MRBS 1.12.2 等保2.0二级整改完整提交

包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
人事系统开发
2026-09-09 16:55:02 +08:00
commit 1ba6efd8ed
2151 changed files with 528780 additions and 0 deletions
+125
View File
@@ -0,0 +1,125 @@
<?php
declare(strict_types=1);
namespace MRBS;
use MRBS\Form\ElementFieldset;
use MRBS\Form\ElementInputSubmit;
use MRBS\Form\FieldDiv;
use MRBS\Form\FieldInputDate;
use MRBS\Form\FieldTextarea;
use MRBS\Form\Form;
require 'defaultincludes.inc';
function get_field_display_from(Message $message): FieldInputDate
{
$field = new FieldInputDate();
$field->setLabel(get_vocab('display_from'))
->setControlAttributes(['name' => 'message_from', 'value' => $message->getFromDate()]);
return $field;
}
function get_field_display_until(Message $message): FieldInputDate
{
$field = new FieldInputDate();
$field->setLabel(get_vocab('display_until'))
->setControlAttributes(['name' => 'message_until', 'value' => $message->getUntilDate()]);
return $field;
}
function get_field_message_text(Message $message): FieldTextarea
{
$field = new FieldTextarea();
$field->setLabel(get_vocab('message'))
->setControlAttribute('name', 'message_text')
->setControlText($message->getText());
return $field;
}
function get_fieldset_submit_buttons() : ElementFieldset
{
$fieldset = new ElementFieldset();
// The back and submit buttons
$field = new FieldDiv();
$back = new ElementInputSubmit();
$back->setAttributes(array(
'name' => 'back_button',
'value' => get_vocab('back'),
'formnovalidate' => true)
);
$submit = new ElementInputSubmit();
$submit->setAttributes(array(
'class' => 'default_action',
'name' => 'save_button',
'value' => get_vocab('save'))
);
$field->setAttribute('class', 'submit_buttons')
->addLabelClass('no_suffix')
->addLabelElement($back)
->addControlElement($submit);
$fieldset->addElement($field);
return $fieldset;
}
// Check the user is authorised for this page
checkAuthorised(this_page());
// Must also be a booking admin
if (!is_book_admin())
{
showAccessDenied($view, $view_all, $year, $month, $day, $area, $room ?? null);
exit;
}
$context = array(
'view' => $view,
'view_all' => $view_all,
'year' => $year,
'month' => $month,
'day' => $day,
'area' => $area,
'room' => isset($room) ? $room : null
);
$returl = 'admin.php?' . http_build_query($context, '', '&');
print_header($context);
// Get the current message, if any
$message = Message::getInstance();
$message->load();
// Construct the form
$form = new Form(Form::METHOD_POST);
$form->setAttributes(array(
'class' => 'standard',
'id' => 'message',
'action' => multisite('edit_message_handler.php'))
);
$form->addHiddenInput('returl', $returl);
$fieldset = new ElementFieldset();
$fieldset->addLegend(get_vocab('edit_message'));
$fieldset->addElement(get_field_message_text($message))
->addElement(get_field_display_from($message))
->addElement(get_field_display_until($message));
$form->addElement($fieldset)
->addElement(get_fieldset_submit_buttons())
->render();
print_footer();