Files
人事系统开发 1ba6efd8ed MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
2026-09-09 16:55:02 +08:00

64 lines
1.5 KiB
PHP

<?php
namespace MRBS\Auth;
/**
* Authentication scheme that uses an Apache "auth basic" password file for user authentication.
*
* To use this authentication scheme, set the following things in config.inc.php:
*
* $auth["type"] = "auth_basic";
* $auth["auth_basic"]["passwd_file] = "/etc/httpd/htpasswd"; // Example
* $auth["auth_basic"]["mode"] = "des"; // The mode of encryption used in
* // the file. Must be one of:
* // 'des', 'sha' or 'md5'.
*
* Then, you may configure admin users:
*
* $auth["admin"][] = "username1";
* $auth["admin"][] = "username2";
*/
class AuthAuthBasic extends Auth
{
public function validateUser(
#[\SensitiveParameter]
?string $user,
#[\SensitiveParameter]
?string $pass)
{
global $auth;
// Check if we do not have a username/password
if(!isset($user) || !isset($pass))
{
return false;
}
if (!isset($auth["auth_basic"]["passwd_file"]))
{
error_log("auth_basic: passwd file not specified");
return false;
}
if (!isset($auth["auth_basic"]["mode"]))
{
error_log("auth_basic: mode not specified");
return false;
}
require_once "File/Passwd/Authbasic.php";
$f = &File_Passwd::factory('Authbasic');
$f->setFile($auth["auth_basic"]["passwd_file"]);
$f->setMode($auth["auth_basic"]["mode"]);
$f->load();
if ($f->verifyPasswd($user, $pass) === true)
{
return $user;
}
return false;
}
}