S.php 4.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164
  1. <?php
  2. require_once dirname(__FILE__) . '/' . 'Lib.php';
  3. Lib::loadClass('V');
  4. Lib::loadClass('User');
  5. /**
  6. * SESSION timeout.
  7. *
  8. * @use $_SESSION['USER_SESSION_EXPIRE'] = 1800;// TODO: read from DB - ADMIN_USERS in authorize user or default value 30 min
  9. * @use $_SESSION['USER_SESSION_LAST_ACTIVITY'] = ;
  10. *
  11. */
  12. class S {
  13. public static function init() {
  14. @session_start();// PHP Notice: A session had already been started - ignoring session_start()
  15. $ses_keys = array();
  16. $ses_keys[] = 'DEBUG';
  17. $ses_keys[] = 'USER_PROFILE';
  18. $ses_keys[] = 'CURRENT_MENU';
  19. $ses_keys[] = 'LAST_MENU';
  20. $ses_keys[] = 'LAST1_MENU';
  21. $ses_keys[] = 'THIS';
  22. $ses_keys[] = 'LAST_FUNCTION';
  23. $ses_keys[] = 'LAST1_FUNCTION';
  24. $ses_keys[] = 'CURRENT_FUNCTION';
  25. $ses_keys[] = 'USER_SESSION_LAST_ACTIVITY';
  26. $ses_keys[] = 'USER_SESSION_EXPIRE';
  27. foreach ($ses_keys as $k) {
  28. if (!isset($_SESSION[$k])) $_SESSION[$k] = null;
  29. }
  30. self::timeoutFetch();
  31. }
  32. public static function get($key) {
  33. $null = null;
  34. return (isset($_SESSION[$key]))? $_SESSION[$key] : $null;
  35. }
  36. /**
  37. * TODO: ustalic czas trwania sesji np. wg. stanowiska
  38. */
  39. public static function timeoutFetch() {
  40. if (empty($_SESSION['USER_SESSION_EXPIRE']) || $_SESSION['USER_SESSION_EXPIRE'] <= 0) {
  41. $_SESSION['USER_SESSION_EXPIRE'] = ini_get('session.gc_maxlifetime');//1800 - 3min
  42. }
  43. if (empty($_SESSION['USER_SESSION_LAST_ACTIVITY'])) {
  44. $_SESSION['USER_SESSION_LAST_ACTIVITY'] = time();
  45. }
  46. }
  47. /**
  48. * Check if user is logged in, and how much time not clicked.
  49. */
  50. public static function timeoutCheck() {
  51. if (!User::logged()) {// if not logged in dont check timeout
  52. return false;
  53. }
  54. $time = time();
  55. $last_activity = V::get('USER_SESSION_LAST_ACTIVITY', 0, $_SESSION, 'int');
  56. if ($last_activity <= 0) {// error last activity not set
  57. return false;
  58. }
  59. $ses_expire = V::get('USER_SESSION_EXPIRE', 0, $_SESSION, 'int');
  60. if (!$ses_expire) {// error expire not set
  61. return false;
  62. }
  63. if ($time - $last_activity > $ses_expire) {
  64. // last request was more than 30 minates ago
  65. self::destroy();
  66. return false;
  67. } else {
  68. return true;
  69. }
  70. }
  71. public static function destroy() {
  72. session_destroy();// destroy session data in storage
  73. session_unset();// unset $_SESSION variable for the runtime
  74. }
  75. public static function timeout_update() {// TODO: legacy
  76. self::timeoutUpdate();
  77. }
  78. public static function timeoutUpdate($force = false) {
  79. if ($force) {
  80. $_SESSION['USER_SESSION_LAST_ACTIVITY'] = time();
  81. return true;
  82. }
  83. else if (self::timeoutCheck()) {
  84. $_SESSION['USER_SESSION_LAST_ACTIVITY'] = time();
  85. return true;
  86. }
  87. return false;
  88. }
  89. public static function timeoutGet() {
  90. if (self::timeoutCheck()) {
  91. $ret = $_SESSION['USER_SESSION_EXPIRE'] - (time() - $_SESSION['USER_SESSION_LAST_ACTIVITY']);
  92. } else {
  93. $ret = 'expired';
  94. }
  95. return $ret;
  96. }
  97. public static function show_session_timer() {
  98. echo '<code id="'."session-timer".'" style="padding:2px 5px;font-weight:normal;color:red;" title="Czas sesji">'."".'</code>';
  99. }
  100. public static function timeout_update_js() {
  101. self::printTimeoutUpdateJs();
  102. }
  103. public static function printTimeoutUpdateJs() {
  104. if (!User::logged()) {
  105. return;
  106. }
  107. UI::inlineJS( __FILE__ . ".sessionTimer.js", [
  108. 'BASE_URL' => Request::getPathUri(),
  109. 'USER_SESSION_EXPIRE' => V::get('USER_SESSION_EXPIRE', 0, $_SESSION, 'int'),
  110. 'SESSION_TIMER_URL' => "session-expire.php?task=getTimer",
  111. 'SESSION_AUTH_STATUS_URL' => "session-expire.php?task=getAuthStatus",
  112. 'USER_LOGIN' => User::getLogin(),
  113. ] );
  114. }
  115. static function printLogoutJs() {
  116. UI::inlineJS( __FILE__ . ".expiredSessionTimer.js", [
  117. 'BASE_URL' => Request::getPathUri(),
  118. ] );
  119. }
  120. static function getAuthStatus() {
  121. if (!self::timeoutCheck()) return [ 'status' => "expired" ];
  122. $currentTime = time();
  123. return [
  124. 'type' => "logged_in",
  125. 'login' => User::getLogin(),
  126. 'expire' => $_SESSION['USER_SESSION_EXPIRE'] - ($currentTime - $_SESSION['USER_SESSION_LAST_ACTIVITY']),
  127. 'time' => $currentTime,
  128. ];
  129. }
  130. static function saveUserMessage($className, $message) {
  131. return self::_userMessage('set', $className, $message);
  132. }
  133. static function getUserMessage() {
  134. return self::_userMessage('get');
  135. }
  136. static function _userMessage($action, $className = '', $message = '') {
  137. static $_msg = null;
  138. switch ($action) {
  139. case 'set': $_msg = [ $className, $message ]; return;
  140. case 'get': $ret = ($_msg) ? [ $_msg[0], $_msg[1] ] : null; $_msg = null; return $ret;
  141. }
  142. }
  143. }