包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
41 lines
762 B
PHP
41 lines
762 B
PHP
<?php
|
|
declare(strict_types=1);
|
|
namespace MRBS;
|
|
|
|
// Returns an object containing all the usernames available for use by the Select2
|
|
// tool on the edit_entry page.
|
|
|
|
use MRBS\Form\Form;
|
|
|
|
require '../defaultincludes.inc';
|
|
|
|
// Check the CSRF token
|
|
Form::checkToken();
|
|
|
|
// Check the user is authorised for this page
|
|
checkAuthorised(this_page());
|
|
|
|
// Check that the user has a legitimate reason for accessing this page
|
|
if (!can_register_others() && !is_book_admin())
|
|
{
|
|
exit;
|
|
}
|
|
|
|
$result = array();
|
|
|
|
if (method_exists(auth(), 'getUsernames'))
|
|
{
|
|
try
|
|
{
|
|
$result = auth()->getUsernames();
|
|
}
|
|
catch (\Exception $e)
|
|
{
|
|
trigger_error($e->getMessage(), E_USER_WARNING);
|
|
}
|
|
}
|
|
|
|
http_headers(array("Content-Type: application/json"));
|
|
|
|
echo json_encode($result);
|