cvs: bugtracker /htdocs config.php /htdocs/index index.php /includes cache.php template.php user.php /template/generic/user login.php
| From: | Barry Carlyon | Date: | Tue, 12 Aug 2008 16:30:21 +0000 |
| Subject: | cvs: bugtracker /htdocs config.php /htdocs/index index.php /includes cache.php template.php user.php /template/generic/user login.php | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-2382@lists.php.net to get a copy of this message | ||
bcarlyon Tue Aug 12 16:30:21 2008 UTC
Modified files:
/bugtracker/htdocs config.php
/bugtracker/htdocs/index index.php
/bugtracker/includes cache.php template.php user.php
/bugtracker/template/generic/user login.php
Log:
Its the session manager, now if you login it creates and maintains your session between page
loads.
Terminates the sesson after 15mins of inactivity using cookies
Uses a tasty hash to generate a session ID for security
http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/config.php?r1=1.7&r2=1.8&diff_format=u Index: bugtracker/htdocs/config.php diff -u bugtracker/htdocs/config.php:1.7 bugtracker/htdocs/config.php:1.8 --- bugtracker/htdocs/config.php:1.7 Mon Aug 11 10:51:22 2008 +++ bugtracker/htdocs/config.php Tue Aug 12 16:30:20 2008 @@ -41,6 +41,8 @@ define('USER_TABLE', 'user'); define('TEMP_USER_TABLE', 'temp_account'); +define('SESSION_TABLE', 'sessions'); + // partial implemneted define define('BUG_TABLE', 'bug'); define('COMMENT_TABLE', 'bug_comment'); http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/index/index.php?r1=1.21&r2=1.22&diff_format=u Index: bugtracker/htdocs/index/index.php diff -u bugtracker/htdocs/index/index.php:1.21 bugtracker/htdocs/index/index.php:1.22 --- bugtracker/htdocs/index/index.php:1.21 Mon Aug 11 10:51:22 2008 +++ bugtracker/htdocs/index/index.php Tue Aug 12 16:30:21 2008 @@ -63,6 +63,7 @@ include($_SERVER['DOCUMENT_ROOT'] . '../includes/bug.php'); include($_SERVER['DOCUMENT_ROOT'] . '../includes/comment.php'); include($_SERVER['DOCUMENT_ROOT'] . '../includes/cache.php'); +include($_SERVER['DOCUMENT_ROOT'] . '../includes/session.php'); $template = new template(); $user = new user(); @@ -70,13 +71,14 @@ $bug = new bug(); $comment = new comment(); $cache = new cache(); +$session = new session(); //cache! $cache->load_cache(); -$template->initialize(); - //now then is the user logged in? $user->check_auth(); +$template->initialize(); +$session->initialize(); //this is where we do stuff //its related to the page we are requesting from the server http://cvs.php.net/viewvc.cgi/bugtracker/includes/cache.php?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/includes/cache.php diff -u bugtracker/includes/cache.php:1.9 bugtracker/includes/cache.php:1.10 --- bugtracker/includes/cache.php:1.9 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/cache.php Tue Aug 12 16:30:21 2008 @@ -54,7 +54,7 @@ $thiscache = $ref[0]; $cacher = array(); - trace('loading cache: ' . $file); + //trace('loading cache: ' . $file); include($_SERVER['DOCUMENT_ROOT'] . '../includes/cache/' . $file); $generated_cache = array(); http://cvs.php.net/viewvc.cgi/bugtracker/includes/template.php?r1=1.15&r2=1.16&diff_format=u Index: bugtracker/includes/template.php diff -u bugtracker/includes/template.php:1.15 bugtracker/includes/template.php:1.16 --- bugtracker/includes/template.php:1.15 Mon Aug 11 19:49:49 2008 +++ bugtracker/includes/template.php Tue Aug 12 16:30:21 2008 @@ -87,6 +87,10 @@ $this->get = $_GET; $this->post = $_POST; $this->cookie = $_COOKIE; + + $this->page = $this->request['page'] ? $this->request['page'] : 'home'; + + return; } // this function will create the head element <title> or at least the content within it @@ -132,8 +136,6 @@ $backtrace = '<div id="error">' . $backtrace . '</div>'; $this->swap('backtrace', $backtrace ); - $this->swap('login', $this->login ); - if ($this->system_error) { $this->system_error = '<div id="error">' . $this->system_error . '</div>'; @@ -165,7 +167,7 @@ $this->html .= $this->prehtml; $this->generate_footer(); - $this->logged_in(); + $this->logged_in();// only affects copiled html so not the logn string!! //need to strip any existing {} // $this->html = preg_replace("[\{[\w\d].