MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
namespace MRBS;
|
||||
|
||||
use MRBS\Form\Form;
|
||||
|
||||
require "defaultincludes.inc";
|
||||
require_once "mrbs_sql.inc";
|
||||
|
||||
|
||||
// Check the CSRF token
|
||||
Form::checkToken();
|
||||
|
||||
// Check the user is authorised for this page
|
||||
checkAuthorised(this_page());
|
||||
|
||||
// Get non-standard form variables
|
||||
$name = get_form_var('name', 'string', null, INPUT_POST);
|
||||
$description = get_form_var('description', 'string', null, INPUT_POST);
|
||||
$capacity = get_form_var('capacity', 'int', null, INPUT_POST);
|
||||
$room_admin_email = get_form_var('room_admin_email', 'string', null, INPUT_POST);
|
||||
$type = get_form_var('type', 'string', null, INPUT_POST);
|
||||
|
||||
// This file is for adding new areas/rooms
|
||||
$error = '';
|
||||
|
||||
// First of all check that we've got an area or room name
|
||||
if (!isset($name) || ($name === ''))
|
||||
{
|
||||
$error = "empty_name";
|
||||
}
|
||||
else
|
||||
{
|
||||
// Strip out any extra whitespace that the user may accidentally have typed in the name
|
||||
$name = remove_extra_whitespace($name);
|
||||
// We need to do different things depending on if it's a room
|
||||
// or an area
|
||||
if ($type == "area")
|
||||
{
|
||||
$area = mrbsAddArea($name, $error);
|
||||
}
|
||||
elseif ($type == "room")
|
||||
{
|
||||
$room = mrbsAddRoom($name, $area, $error, $description, $capacity, $room_admin_email);
|
||||
}
|
||||
}
|
||||
|
||||
$returl = "admin.php?area=$area" . (!empty($error) ? "&error=$error" : "");
|
||||
location_header($returl);
|
||||
Reference in New Issue
Block a user