包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
34 lines
810 B
PHP
34 lines
810 B
PHP
<?php
|
|
declare(strict_types=1);
|
|
namespace MRBS\Session;
|
|
|
|
use MRBS\User;
|
|
use function MRBS\auth;
|
|
|
|
/**
|
|
* Session management scheme that uses Windows NT domain users and Internet
|
|
* Information Server as the source for user authentication.
|
|
*
|
|
* To use this authentication scheme, set the following things in config.inc.php:
|
|
*
|
|
* $auth['type'] = 'none';
|
|
* $auth['session'] = 'nt';
|
|
*
|
|
* Then, you may configure admin users:
|
|
*
|
|
* $auth['admin'][] = 'nt_username1';
|
|
* $auth['admin'][] = 'nt_username2';
|
|
*
|
|
* See AUTHENTICATION for more information.
|
|
*/
|
|
class SessionNt extends Session
|
|
{
|
|
|
|
// For this scheme no need to prompt for a name - NT User always there.
|
|
public function getCurrentUser() : ?User
|
|
{
|
|
return auth()->getUser(get_current_user()) ?? parent::getCurrentUser();
|
|
}
|
|
|
|
}
|