2003-05-09 14:42:42 +02:00
|
|
|
<?php
|
|
|
|
/***************************************************************************
|
|
|
|
* functions_session.inc.php *
|
|
|
|
* ------------------- *
|
2003-08-24 09:40:56 +02:00
|
|
|
* application : PhpWebGallery 1.3 <http://phpwebgallery.net> *
|
|
|
|
* author : Pierrick LE GALL <pierrick@z0rglub.com> *
|
|
|
|
* *
|
|
|
|
* $Id$
|
2003-05-09 14:42:42 +02:00
|
|
|
* *
|
|
|
|
***************************************************************************
|
|
|
|
|
|
|
|
***************************************************************************
|
|
|
|
* *
|
|
|
|
* This program is free software; you can redistribute it and/or modify *
|
|
|
|
* it under the terms of the GNU General Public License as published by *
|
|
|
|
* the Free Software Foundation; *
|
|
|
|
* *
|
|
|
|
***************************************************************************/
|
2003-07-27 10:24:10 +02:00
|
|
|
|
|
|
|
// The function generate_key creates a string with pseudo random characters.
|
|
|
|
// the size of the string depends on the $conf['session_id_size'].
|
|
|
|
// Characters used are a-z A-Z and numerical values. Examples :
|
|
|
|
// "Er4Tgh6", "Rrp08P", "54gj"
|
|
|
|
// input : none (using global variable)
|
|
|
|
// output : $key
|
2003-05-09 14:42:42 +02:00
|
|
|
function generate_key()
|
|
|
|
{
|
|
|
|
global $conf;
|
2003-07-27 10:24:10 +02:00
|
|
|
|
2003-05-09 14:42:42 +02:00
|
|
|
$md5 = md5( substr( microtime(), 2, 6 ).$conf['session_keyword'] );
|
2003-05-18 23:42:32 +02:00
|
|
|
$init = '';
|
2003-05-09 14:42:42 +02:00
|
|
|
for ( $i = 0; $i < strlen( $md5 ); $i++ )
|
|
|
|
{
|
2003-07-27 10:24:10 +02:00
|
|
|
if ( is_numeric( $md5[$i] ) ) $init.= $md5[$i];
|
2003-05-09 14:42:42 +02:00
|
|
|
}
|
|
|
|
$init = substr( $init, 0, 8 );
|
|
|
|
mt_srand( $init );
|
2003-05-18 23:42:32 +02:00
|
|
|
$key = '';
|
2003-05-09 14:42:42 +02:00
|
|
|
for ( $i = 0; $i < $conf['session_id_size']; $i++ )
|
|
|
|
{
|
|
|
|
$c = mt_rand( 0, 2 );
|
2003-07-27 10:24:10 +02:00
|
|
|
if ( $c == 0 ) $key .= chr( mt_rand( 65, 90 ) );
|
|
|
|
else if ( $c == 1 ) $key .= chr( mt_rand( 97, 122 ) );
|
|
|
|
else $key .= mt_rand( 0, 9 );
|
2003-05-09 14:42:42 +02:00
|
|
|
}
|
|
|
|
return $key;
|
|
|
|
}
|
2003-07-27 10:24:10 +02:00
|
|
|
|
|
|
|
// The function create_session finds a non-already-used session key and
|
|
|
|
// returns it once found for the given user.
