From f515729ccf076d5506a27755b0b1f4a0cb2c82fe Mon Sep 17 00:00:00 2001 From: William Jacoby Date: Thu, 3 Sep 2026 18:11:54 -0500 Subject: [PATCH 1/2] Add ACP option to allow HTTP for Stop Forum Spam reports Defaults to HTTPS (bh_sfs_allow_http = 0), matching the fix in #29. An admin whose server can't make outbound HTTPS requests can opt into HTTP explicitly in the ACP; the setting is off by default and the ACP label spells out what enabling it actually sends in clear text. Builds on the not-yet-merged fix-bh-res-xss branch (#29), which is where the HTTPS-only SFS request this adds a toggle for was fixed. Co-Authored-By: Claude Sonnet 5 --- adm/style/banhammer_body.html | 7 +++++++ controller/admin_controller.php | 6 ++++-- event/banhammer_listener.php | 6 ++++-- language/en/banhammer_acp.php | 2 ++ migrations/v105_data.php | 32 ++++++++++++++++++++++++++++++++ 5 files changed, 49 insertions(+), 4 deletions(-) create mode 100644 migrations/v105_data.php diff --git a/adm/style/banhammer_body.html b/adm/style/banhammer_body.html index fcc8f1b..14f808e 100644 --- a/adm/style/banhammer_body.html +++ b/adm/style/banhammer_body.html @@ -75,6 +75,13 @@

{L_ACP_BH_SETTINGS}

+
+

{L_SFS_ALLOW_HTTP_EXPLAIN}
+
+   + +
+

  diff --git a/controller/admin_controller.php b/controller/admin_controller.php index 0da6c55..1a1ade8 100644 --- a/controller/admin_controller.php +++ b/controller/admin_controller.php @@ -109,8 +109,9 @@ public function display_options() 'DEL_PROFILE' => (!empty($this->config['bh_del_profile'])) ? true : false, 'DEL_SIGNATURE' => (!empty($this->config['bh_del_signature'])) ? true : false, 'MOVE_GROUP' => $this->get_groups($this->request->variable('move_group', $this->config['bh_group_id'])), - 'SFS_API_KEY' => (!empty($this->config['bh_sfs_api_key'])) ? $this->config['bh_sfs_api_key'] : '', - 'SFS_CURL' => (function_exists('curl_init')) ? true : false, + 'SFS_ALLOW_HTTP' => (!empty($this->config['bh_sfs_allow_http'])) ? true : false, + 'SFS_API_KEY' => (!empty($this->config['bh_sfs_api_key'])) ? $this->config['bh_sfs_api_key'] : '', + 'SFS_CURL' => (function_exists('curl_init')) ? true : false, 'U_ACTION' => $this->u_action, )); @@ -133,6 +134,7 @@ protected function set_options() $this->config->set('bh_del_signature', $this->request->variable('del_signature', 0)); $this->config->set('bh_group_id', $this->request->variable('move_group', 0)); $this->config->set('bh_sfs_api_key', $this->request->variable('sfs_api_key', '', true)); + $this->config->set('bh_sfs_allow_http', $this->request->variable('sfs_allow_http', 0)); $this->config->set('bh_ban_time', $this->request->variable('ban_time', 0)); } diff --git a/event/banhammer_listener.php b/event/banhammer_listener.php index df8c1c8..eb02142 100644 --- a/event/banhammer_listener.php +++ b/event/banhammer_listener.php @@ -416,8 +416,10 @@ public function do_ban_hammer_stuff($event) if ($this->request->variable('sfs_report', 0) && !empty($this->config['bh_sfs_api_key']) && $curl_exists) { - // add the spammer to the SFS database - $http_request = 'https://www.stopforumspam.com/add.php'; + // add the spammer to the SFS database. HTTPS unless the admin + // has explicitly opted into HTTP for it in the ACP. + $sfs_scheme = (!empty($this->config['bh_sfs_allow_http'])) ? 'http://' : 'https://'; + $http_request = $sfs_scheme . 'www.stopforumspam.com/add.php'; $http_request .= '?username=' . urlencode($this->data['username']); $http_request .= '&ip_addr=' . urlencode($this->data['user_ip']); $http_request .= '&email=' . urlencode($this->data['user_email']); diff --git a/language/en/banhammer_acp.php b/language/en/banhammer_acp.php index d6001c4..54b10df 100644 --- a/language/en/banhammer_acp.php +++ b/language/en/banhammer_acp.php @@ -49,6 +49,8 @@ 'ACP_MOVE_GROUP' => 'Move to group', 'ACP_MOVE_GROUP_EXPLAIN' => 'Name of the group to which banned users should be moved. This will also be their default group.
If nothing but “No group specified.” is in the drop down then you have not set up any groups.', 'BAN_LENGTH_EXPLAIN' => 'If either of the ban options is set then the user will be banned for the amount of time as set here. This is also able to be set when ban hammering the user.', + 'SFS_ALLOW_HTTP' => 'Allow HTTP for Stop Forum Spam reports', + 'SFS_ALLOW_HTTP_EXPLAIN' => 'Reports are sent over HTTPS by default. Only enable this if your server cannot make outbound HTTPS requests - your API key and the reported user\'s username, IP address, and email are sent in clear text over HTTP.', 'SFS_API_KEY' => 'SFS API key', 'SFS_API_KEY_EXPLAIN' => 'If you want to report spammers automatically to StopForumSpam you need an API key, http://www.stopforumspam.com/signup.', 'SFS_NEEDS_CURL' => 'Your server needs cURL installed to use the stop forum spam service.', diff --git a/migrations/v105_data.php b/migrations/v105_data.php new file mode 100644 index 0000000..4d3ac5d --- /dev/null +++ b/migrations/v105_data.php @@ -0,0 +1,32 @@ + Date: Thu, 3 Sep 2026 18:13:49 -0500 Subject: [PATCH 2/2] Hide the HTTP-allow toggle when cURL isn't available Matches the existing SFS API key field's own SFS_CURL gating - when cURL is missing, no SFS request is ever sent regardless of this setting, so showing the transport choice is just noise on top of the SFS_NEEDS_CURL message already telling the admin reporting won't work. Co-Authored-By: Claude Sonnet 5 --- adm/style/banhammer_body.html | 2 ++ 1 file changed, 2 insertions(+) diff --git a/adm/style/banhammer_body.html b/adm/style/banhammer_body.html index 14f808e..fba3bd2 100644 --- a/adm/style/banhammer_body.html +++ b/adm/style/banhammer_body.html @@ -75,6 +75,7 @@

{L_ACP_BH_SETTINGS}

+

{L_SFS_ALLOW_HTTP_EXPLAIN}
@@ -82,6 +83,7 @@

{L_ACP_BH_SETTINGS}

+