Files
mrbs-equbao-2026/lib/MRBS/Session/SessionHost.php
T
人事系统开发 1ba6efd8ed MRBS 1.12.2 等保2.0二级整改完整提交
包含:登录失败锁定、90天密码有效期、30分钟会话超时、
强制改密、登录审计日志、屏幕水印、企业背景图、
备案信息固定底部、favicon、JS空集合保护、
会话过期体验优化(403 JSON)、display_errors 关闭、
固定 key 根治 Integrity check failed 等全部改动

注意:config.inc.php/.htaccess/.user.ini 含敏感信息,
通过 .gitignore 排除,勿推送到公开仓库。
2026-09-09 16:55:02 +08:00

42 lines
1.0 KiB
PHP

<?php
declare(strict_types=1);
namespace MRBS\Session;
use MRBS\User;
use function MRBS\auth;
/**
* This is a slight variant of session_ip.
* Session management scheme that uses the DNS name of the computer to identify users and administrators.
* Anyone who can access the server can make bookings etc.
*
* To use this authentication scheme set the following things in config.inc.php:
*
* $auth['type'] = 'none';
* $auth['session'] = 'host';
*
* Then, you may configure admin users:
*
* $auth['admin'][] = 'DNSname1';
* $auth['admin'][] = 'DNSname2';
*/
class SessionHost extends Session
{
// No need to prompt for a name: if no DNSname is returned, the IP address is used
public function getCurrentUser() : ?User
{
global $server;
if ((!isset($server['REMOTE_ADDR'])) ||
(!is_string($server['REMOTE_ADDR'])) ||
(($server['REMOTE_ADDR'] === '')))
{
return parent::getCurrentUser();
}
return auth()->getUser(gethostbyaddr($server['REMOTE_ADDR']));
}
}