MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
@@ -0,0 +1,53 @@
|
||||
<?php
|
||||
namespace MRBS\Auth;
|
||||
|
||||
|
||||
class AuthConfig extends Auth
|
||||
{
|
||||
public function validateUser(
|
||||
#[\SensitiveParameter]
|
||||
?string $user,
|
||||
#[\SensitiveParameter]
|
||||
?string $pass)
|
||||
{
|
||||
global $auth;
|
||||
|
||||
// Check if we do not have a username/password
|
||||
if(!isset($user) || !isset($pass) || strlen($pass)==0)
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
if ((isset($auth["user"][$user]) &&
|
||||
($auth["user"][$user] == $pass)
|
||||
) ||
|
||||
(isset($auth["user"][mb_strtolower($user)]) &&
|
||||
($auth["user"][mb_strtolower($user)] == $pass)
|
||||
))
|
||||
{
|
||||
return $user; // User validated
|
||||
}
|
||||
|
||||
return false; // User unknown or password invalid
|
||||
}
|
||||
|
||||
|
||||
// Return an array of users, indexed by 'username' and 'display_name'
|
||||
public function getUsernames() : array
|
||||
{
|
||||
global $auth;
|
||||
|
||||
$result = array();
|
||||
|
||||
foreach ($auth['user'] as $user => $password)
|
||||
{
|
||||
$result[] = array('username' => $user,
|
||||
'display_name' => $user);
|
||||
}
|
||||
|
||||
// Need to sort the users
|
||||
self::sortUsers($result);
|
||||
|
||||
return $result;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user