MRBS 1.12.2 等保2.0二级整改完整提交

包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
人事系统开发
2026-09-09 16:55:02 +08:00
commit 1ba6efd8ed
2151 changed files with 528780 additions and 0 deletions
+56
View File
@@ -0,0 +1,56 @@
<?php
namespace MRBS\Auth;
/**
* Authentication scheme that uses an external script as the source for user authentication.
*
* To use this authentication scheme, set the following things in config.inc.php:
*
* $auth["realm"] = "MRBS"; // Or any other string
* $auth["type"] = "ext";
* $auth["prog"] = "authenticationprogram"; // The full path to the external script
* $auth["params"] = "<...>"; // Parameters to pass to the script; #USERNAME# and #PASSWORD#
* // will be expanded to the values typed by the user, e.g.
* // "/etc/htpasswd #USERNAME# #PASSWORD#"
*
* Then, you may configure admin users:
*
* $auth["admin"][] = "username1";
* $auth["admin"][] = "username2";
*
*/
class AuthExt extends Auth
{
public function validateUser(
#[\SensitiveParameter]
?string $user,
#[\SensitiveParameter]
?string $pass)
{
global $auth;
// Check if we do not have a username/password
if(!isset($user) || !isset($pass))
{
return false;
}
// Generate the command line
$cmd = $auth["prog"] . ' ' . $auth["params"];
$cmd = str_replace('#USERNAME#', escapeshellarg($user), $cmd);
$cmd = str_replace('#PASSWORD#', escapeshellarg($pass), $cmd);
// Run the program
exec($cmd, $output, $ret);
// If it succeeded, return success
if ($ret == 0)
{
return $user;
}
// return failure
return false;
}
}