|
2003-05-13 12:02:06 +02:00
|
|
|
function session_create( $username )
|
2003-05-09 14:42:42 +02:00
|
|
|
{
|
2003-05-17 13:42:03 +02:00
|
|
|
global $conf;
|
2003-07-27 10:24:10 +02:00
|
|
|
// 1. searching an unused session key
|
2003-05-09 14:42:42 +02:00
|
|
|
$id_found = false;
|
|
|
|
while ( !$id_found )
|
|
|
|
{
|
|
|
|
$generated_id = generate_key();
|
|
|
|
$query = 'select id';
|
2003-05-17 13:42:03 +02:00
|
|
|
$query.= ' from '.PREFIX_TABLE.'sessions';
|
2003-05-09 14:42:42 +02:00
|
|
|
$query.= " where id = '".$generated_id."';";
|
|
|
|
$result = mysql_query( $query );
|
|
|
|
if ( mysql_num_rows( $result ) == 0 )
|
|
|
|
{
|
|
|
|
$id_found = true;
|
|
|
|
}
|
|
|
|
}
|
2003-05-13 12:02:06 +02:00
|
|
|
// 2. retrieving id of the username given in parameter
|
2003-05-09 14:42:42 +02:00
|
|
|
$query = 'select id';
|
2003-05-17 13:42:03 +02:00
|
|
|
$query.= ' from '.PREFIX_TABLE.'users';
|
2003-05-13 12:02:06 +02:00
|
|
|
$query.= " where username = '".$username."';";
|
2003-05-09 14:42:42 +02:00
|
|
|
$row = mysql_fetch_array( mysql_query( $query ) );
|
|
|
|
$user_id = $row['id'];
|
2003-05-13 12:02:06 +02:00
|
|
|
// 3. inserting session in database
|
2003-05-17 13:42:03 +02:00
|
|
|
$expiration = $conf['session_time'] * 60 + time();
|
|
|
|
$query = 'insert into '.PREFIX_TABLE.'sessions';
|
2003-05-09 14:42:42 +02:00
|
|
|
$query.= ' (id,user_id,expiration,ip) values';
|
|
|
|
$query.= "('".$generated_id."','".$user_id;
|
2003-05-17 13:42:03 +02:00
|
|
|
$query.= "','".$expiration."','".$_SERVER['REMOTE_ADDR']."');";
|
2003-05-09 14:42:42 +02:00
|
|
|
mysql_query( $query );
|
|
|
|
|
|
|
|
return $generated_id;
|
|
|
|
}
|
|
|
|
|
2003-05-13 12:02:06 +02:00
|
|
|
// add_session_id adds the id of the session to the string given in
|
|
|
|
// parameter as $url. If the session id is the first parameter to the url,
|
|
|
|
// it is preceded by a '?', else it is preceded by a '&'. If the
|
|
|
|
// parameter $redirect is set to true, '&' is used instead of '&'.
|
2003-05-09 14:42:42 +02:00
|
|
|
function add_session_id( $url, $redirect = false )
|
|
|
|
{
|
|
|
|
global $page, $user;
|
2003-07-27 10:24:10 +02:00
|
|
|
|
|
|
|
if ( $user['has_cookie'] ) return $url;
|
|
|
|
|
2003-05-13 12:02:06 +02:00
|
|
|
$amp = '&';
|
2003-05-09 14:42:42 +02:00
|
|
|
if ( $redirect )
|
|
|
|
{
|
2003-05-13 12:02:06 +02:00
|
|
|
$amp = '&';
|
2003-05-09 14:42:42 +02:00
|
|
|
}
|
|
|
|
if ( !$user['is_the_guest'] )
|
|
|
|
{
|
2003-05-13 12:02:06 +02:00
|
|
|
if ( preg_match( '/\.php\?/',$url ) )
|
2003-05-09 14:42:42 +02:00
|
|
|
{
|
2003-05-13 12:02:06 +02:00
|
|
|
return $url.$amp.'id='.$page['session_id'];
|
2003-05-09 14:42:42 +02:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2003-05-13 12:02:06 +02:00
|
|
|
return $url.'?id='.$page['session_id'];
|
2003-05-09 14:42:42 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
return $url;
|
|
|
|
}
|
|
|
|
}
|
2003-07-27 10:24:10 +02:00
|
|
|
|
|
|
|
// cookie_path returns the path to use for the PhpWebGallery cookie.
|
|
|
|
// If PhpWebGallery is installed on :
|
|
|
|
// http://domain.org/meeting/gallery/category.php
|
|
|
|
// cookie_path will return : "/meeting/gallery"
|
|
|
|
function cookie_path()
|
|
|
|
{
|
|
|
|
return substr($_SERVER['PHP_SELF'],0,strrpos( $_SERVER['PHP_SELF'],'/'));
|
|
|
|
}
|
2003-05-09 14:42:42 +02:00
|
|
|
?>
|