Version 4.5.0

This commit is contained in:
Neo committed 2025-12-19 05:51:58 -08:00
1 parent 1a0c7fd3c2
commit f79dcf067a
3791 files changed
+248032 -76372

No files matched your search

+48 -27
View File
@@ -11,7 +11,7 @@
namespace IPS;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
@@ -47,7 +47,7 @@ abstract class _Session
{
if( static::$instance === NULL )
{
$classname = get_called_class();
$classname = \get_called_class();
if ( $classname === 'IPS\Session' )
{
@@ -105,19 +105,9 @@ abstract class _Session
/* Upgrader starts session already */
if ( !\IPS\Dispatcher::hasInstance() or !\IPS\Dispatcher::i() instanceof \IPS\Dispatcher\Setup )
{
if ( version_compare( phpversion(), '5.4.0', '>=' ) )
if( session_status() !== PHP_SESSION_ACTIVE )
{
if( session_status() !== PHP_SESSION_ACTIVE )
{
session_start();
}
}
else
{
if( session_id() === '' )
{
session_start();
}
session_start();
}
}
}
@@ -156,13 +146,16 @@ abstract class _Session
{
/* PHP 7.0.2 had a bug reported where session_regenerate_id() does not close opened sessions properly and in some situations can cause PHP to hang or crash.
* This issue is fixed in PHP 7.1.0 - https://bugs.php.net/bug.php?id=71394 */
if ( version_compare( PHP_VERSION, '7.1.0' ) >= 0 )
{
session_regenerate_id();
}
session_regenerate_id();
/* Update our new session id */
$this->id = session_id();
$_SESSION['forcedWrite'] = time();
$this->member = $member;
/* Update CSRF Key based on new data */
$this->regenerateCsrfKey();
}
/**
@@ -175,21 +168,21 @@ abstract class _Session
/* Set ID */
$this->id = session_id();
/* Crate csrf key */
$this->csrfKey = md5( "{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
/* Create csrf key */
$this->regenerateCsrfKey();
/* Update member */
if ( $this->member->member_id )
{
$save = FALSE;
/* Set the last activity */
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS and ! \IPS\Request::i()->isAjax() )
/* Set the last activity (but not if this is an ajax request or a partially registered member as we delete where last_visit=0) */
if ( isset( $this->data ) and ! \IPS\Request::i()->isAjax() and ( $this->member->email and $this->member->name ) )
{
if ( time() - $this->member->last_activity > 3600 )
if ( time() - $this->member->last_activity > 3600 or !$this->member->last_visit )
{
$save = TRUE;
$this->member->last_visit = $this->member->last_activity;
$this->member->last_visit = $this->member->last_activity ?: time();
}
if ( time() - $this->member->last_activity > 180 )
{
@@ -199,7 +192,7 @@ abstract class _Session
}
/* Set timezone */
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
if ( isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and \in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
{
$save = TRUE;
$this->member->timezone = \IPS\Request::i()->cookie['ipsTimezone'];
@@ -243,7 +236,7 @@ abstract class _Session
* @endcode
* @param string $langKey Language key for log
* @param array $params Key/Values - keys are variables to use in sprintf on $langKey, values are booleans indicating if they are language keys themselves (TRUE) or raw data (FALSE)
* @param \IPS\Content\Item|NULL If moderation action is specific to an item
* @param \IPS\Content\Item|NULL $item If moderation action is specific to an item
* @return void
*/
public function modLog( $langKey, $params=array(), $item=null )
@@ -252,7 +245,7 @@ abstract class _Session
if ( $item instanceof \IPS\Content\Item )
{
$class = get_class( $item );
$class = \get_class( $item );
$idColumn = $class::$databaseColumnId;
}
@@ -271,4 +264,32 @@ abstract class _Session
'item_id' => $item ? $item->$idColumn : NULL,
) );
}
/**
* Regenerate CSRF Key
*
* @return void
*/
public function regenerateCsrfKey()
{
$this->csrfKey = md5( \IPS\SUITE_UNIQUE_KEY . "&{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
}
/**
* Return the maximum session lifetime (in seconds)
*
* @return int
*/
public static function sessionLifetime()
{
$timeout = 1440;
if( \function_exists('ini_get') )
{
$phpTimeout = @ini_get('session.gc_maxlifetime');
$timeout = $phpTimeout ?: $timeout;
}
return $timeout;
}
}