MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
<?php
|
||||
declare(strict_types=1);
|
||||
namespace MRBS;
|
||||
|
||||
use MRBS\Form\Form;
|
||||
|
||||
require 'defaultincludes.inc';
|
||||
|
||||
// Check the CSRF token
|
||||
Form::checkToken();
|
||||
|
||||
// Check the user is authorised for this page
|
||||
checkAuthorised(this_page());
|
||||
|
||||
// Must also be a booking admin
|
||||
if (!is_book_admin())
|
||||
{
|
||||
showAccessDenied($view, $view_all, $year, $month, $day, $area, $room ?? null);
|
||||
exit;
|
||||
}
|
||||
|
||||
$message_text = get_form_var('message_text', 'string', '');
|
||||
$message_from = get_form_var('message_from', 'string', '');
|
||||
$message_until = get_form_var('message_until', 'string', '');
|
||||
$returl = get_form_var('returl', 'url_local', 'admin.php');
|
||||
$save_button = get_form_var('save_button', 'string');
|
||||
|
||||
if (!empty($save_button))
|
||||
{
|
||||
$message = Message::getInstance($message_text, $message_from, $message_until);
|
||||
$message->save();
|
||||
}
|
||||
|
||||
location_header($returl);
|
||||
Reference in New Issue
Block a user