*\}]", '', $this->html); // $this->html = preg_replace("[\{[\w\d].*\}[\s]]", '', $this->html); @@ -315,7 +317,7 @@ $base_directory = $_SERVER['DOCUMENT_ROOT'] . '../template/'; $base_this = $base_directory . $this->template_dir . '/'; - $this->page = $this->request['page'] ? $this->request['page'] : 'home'; +// $this->page = $this->request['page'] ? $this->request['page'] : 'home'; if (substr($this->page,-1,1) == '/') { $this->page = substr($this->page, 0, -1); @@ -415,6 +417,12 @@ $this->html = $new_html; } + if ($user->logged_in) + { + $this->login = '<li>LOGGED IN</li>'; + } + $this->swap('login', $this->login ); + return; } } http://cvs.php.net/viewvc.cgi/bugtracker/includes/user.php?r1=1.13&r2=1.14&diff_format=u Index: bugtracker/includes/user.php diff -u bugtracker/includes/user.php:1.13 bugtracker/includes/user.php:1.14 --- bugtracker/includes/user.php:1.13 Mon Aug 11 19:49:49 2008 +++ bugtracker/includes/user.php Tue Aug 12 16:30:21 2008 @@ -34,7 +34,7 @@ public $handle = ''; function check_auth() { - global $cookie; + global $cookie, $session; //read cookie if (isset($_COOKIE[$cookie['name']])) { @@ -46,7 +46,14 @@ $this->handle = $data[1]; //no further auth required trace('cookie: ' . $data[0] . ' -- ' . $data[1]); - } + } elseif ($data[0] == 'session') { + //woo session!! + trace('session detected'); + $session->cookie_session_id = $data[1]; + } + } else { +//if ($data[0] == 'rememberme') { +// } } return; @@ -224,7 +231,7 @@ return TRUE; } function login($user,$password) { - global $form_data,$db,$template; + global $form_data,$db,$template,$session; //lets authenticate the user $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE (handle = \'' . $db->protect_data($user) . '\' OR email = \'' . $db->protect_data($user) . '\') AND password = \'' . $password . '\''; @@ -242,12 +249,15 @@ } $this->handle = $user_row['handle']; - if ($this->write_cookie('',$form_data['return'])) + //instigate a session! + $this->handle = $user_row['handle']; + if ($session->create_session()) { - $user->logged_in = TRUE; + $this->logged_in = TRUE; return TRUE; } - $template->system_error = 'The Cookie could not be set'; + $template->system_error = 'Your session could not be created'; + return FALSE; } //try temp @@ -259,7 +269,7 @@ $this->handle = $user_row['handle']; //temp account login! //set a cookie - if ($this->write_cookie(array('handle' => $this->handle),TEMP_ACCOUNT)) + if ($this->write_cookie(TEMP_ACCOUNT)) { //convert? header('Location: /user/convert/'); @@ -280,7 +290,8 @@ } - function write_cookie($user_data, $type = 'user', $redirect = FALSE) +// function write_cookie($user_data, $type = 'user') + function write_cookie($type = 'user', $data = '', $name_append = '', $timeout = 0) { global $cookie; if ($type == TEMP_ACCOUNT) @@ -290,14 +301,13 @@ return TRUE; } } - else if (setcookie('php_bugz','temp',time() + (15*60), '/', str_replace('www.','',$_SERVER['HTTP_HOST']), 0)) + else if ($data) { - $this->logged_in = TRUE; - if ($redirect) + $timeout = $timeout ? $timeout : time() + (15 * 60); + if (setcookie($cookie['name'] . $name_append, $data, $timeout, '/', str_replace('www.','',$_SERVER['HTTP_HOST']), 0)) { - header('Location: ' . $redirect); + return TRUE; } - return TRUE; } return FALSE; } http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/login.php?r1=1.7&r2=1.8&diff_format=u Index: bugtracker/template/generic/user/login.php diff -u bugtracker/template/generic/user/login.php:1.7 bugtracker/template/generic/user/login.php:1.8 --- bugtracker/template/generic/user/login.php:1.7 Mon Aug 11 22:04:00 2008 +++ bugtracker/template/generic/user/login.php Tue Aug 12 16:30:21 2008 @@ -65,8 +65,10 @@ //call login if ($user->login($username,$password)) { -echo '@ user->login'; -exit; +//echo '@ user->login here needs to be session management of some description'; +//exit; + $content = '<div id="success">You have logged in successfully, <a href="' . $form_data['return'] . '">Return</a></div>'; + $template->meta_refresh($form_data['return']); break; } @@ -85,8 +87,10 @@ <br /><br /> <label for="password" >Password:</label> <input type="password" name="password" id="password" /> <br /><br /> +<!-- <label for="remember" >Remember:</label> <input type="checkbox" name="remember" id="remember" {FORM_REMEMBER} /> <br /><br /> +--> <input type="submit" name="submit" id="submit" value="Submit" /> <br /><br /><a href="/user/help/">Account Support</a> </div>
