Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
@@ -11,7 +11,7 @@
|
||||
namespace IPS\Session;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -26,12 +26,7 @@ class _Admin extends \IPS\Session
|
||||
* @brief Unix Timestamp of log in time
|
||||
*/
|
||||
public $logInTime;
|
||||
|
||||
/**
|
||||
* @brief Key for cookie
|
||||
*/
|
||||
public $cookieKey;
|
||||
|
||||
|
||||
/**
|
||||
* Open Session
|
||||
*
|
||||
@@ -58,9 +53,8 @@ class _Admin extends \IPS\Session
|
||||
try
|
||||
{
|
||||
/* Load session */
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sys_cp_sessions', array( 'session_id=?', $sessionId ) )->first();
|
||||
$session = \IPS\Db::i()->select( '*', 'core_sys_cp_sessions', array( 'session_id=? AND session_running_time>=?', $sessionId, ( time() - \IPS\Session::sessionLifetime() ) ) )->first();
|
||||
$this->logInTime = $session['session_log_in_time'];
|
||||
$this->cookieKey = $session['session_cookie_key'];
|
||||
|
||||
/* Store this so plugins can access */
|
||||
$this->sessionData = $session;
|
||||
@@ -71,19 +65,9 @@ class _Admin extends \IPS\Session
|
||||
{
|
||||
throw new \DomainException('NO_ACPACCESS');
|
||||
}
|
||||
|
||||
/* Validate adsess */
|
||||
if ( \IPS\Request::i()->adsess !== $session['session_id'] )
|
||||
{
|
||||
throw new \DomainException('NO_ADSESS');
|
||||
}
|
||||
if ( \IPS\Request::i()->cookie['acp_login_key'] !== $this->cookieKey )
|
||||
{
|
||||
throw new \DomainException('NO_COOKIE');
|
||||
}
|
||||
|
||||
|
||||
/* Check IP address */
|
||||
if ( ( defined( '\IPS\BYPASS_ACP_IP_CHECK' ) and !\IPS\BYPASS_ACP_IP_CHECK ) and \IPS\Settings::i()->match_ipaddress and $session['session_ip_address'] !== \IPS\Request::i()->ipAddress() )
|
||||
if ( ( \defined( '\IPS\BYPASS_ACP_IP_CHECK' ) and !\IPS\BYPASS_ACP_IP_CHECK ) and \IPS\Settings::i()->match_ipaddress and $session['session_ip_address'] !== \IPS\Request::i()->ipAddress() )
|
||||
{
|
||||
throw new \DomainException('BAD_IP');
|
||||
}
|
||||
@@ -96,7 +80,6 @@ class _Admin extends \IPS\Session
|
||||
$this->member = new \IPS\Member;
|
||||
$this->logInTime = 0;
|
||||
$this->error = $e;
|
||||
$this->cookieKey = \IPS\Login::generateRandomString();
|
||||
return isset( $this->sessionData['session_app_data'] ) ? $this->sessionData['session_app_data'] : '';
|
||||
}
|
||||
}
|
||||
@@ -119,8 +102,7 @@ class _Admin extends \IPS\Session
|
||||
'session_log_in_time' => $this->logInTime,
|
||||
'session_running_time' => time(),
|
||||
'session_url' => \IPS\Request::i()->url(),
|
||||
'session_app_data' => $data,
|
||||
'session_cookie_key' => $this->cookieKey
|
||||
'session_app_data' => $data
|
||||
) );
|
||||
|
||||
return TRUE;
|
||||
|
||||
Reference in new issue
Block a user