1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
|
<?php
require_once('config.php');
@mkdir(CONFIG_SESSION_DIR, 0700, true);
@chmod(CONFIG_SESSION_DIR, 0700);
if (!is_writable(CONFIG_SESSION_DIR)) die('Config error: Session Path not writable!');
class Session
{
private static $sid = false;
private static $data = false;
private static function generateSessionId($salt)
{
if (self::$sid !== false) Util::traceError('Error: Asked to generate session id when already set.');
self::$sid = sha1($salt . ','
. mt_rand(0, 65535)
. $_SERVER['REMOTE_ADDR']
. mt_rand(0, 65535)
. $_SERVER['REMOTE_PORT']
. mt_rand(0, 65535)
. $_SERVER['HTTP_USER_AGENT']
. mt_rand(0, 65535)
. microtime(true)
. mt_rand(0, 65535)
);
}
public static function create($salt = '')
{
self::generateSessionId($salt);
self::$data = array();
}
public static function load()
{
// Try to load session id from cookie
if (!self::loadSessionId()) return false;
// Succeded, now try to load session data. If successful, job is done
if (self::readSessionData()) return true;
// Loading session data failed
self::delete();
return false;
}
public static function get($key)
{
if (!isset(self::$data[$key])) return false;
return self::$data[$key];
}
public static function set($key, $value)
{
if (self::$data === false) Util::traceError('Tried to set session data with no active session');
if ($value === false) {
unset(self::$data[$key]);
} else {
self::$data[$key] = $value;
}
}
private static function loadSessionId()
{
if (self::$sid !== false) die('Error: Asked to load session id when already set.');
if (empty($_COOKIE['sid'])) return false;
$id = preg_replace('/[^a-zA-Z0-9]/', '', $_COOKIE['sid']);
if (empty($id)) return false;
self::$sid = $id;
return true;
}
public static function delete()
{
if (self::$sid === false) return;
@unlink(self::getSessionFile());
@setcookie('sid', '', time() - 8640000, null, null, !empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off', true);
self::$sid = false;
self::$data = false;
}
private static function getSessionFile()
{
if (self::$sid === false) Util::traceError('Error: Tried to access session file when no session id was set.');
return CONFIG_SESSION_DIR . '/' . self::$sid;
}
private static function readSessionData()
{
if (self::$data !== false) Util::traceError('Tried to call read session data twice');
$sessionfile = self::getSessionFile();
if (!is_readable($sessionfile) || filemtime($sessionfile) + CONFIG_SESSION_TIMEOUT < time()) {
@unlink($sessionfile);
return false;
}
self::$data = @unserialize(@file_get_contents($sessionfile));
if (self::$data === false) return false;
return true;
}
public static function save()
{
if (self::$sid === false || self::$data === false) return; //Util::traceError('Called saveSession with no active session');
$sessionfile = self::getSessionFile();
$ret = @file_put_contents($sessionfile, @serialize(self::$data));
if (!$ret) Util::traceError('Storing session data in ' . $sessionfile . ' failed.');
$ret = @setcookie('sid', self::$sid, time() + CONFIG_SESSION_TIMEOUT, null, null, !empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off', true);
if (!$ret) Util::traceError('Error: Could not set Cookie for Client (headers already sent)');
}
}
|