MRBS 1.12.2 等保2.0二级整改完整提交

包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
This commit is contained in:
人事系统开发
2026-09-09 16:55:02 +08:00
commit 1ba6efd8ed
2151 changed files with 528780 additions and 0 deletions
+84
View File
@@ -0,0 +1,84 @@
<?php
declare(strict_types=1);
namespace MRBS\Session;
use MRBS\Form\Form;
use MRBS\User;
use function MRBS\auth;
/**
* Get user identity/password using the REMOTE_USER environment variable. Both identity and password
* equal the value of REMOTE_USER.
*
* To use this session scheme, set in config.inc.php:
*
* $auth['session'] = 'remote_user';
* $auth['type'] = 'none';
*
* If you want to display a login link, set in config.inc.php:
*
* $auth['remote_user']['login_link'] = '/login/link.html';
*
* If you want to display a logout link, set in config.inc.php:
*
* $auth['remote_user']['logout_link'] = '/logout/link.html';
*/
class SessionRemoteUser extends SessionWithLogin
{
// User is expected to already be authenticated by the web server, so do nothing
public function authGet(?string $target_url=null, ?string $returl=null, ?string $error=null, bool $raw=false) : void
{
}
public function getCurrentUser() : ?User
{
global $server;
if ((!isset($server['REMOTE_USER'])) ||
(!is_string($server['REMOTE_USER'])) ||
(($server['REMOTE_USER'] === '')))
{
return parent::getCurrentUser();
}
return auth()->getUser($server['REMOTE_USER']);
}
public function getLogonFormParams() : ?array
{
global $auth;
if (isset($auth['remote_user']['login_link']))
{
return array(
'action' => $auth['remote_user']['login_link'],
'method' => Form::METHOD_GET,
);
}
else
{
return null;
}
}
public function getLogoffFormParams() : ?array
{
global $auth;
if (isset($auth['remote_user']['logout_link']))
{
return array(
'action' => $auth['remote_user']['logout_link'],
'method' => Form::METHOD_GET
);
}
else
{
return null;
}
}
}