包含:登录失败锁定、90天密码有效期、30分钟会话超时、 强制改密、登录审计日志、屏幕水印、企业背景图、 备案信息固定底部、favicon、JS空集合保护、 会话过期体验优化(403 JSON)、display_errors 关闭、 固定 key 根治 Integrity check failed 等全部改动 注意:config.inc.php/.htaccess/.user.ini 含敏感信息, 通过 .gitignore 排除,勿推送到公开仓库。
166 lines
4.3 KiB
PHP
166 lines
4.3 KiB
PHP
<?php
|
|
declare(strict_types=1);
|
|
namespace MRBS\Session;
|
|
|
|
use MRBS\Form\Form;
|
|
use MRBS\User;
|
|
use SimpleSAML\Auth\Simple;
|
|
use function MRBS\auth;
|
|
use function MRBS\this_page;
|
|
use function MRBS\url_base;
|
|
|
|
|
|
/**
|
|
* Session management scheme that delegates everything to a ready configured
|
|
* SimpleSamlPhp instance. You should use this scheme, along with the
|
|
* authentication scheme with the same name, if you want your users to
|
|
* authenticate using SAML Single Sign-on.
|
|
*
|
|
* In config.inc.php (assuming Active Directory attributes):
|
|
*
|
|
* $auth['type'] = 'saml';
|
|
* $auth['session'] = 'saml';
|
|
* $auth['saml']['ssp_path'] = '/opt/simplesamlphp';
|
|
* $auth['saml']['authsource'] = 'default-sp';
|
|
* $auth['saml']['attr']['username'] = 'sAMAccountName';
|
|
* $auth['saml']['attr']['mail'] = 'mail';
|
|
* $auth['saml']['attr']['givenName'] = 'givenname';
|
|
* $auth['saml']['attr']['surname'] = 'sn'
|
|
* $auth['saml']['admin']['memberOf'] = ['CN=Domain Admins,CN=Users,DC=example,DC=com'];
|
|
*
|
|
* This scheme assumes that you've already configured SimpleSamlPhp,
|
|
* and that you have set up aliases in your webserver so that SimpleSamlPhp
|
|
* can handle incoming assertions. Refer to the SimpleSamlPhp documentation
|
|
* for more information on how to do that.
|
|
*
|
|
* @see https://simplesamlphp.org/docs/stable/simplesamlphp-install
|
|
* @see https://simplesamlphp.org/docs/stable/simplesamlphp-sp
|
|
*/
|
|
class SessionSaml extends SessionWithLogin
|
|
{
|
|
public $ssp;
|
|
|
|
|
|
public function __construct()
|
|
{
|
|
global $auth;
|
|
|
|
$this->checkTypeMatchesSession();
|
|
|
|
// Check that the config variables have been set
|
|
if (!isset($auth['saml']['ssp_path']))
|
|
{
|
|
throw new \Exception('$auth["saml"]["ssp_path"] must be set in the config file.');
|
|
}
|
|
|
|
if (!isset($auth['saml']['attr']['username']))
|
|
{
|
|
throw new \Exception('$auth["saml"]["attr"]["username"] must be set in the config file.');
|
|
}
|
|
|
|
// Include the SimpleSamlPhp autoloader
|
|
require_once $auth['saml']['ssp_path'] . '/lib/_autoload.php';
|
|
|
|
// Get the SimpleSamlPhp instance for the configured auth source
|
|
$authSource = $auth['saml']['authsource'] ?? 'default-sp';
|
|
|
|
$this->ssp = new \SimpleSAML\Auth\Simple($authSource);
|
|
$this->samesite = self::SAMESITE_LAX;
|
|
parent::__construct();
|
|
}
|
|
|
|
|
|
public function init(int $lifetime) : void
|
|
{
|
|
global $auth;
|
|
|
|
if ($auth['saml']['disable_mrbs_session_init'])
|
|
{
|
|
// If we're using SAML then initialising sessions here can interfere with
|
|
// session handling in some SAML libraries
|
|
return;
|
|
}
|
|
|
|
parent::init($lifetime);
|
|
}
|
|
|
|
// No need to prompt for a name - this is done by SimpleSamlPhp
|
|
public function authGet(?string $target_url=null, ?string $returl=null, ?string $error=null, bool $raw=false) : void
|
|
{
|
|
$this->ssp->requireAuth();
|
|
}
|
|
|
|
|
|
public function getCurrentUser() : ?User
|
|
{
|
|
$current_username = $this->getUsername();
|
|
|
|
return (isset($current_username)) ? auth()->getUser($current_username) : parent::getCurrentUser();
|
|
}
|
|
|
|
|
|
public function getUsername() : ?string
|
|
{
|
|
global $auth;
|
|
|
|
if (!$this->ssp->isAuthenticated())
|
|
{
|
|
return null;
|
|
}
|
|
|
|
$userData = $this->ssp->getAttributes();
|
|
$userNameAttr = $auth['saml']['attr']['username'];
|
|
|
|
return array_key_exists($userNameAttr, $userData) ? $userData[$userNameAttr][0] : null;
|
|
}
|
|
|
|
|
|
public function getLogonFormParams() : ?array
|
|
{
|
|
$target_url = url_base() . this_page(true);
|
|
$url = $this->ssp->getLoginURL($target_url);
|
|
$baseURL = strstr($url, '?', true);
|
|
parse_str(substr(strstr($url, '?'), 1), $params);
|
|
|
|
$result = array(
|
|
'action' => $baseURL,
|
|
'method' => Form::METHOD_GET
|
|
);
|
|
|
|
if (!empty($params))
|
|
{
|
|
$result['hidden_inputs'] = $params;
|
|
}
|
|
|
|
return $result;
|
|
}
|
|
|
|
|
|
public function getLogoffFormParams() : ?array
|
|
{
|
|
$target_url = url_base() . this_page(true);
|
|
$url = $this->ssp->getLogoutURL($target_url);
|
|
$baseURL = strstr($url, '?', true);
|
|
parse_str(substr(strstr($url, '?'), 1), $params);
|
|
|
|
$result = array(
|
|
'action' => $baseURL,
|
|
'method' => Form::METHOD_GET
|
|
);
|
|
|
|
if (!empty($params))
|
|
{
|
|
$result['hidden_inputs'] = $params;
|
|
}
|
|
|
|
return $result;
|
|
}
|
|
|
|
|
|
public function processForm() : void
|
|
{
|
|
// No need to do anything - all handled by SAML
|
|
}
|
|
|
|
}
|