Version 4.1.19
This commit is contained in:
1 parent
28bd025b35
commit
2bd5025018
2674 files changed
+233518
-77766
No files matched your search
+15
-14
@@ -2,9 +2,9 @@
|
||||
/**
|
||||
* @brief Session Handler
|
||||
* @author <a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
|
||||
* @copyright (c) 2001 - SVN_YYYY Invision Power Services, Inc.
|
||||
* @copyright (c) 2001 - 2016 Invision Power Services, Inc.
|
||||
* @license http://www.invisionpower.com/legal/standards/
|
||||
* @package IPS Social Suite
|
||||
* @package IPS Community Suite
|
||||
* @since 11 Mar 2013
|
||||
* @version SVN_VERSION_NUMBER
|
||||
*/
|
||||
@@ -46,7 +46,7 @@ abstract class _Session
|
||||
*/
|
||||
public static function i()
|
||||
{
|
||||
if( self::$instance === NULL )
|
||||
if( static::$instance === NULL )
|
||||
{
|
||||
$classname = get_called_class();
|
||||
if ( get_called_class() === 'IPS\Session' )
|
||||
@@ -69,21 +69,21 @@ abstract class _Session
|
||||
if ( class_exists( $classname ) )
|
||||
{
|
||||
/* Create class */
|
||||
self::$instance = new $classname;
|
||||
static::$instance = new $classname;
|
||||
|
||||
/* Name the session */
|
||||
$name = session_name( ( \IPS\COOKIE_PREFIX !== NULL ) ? \IPS\COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
|
||||
|
||||
/* Set the handler */
|
||||
session_write_close();
|
||||
session_set_save_handler( array( self::$instance, 'open' ), array( self::$instance, 'close' ), array( self::$instance, 'read' ), array( self::$instance, 'write' ), array( self::$instance, 'destroy' ), array( self::$instance, 'gc' ) );
|
||||
session_set_save_handler( array( static::$instance, 'open' ), array( static::$instance, 'close' ), array( static::$instance, 'read' ), array( static::$instance, 'write' ), array( static::$instance, 'destroy' ), array( static::$instance, 'gc' ) );
|
||||
|
||||
/* Make sure we use HTTP-Only cookies */
|
||||
session_set_cookie_params(
|
||||
'0',
|
||||
( \IPS\COOKIE_PATH !== NULL ) ? \IPS\COOKIE_PATH : '/',
|
||||
( \IPS\COOKIE_DOMAIN !== NULL ) ? \IPS\COOKIE_DOMAIN : '',
|
||||
( \IPS\COOKIE_BYPASS_SSLONLY !== NULL ) ? ( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
( \IPS\COOKIE_BYPASS_SSLONLY !== TRUE ) ? ( mb_substr( \IPS\Settings::i()->base_url, 0, 5 ) == 'https' ) : FALSE,
|
||||
TRUE
|
||||
);
|
||||
|
||||
@@ -91,16 +91,16 @@ abstract class _Session
|
||||
session_start();
|
||||
|
||||
/* Init */
|
||||
self::$instance->init();
|
||||
static::$instance->init();
|
||||
|
||||
/* Register shutdown */
|
||||
register_shutdown_function('session_write_close');
|
||||
}
|
||||
else
|
||||
{
|
||||
self::$instance = new \StdClass;
|
||||
self::$instance->member = new \IPS\Member;
|
||||
self::$instance->csrfKey = '';
|
||||
static::$instance = new \StdClass;
|
||||
static::$instance->member = new \IPS\Member;
|
||||
static::$instance->csrfKey = '';
|
||||
|
||||
/* Upgrader starts session already */
|
||||
if ( !\IPS\Dispatcher::hasInstance() or !\IPS\Dispatcher::i() instanceof \IPS\Dispatcher\Setup )
|
||||
@@ -123,7 +123,7 @@ abstract class _Session
|
||||
}
|
||||
}
|
||||
|
||||
return self::$instance;
|
||||
return static::$instance;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -177,7 +177,7 @@ abstract class _Session
|
||||
$save = FALSE;
|
||||
|
||||
/* Set the last activity */
|
||||
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS )
|
||||
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS and ! \IPS\Request::i()->isAjax() )
|
||||
{
|
||||
if ( time() - $this->member->last_activity > 3600 )
|
||||
{
|
||||
@@ -192,7 +192,7 @@ abstract class _Session
|
||||
}
|
||||
|
||||
/* Set timezone */
|
||||
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone )
|
||||
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
|
||||
{
|
||||
$save = TRUE;
|
||||
$this->member->timezone = \IPS\Request::i()->cookie['ipsTimezone'];
|
||||
@@ -213,7 +213,7 @@ abstract class _Session
|
||||
*/
|
||||
public function csrfCheck()
|
||||
{
|
||||
if ( \IPS\Request::i()->csrfKey !== $this->csrfKey )
|
||||
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, (string) \IPS\Request::i()->csrfKey ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
|
||||
}
|
||||
@@ -241,6 +241,7 @@ abstract class _Session
|
||||
|
||||
\IPS\Db::i()->insert( 'core_moderator_logs', array(
|
||||
'member_id' => \IPS\Member::loggedIn()->member_id,
|
||||
'member_name' => \IPS\Member::loggedIn()->name,
|
||||
'ctime' => time(),
|
||||
'note' => json_encode( $params ),
|
||||
'ip_address' => \IPS\Request::i()->ipAddress(),
|
||||
|
||||
Reference in new issue
Block a user