawPage( $wgArticle ); - $raw->view(); - break; - case "purge": - wfPurgeSquidServers(array($wgTitle->getInternalURL())); - $wgOut->setSquidMaxage( $wgSquidMaxage ); - $wgTitle->invalidateCache(); - $wgArticle->view(); - break; - default: - $wgOut->errorpage( "nosuchaction", "nosuchactiontext" ); - } -} -wfProfileOut( "main-action" ); - -# Deferred updates aren't really deferred anymore. It's important to report errors to the -# user, and that means doing this before OutputPage::output(). Note that for page saves, -# the client will wait until the script exits anyway before following the redirect. -wfProfileIn( "main-updates" ); -foreach ( $wgDeferredUpdateList as $up ) { - $up->doUpdate(); -} -wfProfileOut( "main-updates" ); +wfProfileOut( 'main-misc-setup' ); -wfProfileIn( "main-cleanup" ); -$wgLoadBalancer->saveMasterPos(); +# Setting global variables in mediaWiki +$mediaWiki->setVal( 'Server', $wgServer ); +$mediaWiki->setVal( 'DisableInternalSearch', $wgDisableInternalSearch ); +$mediaWiki->setVal( 'action', $action ); +$mediaWiki->setVal( 'SquidMaxage', $wgSquidMaxage ); +$mediaWiki->setVal( 'EnableDublinCoreRdf', $wgEnableDublinCoreRdf ); +$mediaWiki->setVal( 'EnableCreativeCommonsRdf', $wgEnableCreativeCommonsRdf ); +$mediaWiki->setVal( 'CommandLineMode', $wgCommandLineMode ); +$mediaWiki->setVal( 'UseExternalEditor', $wgUseExternalEditor ); +$mediaWiki->setVal( 'DisabledActions', $wgDisabledActions ); -# Now commit any transactions, so that unreported errors after output() don't roll back the whole thing -$wgLoadBalancer->commitAll(); +$wgArticle = $mediaWiki->initialize ( $wgTitle, $wgOut, $wgUser, $wgRequest ); +$mediaWiki->finalCleanup ( $wgDeferredUpdateList, $wgLoadBalancer, $wgOut ); -$wgOut->output(); -wfProfileOut( "main-cleanup" ); +# Not sure when $wgPostCommitUpdateList gets set, so I keep this separate from finalCleanup +$mediaWiki->doUpdates( $wgPostCommitUpdateList ); -logProfilingData(); -$wgLoadBalancer->closeAll(); -wfDebug( "Request ended normally\n" ); +$mediaWiki->restInPeace( $wgLoadBalancer ); ?>