Version 4.5.0
This commit is contained in:
1 parent
1a0c7fd3c2
commit
f79dcf067a
3791 files changed
+248032
-76372
No files matched your search
+48
-27
@@ -11,7 +11,7 @@
|
||||
namespace IPS;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
exit;
|
||||
@@ -47,7 +47,7 @@ abstract class _Session
|
||||
{
|
||||
if( static::$instance === NULL )
|
||||
{
|
||||
$classname = get_called_class();
|
||||
$classname = \get_called_class();
|
||||
|
||||
if ( $classname === 'IPS\Session' )
|
||||
{
|
||||
@@ -105,19 +105,9 @@ abstract class _Session
|
||||
/* Upgrader starts session already */
|
||||
if ( !\IPS\Dispatcher::hasInstance() or !\IPS\Dispatcher::i() instanceof \IPS\Dispatcher\Setup )
|
||||
{
|
||||
if ( version_compare( phpversion(), '5.4.0', '>=' ) )
|
||||
if( session_status() !== PHP_SESSION_ACTIVE )
|
||||
{
|
||||
if( session_status() !== PHP_SESSION_ACTIVE )
|
||||
{
|
||||
session_start();
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
if( session_id() === '' )
|
||||
{
|
||||
session_start();
|
||||
}
|
||||
session_start();
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -156,13 +146,16 @@ abstract class _Session
|
||||
{
|
||||
/* PHP 7.0.2 had a bug reported where session_regenerate_id() does not close opened sessions properly and in some situations can cause PHP to hang or crash.
|
||||
* This issue is fixed in PHP 7.1.0 - https://bugs.php.net/bug.php?id=71394 */
|
||||
if ( version_compare( PHP_VERSION, '7.1.0' ) >= 0 )
|
||||
{
|
||||
session_regenerate_id();
|
||||
}
|
||||
session_regenerate_id();
|
||||
|
||||
/* Update our new session id */
|
||||
$this->id = session_id();
|
||||
|
||||
$_SESSION['forcedWrite'] = time();
|
||||
$this->member = $member;
|
||||
|
||||
/* Update CSRF Key based on new data */
|
||||
$this->regenerateCsrfKey();
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -175,21 +168,21 @@ abstract class _Session
|
||||
/* Set ID */
|
||||
$this->id = session_id();
|
||||
|
||||
/* Crate csrf key */
|
||||
$this->csrfKey = md5( "{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
|
||||
/* Create csrf key */
|
||||
$this->regenerateCsrfKey();
|
||||
|
||||
/* Update member */
|
||||
if ( $this->member->member_id )
|
||||
{
|
||||
$save = FALSE;
|
||||
|
||||
/* Set the last activity */
|
||||
if ( isset( $this->data ) and $this->data['login_type'] != static::LOGIN_TYPE_ANONYMOUS and ! \IPS\Request::i()->isAjax() )
|
||||
/* Set the last activity (but not if this is an ajax request or a partially registered member as we delete where last_visit=0) */
|
||||
if ( isset( $this->data ) and ! \IPS\Request::i()->isAjax() and ( $this->member->email and $this->member->name ) )
|
||||
{
|
||||
if ( time() - $this->member->last_activity > 3600 )
|
||||
if ( time() - $this->member->last_activity > 3600 or !$this->member->last_visit )
|
||||
{
|
||||
$save = TRUE;
|
||||
$this->member->last_visit = $this->member->last_activity;
|
||||
$this->member->last_visit = $this->member->last_activity ?: time();
|
||||
}
|
||||
if ( time() - $this->member->last_activity > 180 )
|
||||
{
|
||||
@@ -199,7 +192,7 @@ abstract class _Session
|
||||
}
|
||||
|
||||
/* Set timezone */
|
||||
if ( !$this->member->members_bitoptions['timezone_override'] and isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
|
||||
if ( isset( \IPS\Request::i()->cookie['ipsTimezone'] ) and \IPS\Request::i()->cookie['ipsTimezone'] !== $this->member->timezone and \in_array( \IPS\Request::i()->cookie['ipsTimezone'], \DateTimeZone::listIdentifiers() ) )
|
||||
{
|
||||
$save = TRUE;
|
||||
$this->member->timezone = \IPS\Request::i()->cookie['ipsTimezone'];
|
||||
@@ -243,7 +236,7 @@ abstract class _Session
|
||||
* @endcode
|
||||
* @param string $langKey Language key for log
|
||||
* @param array $params Key/Values - keys are variables to use in sprintf on $langKey, values are booleans indicating if they are language keys themselves (TRUE) or raw data (FALSE)
|
||||
* @param \IPS\Content\Item|NULL If moderation action is specific to an item
|
||||
* @param \IPS\Content\Item|NULL $item If moderation action is specific to an item
|
||||
* @return void
|
||||
*/
|
||||
public function modLog( $langKey, $params=array(), $item=null )
|
||||
@@ -252,7 +245,7 @@ abstract class _Session
|
||||
|
||||
if ( $item instanceof \IPS\Content\Item )
|
||||
{
|
||||
$class = get_class( $item );
|
||||
$class = \get_class( $item );
|
||||
$idColumn = $class::$databaseColumnId;
|
||||
}
|
||||
|
||||
@@ -271,4 +264,32 @@ abstract class _Session
|
||||
'item_id' => $item ? $item->$idColumn : NULL,
|
||||
) );
|
||||
}
|
||||
|
||||
/**
|
||||
* Regenerate CSRF Key
|
||||
*
|
||||
* @return void
|
||||
*/
|
||||
public function regenerateCsrfKey()
|
||||
{
|
||||
$this->csrfKey = md5( \IPS\SUITE_UNIQUE_KEY . "&{$this->member->email}& " . ( $this->member->member_id ? $this->member->joined->getTimestamp() : 0 ) . '&' . $this->id );
|
||||
}
|
||||
|
||||
/**
|
||||
* Return the maximum session lifetime (in seconds)
|
||||
*
|
||||
* @return int
|
||||
*/
|
||||
public static function sessionLifetime()
|
||||
{
|
||||
$timeout = 1440;
|
||||
|
||||
if( \function_exists('ini_get') )
|
||||
{
|
||||
$phpTimeout = @ini_get('session.gc_maxlifetime');
|
||||
$timeout = $phpTimeout ?: $timeout;
|
||||
}
|
||||
|
||||
return $timeout;
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user