DRY: set (secure) cookies using rcmail::setcookie() + set session.only_use_cookies

release-0.6
thomascube 16 years ago
parent cc4b36b143
commit cefd1d8c91

@ -52,6 +52,7 @@ if (set_include_path($include_path) === false) {
ini_set('session.name', 'roundcube_sessid'); ini_set('session.name', 'roundcube_sessid');
ini_set('session.use_cookies', 1); ini_set('session.use_cookies', 1);
ini_set('session.only_use_cookies', 1);
ini_set('session.gc_maxlifetime', 21600); ini_set('session.gc_maxlifetime', 21600);
ini_set('session.gc_divisor', 500); ini_set('session.gc_divisor', 500);
ini_set('error_reporting', E_ALL&~E_NOTICE); ini_set('error_reporting', E_ALL&~E_NOTICE);

@ -728,9 +728,7 @@ class rcmail
if (!$valid || ($_SERVER['REQUEST_METHOD']!='POST' && $now - $_SESSION['auth_time'] > 300)) { if (!$valid || ($_SERVER['REQUEST_METHOD']!='POST' && $now - $_SESSION['auth_time'] > 300)) {
$_SESSION['last_auth'] = $_SESSION['auth_time']; $_SESSION['last_auth'] = $_SESSION['auth_time'];
$_SESSION['auth_time'] = $now; $_SESSION['auth_time'] = $now;
$cookie = session_get_cookie_params(); rcmail::setcookie('sessauth', $this->get_auth_hash(session_id(), $now), 0);
setcookie('sessauth', $this->get_auth_hash(session_id(), $now), 0, $cookie['path'],
$cookie['domain'], $_SERVER['HTTPS'] && ($_SERVER['HTTPS']!='off'));
} }
} }
else { else {
@ -753,7 +751,7 @@ class rcmail
public function kill_session() public function kill_session()
{ {
$_SESSION = array('language' => $this->user->language, 'auth_time' => time(), 'temp' => true); $_SESSION = array('language' => $this->user->language, 'auth_time' => time(), 'temp' => true);
setcookie('sessauth', '-del-', time() - 60); rcmail::setcookie('sessauth', '-del-', time() - 60);
$this->user->reset(); $this->user->reset();
} }
@ -911,6 +909,21 @@ class rcmail
} }
return $url; return $url;
} }
/**
* Helper method to set a cookie with the current path and host settings
*
* @param string Cookie name
* @param string Cookie value
* @param string Expiration time
*/
public static function setcookie($name, $value, $exp = 0)
{
$cookie = session_get_cookie_params();
setcookie($name, $value, $exp, $cookie['path'], $cookie['domain'],
($_SERVER['HTTPS'] && ($_SERVER['HTTPS'] != 'off')));
}
} }

@ -183,9 +183,7 @@ function rcube_sess_regenerate_id()
$cookie = session_get_cookie_params(); $cookie = session_get_cookie_params();
$lifetime = $cookie['lifetime'] ? time() + $cookie['lifetime'] : 0; $lifetime = $cookie['lifetime'] ? time() + $cookie['lifetime'] : 0;
setcookie(session_name(), '', time() - 3600); rcmail::setcookie(session_name(), $random, $lifetime);
setcookie(session_name(), $random, $lifetime, $cookie['path'], $cookie['domain'],
$_SERVER['HTTPS'] && ($_SERVER['HTTPS']!='off'));
return true; return true;
} }

Loading…
Cancel
Save