包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
64 lines
1.3 KiB
PHP
64 lines
1.3 KiB
PHP
<?php
|
|
declare(strict_types=1);
|
|
namespace MRBS\Session;
|
|
|
|
use MRBS\User;
|
|
use function MRBS\auth;
|
|
|
|
/**
|
|
* Get user identity using the HTTP basic authentication.
|
|
*/
|
|
class SessionHttp extends SessionWithLogin
|
|
{
|
|
|
|
public function authGet(?string $target_url=null, ?string $returl=null, ?string $error=null, bool $raw=false) : void
|
|
{
|
|
global $auth;
|
|
|
|
header("WWW-Authenticate: Basic realm=\"$auth[realm]\"");
|
|
header("HTTP/1.0 401 Unauthorized");
|
|
}
|
|
|
|
|
|
public function getCurrentUser() : ?User
|
|
{
|
|
global $server;
|
|
|
|
if (!isset($server['PHP_AUTH_USER']))
|
|
{
|
|
return parent::getCurrentUser();
|
|
}
|
|
|
|
// Trim any whitespace because PHP_AUTH_USER can contain it.
|
|
$php_auth_user = trim($server['PHP_AUTH_USER']);
|
|
|
|
if ($php_auth_user === '')
|
|
{
|
|
return parent::getCurrentUser();
|
|
}
|
|
|
|
if (auth()->validateUser($php_auth_user, self::getAuthPassword()) === false)
|
|
{
|
|
return parent::getCurrentUser();
|
|
}
|
|
|
|
return auth()->getUser($php_auth_user);
|
|
}
|
|
|
|
|
|
public function getLogoffFormParams() : ?array
|
|
{
|
|
// Just return null - you can't log off
|
|
// (well, there are ways of achieving a logoff but we haven't implemented them)
|
|
return null;
|
|
}
|
|
|
|
|
|
private static function getAuthPassword() : ?string
|
|
{
|
|
global $server;
|
|
|
|
return (isset($server['PHP_AUTH_PW'])) ? $server['PHP_AUTH_PW'] : null;
|
|
}
|
|
}
|