Files
mrbs-equbao-2026/lib/MRBS/Auth/AuthIdcheck.php
T
人事系统开发 1ba6efd8ed MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
2026-09-09 16:55:02 +08:00

62 lines
1.3 KiB
PHP

<?php
namespace MRBS\Auth;
use MRBS\User;
/**
* For use with mod_idcheck (http://idcheck.sourceforge.net/).
*
* Must have `$auth['session']` set to 'remote_user'.
*/
class AuthIdcheck extends AuthNone
{
public function __construct()
{
global $auth;
if ($auth['session'] != 'remote_user')
{
$message = 'MRBS configuration error. If $auth["type"] is set to "idcheck"' .
' then $auth["session"] must be set to "remote_user"';
die($message);
}
}
public function validateUser(
#[\SensitiveParameter]
?string $user,
#[\SensitiveParameter]
?string $pass)
{
// Method provided for completeness as it's an abstract method.
// However it's not used by the 'remote_user' session scheme.
return $user;
}
protected function getUserFresh(string $username) : ?User
{
global $server;
$user = new User($username);
$user->level = $this->getDefaultLevel($username);
// We only know the details of the currently logged in user
if (isset($username) && isset($server['REMOTE_USER']) && ($username == $server['REMOTE_USER']))
{
$user->display_name = $server['IDCHECK_NAME'];
$user->email = $server['IDCHECK_MAIL'];
}
else
{
$user->display_name = $username;
$user->email = '';
}
return $user;
}
}