jasteele123

concrete5 Login only IP(s) Allowed override (5.6)

Aug 18th, 2014
316
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.15 KB | None | 0 0
  1. <?php /* controllers/login.php - override to only allow certain IPs to login */
  2. defined('C5_EXECUTE') or die('Access Denied.');
  3. /**
  4. concrete5 Login only IPs Allowed override (concrete5 5.6+)
  5.     Overrides the concrete5 concrete/controllers/login.php to only allow certain IP(s) to access the login page
  6. Usage
  7.     Copy login.php to controllers/login.php NOT concrete/controllers/login.php
  8.     Uncomment and Edit the define for LOGIN_ONLY_IPS - or move it to config/site.php
  9.     If the remote IP is not in the list, they will receive an Access Denied message instead of the login form.
  10. Notes
  11.     Make sure the Overrides Cache is turned off until you get it working
  12.     See the comments for additional/optional customization.
  13. Contact
  14.     John Steele - Steelesoft Consulting
  15.     http://steelesoftconsulting.com/    http://steelesoft.net/concrete5
  16.     https://www.oncrete5.org/profile/-/view/13433/
  17. **/
  18.  
  19.     // you could put one of these in config/site.php instead (only one define is allowed of course)
  20. // define('LOGIN_ONLY_IPS', '192.168.1.2,192.168.1.3');     // IPs allowed to login, comma separated list
  21. // define('LOGIN_ONLY_IPS', '75.170.15.217');           // IP allowed to login, single example
  22.  
  23. if (defined('LOGIN_ONLY_IPS')) {
  24.     $ip = Loader::helper('validation/ip');
  25.     $remote = $ip->getRequestIP();  // $remote = $_SERVER['REMOTE_ADDR'];
  26.     // die('Current IP: '. $remote);    // uncomment to make sure the override is working, showing IP Address
  27.     $login_ips = explode(',', LOGIN_ONLY_IPS);
  28.         // die('<pre>'. print_r($login_ips, 1). '</pre>');
  29.     $can_login = false;
  30.         // check if they are allowed to login
  31.     foreach($login_ips as $login) {
  32.         if ($remote == $login) {
  33.             $can_login = true;
  34.         }
  35.     }
  36.     if (!$can_login) {
  37. /*          // optionally log, bad idea if your site is being attacked
  38.         $log = new Log('login_attempt', true);
  39.         $log->write('Login attempted from '. $remote);
  40.         $log->close();
  41. */
  42. /*          // this might also add to the exception log
  43.         throw new Exception(t('IP Address not Allowed'));
  44. */
  45.         die('<h2>Access Denied</h2>');
  46.     }
  47. }
  48.  
  49. class LoginController extends Concrete5_Controller_Login { }
Advertisement
Add Comment
Please, Sign In to add comment