1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
/* |
4
|
|
|
* This file is part of Jitamin. |
5
|
|
|
* |
6
|
|
|
* Copyright (C) Jitamin Team |
7
|
|
|
* |
8
|
|
|
* For the full copyright and license information, please view the LICENSE |
9
|
|
|
* file that was distributed with this source code. |
10
|
|
|
*/ |
11
|
|
|
|
12
|
|
|
namespace Jitamin\Foundation\Session; |
13
|
|
|
|
14
|
|
|
use Jitamin\Foundation\Base; |
15
|
|
|
|
16
|
|
|
/** |
17
|
|
|
* Session Manager. |
18
|
|
|
*/ |
19
|
|
|
class SessionManager extends Base |
20
|
|
|
{ |
21
|
|
|
/** |
22
|
|
|
* Event names. |
23
|
|
|
* |
24
|
|
|
* @var string |
25
|
|
|
*/ |
26
|
|
|
const EVENT_DESTROY = 'session.destroy'; |
27
|
|
|
|
28
|
|
|
/** |
29
|
|
|
* Return true if the session is open. |
30
|
|
|
* |
31
|
|
|
* @static |
32
|
|
|
* |
33
|
|
|
* @return bool |
34
|
|
|
*/ |
35
|
|
|
public static function isOpen() |
36
|
|
|
{ |
37
|
|
|
return session_id() !== ''; |
38
|
|
|
} |
39
|
|
|
|
40
|
|
|
/** |
41
|
|
|
* Create a new session. |
42
|
|
|
*/ |
43
|
|
|
public function open() |
|
|
|
|
44
|
|
|
{ |
45
|
|
|
$this->configure(); |
46
|
|
|
|
47
|
|
|
if (ini_get('session.auto_start') == 1) { |
48
|
|
|
session_destroy(); |
49
|
|
|
} |
50
|
|
|
|
51
|
|
|
session_name('JM_SID'); |
52
|
|
|
session_start(); |
53
|
|
|
|
54
|
|
|
$this->sessionStorage->setStorage($_SESSION); |
|
|
|
|
55
|
|
|
} |
56
|
|
|
|
57
|
|
|
/** |
58
|
|
|
* Destroy the session. |
59
|
|
|
*/ |
60
|
|
|
public function close() |
61
|
|
|
{ |
62
|
|
|
$this->dispatcher->dispatch(self::EVENT_DESTROY); |
|
|
|
|
63
|
|
|
|
64
|
|
|
// Destroy the session cookie |
65
|
|
|
$params = session_get_cookie_params(); |
66
|
|
|
|
67
|
|
|
setcookie( |
68
|
|
|
session_name(), |
69
|
|
|
'', |
70
|
|
|
time() - 42000, |
71
|
|
|
$params['path'], |
72
|
|
|
$params['domain'], |
73
|
|
|
$params['secure'], |
74
|
|
|
$params['httponly'] |
75
|
|
|
); |
76
|
|
|
|
77
|
|
|
session_unset(); |
78
|
|
|
session_destroy(); |
79
|
|
|
} |
80
|
|
|
|
81
|
|
|
/** |
82
|
|
|
* Define session settings. |
83
|
|
|
*/ |
84
|
|
|
private function configure() |
85
|
|
|
{ |
86
|
|
|
// Session cookie: HttpOnly and secure flags |
87
|
|
|
session_set_cookie_params( |
88
|
|
|
SESSION_DURATION, |
89
|
|
|
$this->helper->url->dir() ?: '/', |
|
|
|
|
90
|
|
|
null, |
91
|
|
|
$this->request->isHTTPS(), |
|
|
|
|
92
|
|
|
true |
93
|
|
|
); |
94
|
|
|
|
95
|
|
|
// Avoid session id in the URL |
96
|
|
|
ini_set('session.use_only_cookies', '1'); |
97
|
|
|
ini_set('session.use_trans_sid', '0'); |
98
|
|
|
|
99
|
|
|
// Enable strict mode |
100
|
|
|
ini_set('session.use_strict_mode', '1'); |
101
|
|
|
|
102
|
|
|
// Better session hash |
103
|
|
|
ini_set('session.hash_function', '1'); // 'sha512' is not compatible with FreeBSD, only MD5 '0' and SHA-1 '1' seems to work |
104
|
|
|
ini_set('session.hash_bits_per_character', 6); |
105
|
|
|
|
106
|
|
|
// Set an additional entropy |
107
|
|
|
ini_set('session.entropy_file', '/dev/urandom'); |
108
|
|
|
ini_set('session.entropy_length', '256'); |
109
|
|
|
} |
110
|
|
|
} |
111
|
|
|
|
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: