MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
<?php
|
||||
namespace MRBS\Auth;
|
||||
|
||||
/**
|
||||
* Authentication scheme that uses a password hash file as the source for user authentication.
|
||||
*
|
||||
* This supports any password hash format that your installation of PHP supports.
|
||||
*
|
||||
* To use this authentication scheme, set the following things in config.inc.php:
|
||||
*
|
||||
* $auth["type"] = "crypt";
|
||||
* $auth["crypt"]["passwd_file] = "/etc/httpd/mrbs_passwd";
|
||||
*
|
||||
* Then, you may configure admin users:
|
||||
*
|
||||
* $auth["admin"][] = "username1";
|
||||
* $auth["admin"][] = "username2";
|
||||
*/
|
||||
class AuthCrypt extends Auth
|
||||
{
|
||||
public function validateUser(
|
||||
#[\SensitiveParameter]
|
||||
?string $user,
|
||||
#[\SensitiveParameter]
|
||||
?string $pass)
|
||||
{
|
||||
global $auth;
|
||||
|
||||
// Check if we do not have a username/password
|
||||
if(!isset($user) || !isset($pass))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
if (!isset($auth["crypt"]["passwd_file"]))
|
||||
{
|
||||
error_log("auth_crypt: passwd file not specified");
|
||||
return false;
|
||||
}
|
||||
|
||||
$fh = fopen($auth["crypt"]["passwd_file"], "r");
|
||||
if (!$fh)
|
||||
{
|
||||
error_log("auth_crypt: couldn't open passwd file\n");
|
||||
return false;
|
||||
}
|
||||
|
||||
$ret = false; // Default to failure
|
||||
while ($line = fgets($fh))
|
||||
{
|
||||
if (preg_match("/^\Q$user\E:(.*)/", $line, $matches))
|
||||
{
|
||||
if (password_verify($pass, $matches[1]))
|
||||
{
|
||||
$ret = $user; // Success!
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fclose($fh);
|
||||
return $ret;
|
||||
}
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user