包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
23 lines
382 B
PHP
23 lines
382 B
PHP
<?php
|
|
namespace MRBS\Auth;
|
|
|
|
|
|
class AuthNone extends Auth
|
|
{
|
|
/**
|
|
* Checks if the specified username/password pair are valid.
|
|
*
|
|
* This authentication scheme always validates positively.
|
|
*
|
|
* @return string|null
|
|
*/
|
|
public function validateUser(
|
|
#[\SensitiveParameter]
|
|
?string $user,
|
|
#[\SensitiveParameter]
|
|
?string $pass)
|
|
{
|
|
return $user;
|
|
}
|
|
}
|