http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/config.php?r1=1.7&r2=1.8&diff_format=u Index: bugtracker/htdocs/config.php diff -u bugtracker/htdocs/config.php:1.7 bugtracker/htdocs/config.php:1.8 --- bugtracker/htdocs/config.php:1.7 Mon Aug 11 10:51:22 2008 +++ bugtracker/htdocs/config.php Tue Aug 12 16:30:20 2008 @@ -41,6 +41,8 @@ define('USER_TABLE', 'user'); define('TEMP_USER_TABLE', 'temp_account'); +define('SESSION_TABLE', 'sessions'); + // partial implemneted define define('BUG_TABLE', 'bug'); define('COMMENT_TABLE', 'bug_comment'); http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/index/index.php?r1=1.21&r2=1.22&diff_format=u Index: bugtracker/htdocs/index/index.php diff -u bugtracker/htdocs/index/index.php:1.21 bugtracker/htdocs/index/index.php:1.22 --- bugtracker/htdocs/index/index.php:1.21 Mon Aug 11 10:51:22 2008 +++ bugtracker/htdocs/index/index.php Tue Aug 12 16:30:21 2008 @@ -63,6 +63,7 @@ include($_SERVER['DOCUMENT_ROOT'] . '../includes/bug.php'); include($_SERVER['DOCUMENT_ROOT'] . '../includes/comment.php'); include($_SERVER['DOCUMENT_ROOT'] . '../includes/cache.php'); +include($_SERVER['DOCUMENT_ROOT'] . '../includes/session.php'); $template = new template(); $user = new user(); @@ -70,13 +71,14 @@ $bug = new bug(); $comment = new comment(); $cache = new cache(); +$session = new session(); //cache! $cache->load_cache(); -$template->initialize(); - //now then is the user logged in? $user->check_auth(); +$template->initialize(); +$session->initialize(); //this is where we do stuff //its related to the page we are requesting from the server http://cvs.php.net/viewvc.cgi/bugtracker/includes/cache.php?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/includes/cache.php diff -u bugtracker/includes/cache.php:1.9 bugtracker/includes/cache.php:1.10 --- bugtracker/includes/cache.php:1.9 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/cache.php Tue Aug 12 16:30:21 2008 @@ -54,7 +54,7 @@ $thiscache = $ref[0]; $cacher = array(); - trace('loading cache: ' . $file); + //trace('loading cache: ' . $file); include($_SERVER['DOCUMENT_ROOT'] . '../includes/cache/' . $file); $generated_cache = array(); http://cvs.php.net/viewvc.cgi/bugtracker/includes/template.php?r1=1.15&r2=1.16&diff_format=u Index: bugtracker/includes/template.php diff -u bugtracker/includes/template.php:1.15 bugtracker/includes/template.php:1.16 --- bugtracker/includes/template.php:1.15 Mon Aug 11 19:49:49 2008 +++ bugtracker/includes/template.php Tue Aug 12 16:30:21 2008 @@ -87,6 +87,10 @@ $this->get = $_GET; $this->post = $_POST; $this->cookie = $_COOKIE; + + $this->page = $this->request['page'] ? $this->request['page'] : 'home'; + + return; } // this function will create the head element <title> or at least the content within it @@ -132,8 +136,6 @@ $backtrace = '<div id="error">' . $backtrace . '</div>'; $this->swap('backtrace', $backtrace ); - $this->swap('login', $this->login ); - if ($this->system_error) { $this->system_error = '<div id="error">' . $this->system_error . '</div>'; @@ -165,7 +167,7 @@ $this->html .= $this->prehtml; $this->generate_footer(); - $this->logged_in(); + $this->logged_in();// only affects copiled html so not the logn string!! //need to strip any existing {} // $this->html = preg_replace("[\{[\w\d].*\}]", '', $this->html); // $this->html = preg_replace("[\{[\w\d].