|
1
|
|
|
<?php |
|
2
|
|
|
|
|
3
|
|
|
/* |
|
4
|
|
|
* This file is part of Jitamin. |
|
5
|
|
|
* |
|
6
|
|
|
* Copyright (C) Jitamin Team |
|
7
|
|
|
* |
|
8
|
|
|
* For the full copyright and license information, please view the LICENSE |
|
9
|
|
|
* file that was distributed with this source code. |
|
10
|
|
|
*/ |
|
11
|
|
|
|
|
12
|
|
|
namespace Jitamin\Foundation\Session; |
|
13
|
|
|
|
|
14
|
|
|
use Jitamin\Foundation\Base; |
|
15
|
|
|
|
|
16
|
|
|
/** |
|
17
|
|
|
* Session Manager. |
|
18
|
|
|
*/ |
|
19
|
|
|
class SessionManager extends Base |
|
20
|
|
|
{ |
|
21
|
|
|
/** |
|
22
|
|
|
* Event names. |
|
23
|
|
|
* |
|
24
|
|
|
* @var string |
|
25
|
|
|
*/ |
|
26
|
|
|
const EVENT_DESTROY = 'session.destroy'; |
|
27
|
|
|
|
|
28
|
|
|
/** |
|
29
|
|
|
* Return true if the session is open. |
|
30
|
|
|
* |
|
31
|
|
|
* @static |
|
32
|
|
|
* |
|
33
|
|
|
* @return bool |
|
34
|
|
|
*/ |
|
35
|
|
|
public static function isOpen() |
|
36
|
|
|
{ |
|
37
|
|
|
return session_id() !== ''; |
|
38
|
|
|
} |
|
39
|
|
|
|
|
40
|
|
|
/** |
|
41
|
|
|
* Create a new session. |
|
42
|
|
|
*/ |
|
43
|
|
|
public function open() |
|
|
|
|
|
|
44
|
|
|
{ |
|
45
|
|
|
$this->configure(); |
|
46
|
|
|
|
|
47
|
|
|
if (ini_get('session.auto_start') == 1) { |
|
48
|
|
|
session_destroy(); |
|
49
|
|
|
} |
|
50
|
|
|
|
|
51
|
|
|
session_name('JM_SID'); |
|
52
|
|
|
session_start(); |
|
53
|
|
|
|
|
54
|
|
|
$this->sessionStorage->setStorage($_SESSION); |
|
|
|
|
|
|
55
|
|
|
} |
|
56
|
|
|
|
|
57
|
|
|
/** |
|
58
|
|
|
* Destroy the session. |
|
59
|
|
|
*/ |
|
60
|
|
|
public function close() |
|
61
|
|
|
{ |
|
62
|
|
|
$this->dispatcher->dispatch(self::EVENT_DESTROY); |
|
|
|
|
|
|
63
|
|
|
|
|
64
|
|
|
// Destroy the session cookie |
|
65
|
|
|
$params = session_get_cookie_params(); |
|
66
|
|
|
|
|
67
|
|
|
setcookie( |
|
68
|
|
|
session_name(), |
|
69
|
|
|
'', |
|
70
|
|
|
time() - 42000, |
|
71
|
|
|
$params['path'], |
|
72
|
|
|
$params['domain'], |
|
73
|
|
|
$params['secure'], |
|
74
|
|
|
$params['httponly'] |
|
75
|
|
|
); |
|
76
|
|
|
|
|
77
|
|
|
session_unset(); |
|
78
|
|
|
session_destroy(); |
|
79
|
|
|
} |
|
80
|
|
|
|
|
81
|
|
|
/** |
|
82
|
|
|
* Define session settings. |
|
83
|
|
|
*/ |
|
84
|
|
|
private function configure() |
|
85
|
|
|
{ |
|
86
|
|
|
// Session cookie: HttpOnly and secure flags |
|
87
|
|
|
session_set_cookie_params( |
|
88
|
|
|
SESSION_DURATION, |
|
89
|
|
|
$this->helper->url->dir() ?: '/', |
|
|
|
|
|
|
90
|
|
|
null, |
|
91
|
|
|
$this->request->isHTTPS(), |
|
|
|
|
|
|
92
|
|
|
true |
|
93
|
|
|
); |
|
94
|
|
|
|
|
95
|
|
|
// Avoid session id in the URL |
|
96
|
|
|
ini_set('session.use_only_cookies', '1'); |
|
97
|
|
|
ini_set('session.use_trans_sid', '0'); |
|
98
|
|
|
|
|
99
|
|
|
// Enable strict mode |
|
100
|
|
|
ini_set('session.use_strict_mode', '1'); |
|
101
|
|
|
|
|
102
|
|
|
// Better session hash |
|
103
|
|
|
ini_set('session.hash_function', '1'); // 'sha512' is not compatible with FreeBSD, only MD5 '0' and SHA-1 '1' seems to work |
|
104
|
|
|
ini_set('session.hash_bits_per_character', 6); |
|
105
|
|
|
|
|
106
|
|
|
// Set an additional entropy |
|
107
|
|
|
ini_set('session.entropy_file', '/dev/urandom'); |
|
108
|
|
|
ini_set('session.entropy_length', '256'); |
|
109
|
|
|
} |
|
110
|
|
|
} |
|
111
|
|
|
|
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: