mailcow/data/web/inc/sessions.inc.php

98 lines
2.8 KiB
PHP
Raw Normal View History

<?php
// Start session
ini_set("session.cookie_httponly", 1);
ini_set('session.gc_maxlifetime', $SESSION_LIFETIME);
if (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) &&
strtolower($_SERVER['HTTP_X_FORWARDED_PROTO']) == "https") {
ini_set("session.cookie_secure", 1);
$IS_HTTPS = true;
}
elseif (isset($_SERVER['HTTPS'])) {
ini_set("session.cookie_secure", 1);
$IS_HTTPS = true;
}
else {
$IS_HTTPS = false;
}
// session_set_cookie_params($SESSION_LIFETIME, '/', '', $IS_HTTPS, true);
session_start();
2017-05-15 17:37:12 +08:00
if (!isset($_SESSION['CSRF']['TOKEN'])) {
$_SESSION['CSRF']['TOKEN'] = bin2hex(random_bytes(32));
}
2017-05-19 01:45:41 +08:00
// Set session UA
if (!isset($_SESSION['SESS_REMOTE_UA'])) {
$_SESSION['SESS_REMOTE_UA'] = $_SERVER['HTTP_USER_AGENT'];
}
2017-12-09 20:17:15 +08:00
// API
if (!empty($_SERVER['HTTP_X_API_KEY'])) {
$stmt = $pdo->prepare("SELECT `allow_from` FROM `api` WHERE `api_key` = :api_key AND `active` = '1';");
2017-12-09 20:17:15 +08:00
$stmt->execute(array(
':api_key' => preg_replace('/[^a-zA-Z0-9-]/', '', $_SERVER['HTTP_X_API_KEY'])
2017-12-09 20:17:15 +08:00
));
$api_return = $stmt->fetch(PDO::FETCH_ASSOC);
2018-10-17 02:09:01 +08:00
if (!empty($api_return['allow_from'])) {
$remote = get_remote_ip(false);
$allow_from = array_map('trim', preg_split( "/( |,|;|\n)/", $api_return['allow_from']));
if (in_array($remote, $allow_from)) {
$_SESSION['mailcow_cc_username'] = 'API';
2017-12-09 20:17:15 +08:00
$_SESSION['mailcow_cc_role'] = 'admin';
$_SESSION['mailcow_cc_api'] = true;
}
}
}
2017-07-27 05:09:50 +08:00
// Update session cookie
// setcookie(session_name() ,session_id(), time() + $SESSION_LIFETIME);
2017-07-27 05:09:50 +08:00
// Check session
function session_check() {
2017-12-09 20:17:15 +08:00
if ($_SESSION['mailcow_cc_api'] === true) {
return true;
}
if (!isset($_SESSION['SESS_REMOTE_UA']) || ($_SESSION['SESS_REMOTE_UA'] != $_SERVER['HTTP_USER_AGENT'])) {
$_SESSION['return'][] = array(
'type' => 'warning',
'msg' => 'session_ua'
);
return false;
}
2017-05-15 17:37:12 +08:00
if (!empty($_POST)) {
if ($_SESSION['CSRF']['TOKEN'] != $_POST['csrf_token']) {
$_SESSION['return'][] = array(
'type' => 'warning',
'msg' => 'session_token'
);
2017-05-15 17:37:12 +08:00
return false;
}
unset($_POST['csrf_token']);
2017-05-15 17:37:12 +08:00
$_SESSION['CSRF']['TOKEN'] = bin2hex(random_bytes(32));
$_SESSION['CSRF']['TIME'] = time();
}
return true;
}
2017-05-15 17:37:12 +08:00
if (isset($_SESSION['mailcow_cc_role']) && session_check() === false) {
2017-05-15 17:37:12 +08:00
$_POST = array();
$_FILES = array();
}
2017-05-15 17:37:12 +08:00
// Handle logouts
if (isset($_POST["logout"])) {
if (isset($_SESSION["dual-login"])) {
$_SESSION["mailcow_cc_username"] = $_SESSION["dual-login"]["username"];
$_SESSION["mailcow_cc_role"] = $_SESSION["dual-login"]["role"];
unset($_SESSION["dual-login"]);
header("Location: /mailbox");
exit();
2017-05-15 17:37:12 +08:00
}
else {
session_regenerate_id(true);
session_unset();
session_destroy();
session_write_close();
header("Location: /");
}
2017-05-19 01:45:41 +08:00
}