*\}[\s]]", '', $this->html); @@ -315,7 +317,7 @@ $base_directory = $_SERVER['DOCUMENT_ROOT'] . '../template/'; $base_this = $base_directory . $this->template_dir . '/'; - $this->page = $this->request['page'] ? $this->request['page'] : 'home'; +// $this->page = $this->request['page'] ? $this->request['page'] : 'home'; if (substr($this->page,-1,1) == '/') { $this->page = substr($this->page, 0, -1); @@ -415,6 +417,12 @@ $this->html = $new_html; } + if ($user->logged_in) + { + $this->login = '<li>LOGGED IN</li>'; + } + $this->swap('login', $this->login ); + return; } } http://cvs.php.net/viewvc.cgi/bugtracker/includes/user.php?r1=1.13&r2=1.14&diff_format=u Index: bugtracker/includes/user.php diff -u bugtracker/includes/user.php:1.13 bugtracker/includes/user.php:1.14 --- bugtracker/includes/user.php:1.13 Mon Aug 11 19:49:49 2008 +++ bugtracker/includes/user.php Tue Aug 12 16:30:21 2008 @@ -34,7 +34,7 @@ public $handle = ''; function check_auth() { - global $cookie; + global $cookie, $session; //read cookie if (isset($_COOKIE[$cookie['name']])) { @@ -46,7 +46,14 @@ $this->handle = $data[1]; //no further auth required trace('cookie: ' . $data[0] . ' -- ' . $data[1]); - } + } elseif ($data[0] == 'session') { + //woo session!! + trace('session detected'); + $session->cookie_session_id = $data[1]; + } + } else { +//if ($data[0] == 'rememberme') { +// } } return; @@ -224,7 +231,7 @@ return TRUE; } function login($user,$password) { - global $form_data,$db,$template; + global $form_data,$db,$template,$session; //lets authenticate the user $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE (handle = \'' . $db->protect_data($user) . '\' OR email = \'' . $db->protect_data($user) . '\') AND password = \'' . $password . '\''; @@ -242,12 +249,15 @@ } $this->handle = $user_row['handle']; - if ($this->write_cookie('',$form_data['return'])) + //instigate a session! + $this->handle = $user_row['handle']; + if ($session->create_session()) { - $user->logged_in = TRUE; + $this->logged_in = TRUE; return TRUE; } - $template->system_error = 'The Cookie could not be set'; + $template->system_error = 'Your session could not be created'; + return FALSE; } //try temp @@ -259,7 +269,7 @@ $this->handle = $user_row['handle']; //temp account login! //set a cookie - if ($this->write_cookie(array('handle' => $this->handle),TEMP_ACCOUNT)) + if ($this->write_cookie(TEMP_ACCOUNT)) { //convert? header('Location: /user/convert/'); @@ -280,7 +290,8 @@ } - function write_cookie($user_data, $type = 'user', $redirect = FALSE) +// function write_cookie($user_data, $type = 'user') + function write_cookie($type = 'user', $data = '', $name_append = '', $timeout = 0) { global $cookie; if ($type == TEMP_ACCOUNT) @@ -290,14 +301,13 @@ return TRUE; } } - else if (setcookie('php_bugz','temp',time() + (15*60), '/', str_replace('www.','',$_SERVER['HTTP_HOST']), 0)) + else if ($data) { - $this->logged_in = TRUE; - if ($redirect) + $timeout = $timeout ? $timeout : time() + (15 * 60); + if (setcookie($cookie['name'] . $name_append, $data, $timeout, '/', str_replace('www.','',$_SERVER['HTTP_HOST']), 0)) { - header('Location: ' . $redirect); + return TRUE; } - return TRUE; } return FALSE; } http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/login.php?r1=1.7&r2=1.8&diff_format=u Index: bugtracker/template/generic/user/login.php diff -u bugtracker/template/generic/user/login.php:1.7 bugtracker/template/generic/user/login.php:1.8 --- bugtracker/template/generic/user/login.php:1.7 Mon Aug 11 22:04:00 2008 +++ bugtracker/template/generic/user/login.php Tue Aug 12 16:30:21 2008 @@ -65,8 +65,10 @@ //call login if ($user->login($username,$password)) { -echo '@ user->login'; -exit; +//echo '@ user->login here needs to be session management of some description'; +//exit; + $content = '<div id="success">You have logged in successfully, <a href="' . $form_data['return'] . '">Return</a></div>'; + $template->meta_refresh($form_data['return']); break; } @@ -85,8 +87,10 @@ <br /><br /> <label for="password" >Password:</label> <input type="password" name="password" id="password" /> <br /><br /> +<!-- <label for="remember" >Remember:</label> <input type="checkbox" name="remember" id="remember" {FORM_REMEMBER} /> <br /><br /> +--> <input type="submit" name="submit" id="submit" value="Submit" /> <br /><br /><a href="/user/help/">Account Support</a> </div>