包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
1.9 KiB
Upgrading From Version 1.2
With version 2.0.0 of this library came major changes to the ciphertext format, algorithms used for encryption, and API.
In version 1.2, keys were represented by 16-byte string variables. In version
2.0.0, keys are represented by objects, instances of the Key class. This
change was made in order to make it harder to misuse the API. For example, in
version 1.2, you could pass in any 16-byte string, but in version 2.0.0 you
need a Key object, which you can only get if you're "doing the right thing."
This means that for all of your old version 1.2 keys, you'll have to:
- Generate a new version 2.0.0 key.
- For all of the ciphertexts encrypted under the old key:
- Decrypt the ciphertext using the old version 1.2 key.
- Re-encrypt it using the new version 2.0.0 key.
Use the special Crypto::legacyDecrypt() method to decrypt the old ciphertexts
using the old key and then re-encrypt them using Crypto::encrypt() with the
new key. Your code will look something like the following. To avoid data loss,
securely back up your keys and data before running your upgrade code.
<?php
// ...
$legacy_ciphertext = // ... get the ciphertext you want to upgrade ...
$legacy_key = // ... get the key to decrypt this ciphertext ...
// Generate the new key that we'll re-encrypt the ciphertext with.
$new_key = Key::createNewRandomKey();
// ... save it somewhere ...
// Decrypt it.
try {
$plaintext = Crypto::legacyDecrypt($legacy_ciphertext, $legacy_key);
} catch (Defuse\Crypto\Exception\WrongKeyOrModifiedCiphertextException $ex)
{
// ... TODO: handle this case appropriately ...
}
// Re-encrypt it.
$new_ciphertext = Crypto::encrypt($plaintext, $new_key);
// ... replace the old $legacy_ciphertext with the new $new_ciphertext
// ...