golden hour
/home/doctorbruno/public_html/doctorbruno.info/taeionline/support/include
⬆️ Go Up
Upload
File/Folder
Size
Actions
.MANIFEST
194.97 KB
Del
OK
.htaccess
14 B
Del
OK
JSON.php
33.13 KB
Del
OK
PasswordHash.php
6.92 KB
Del
OK
Spyc.php
31.74 KB
Del
OK
UniversalClassLoader.php
8.61 KB
Del
OK
ajax.admin.php
7.29 KB
Del
OK
ajax.config.php
4.61 KB
Del
OK
ajax.content.php
9.76 KB
Del
OK
ajax.draft.php
13.03 KB
Del
OK
ajax.email.php
2.33 KB
Del
OK
ajax.export.php
1006 B
Del
OK
ajax.filter.php
874 B
Del
OK
ajax.forms.php
13.84 KB
Del
OK
ajax.i18n.php
5.1 KB
Del
OK
ajax.kbase.php
2.93 KB
Del
OK
ajax.note.php
2.05 KB
Del
OK
ajax.orgs.php
11.73 KB
Del
OK
ajax.plugins.php
2.15 KB
Del
OK
ajax.schedule.php
4.29 KB
Del
OK
ajax.search.php
12.72 KB
Del
OK
ajax.sequence.php
3.2 KB
Del
OK
ajax.staff.php
11.62 KB
Del
OK
ajax.tasks.php
33.87 KB
Del
OK
ajax.thread.php
8.81 KB
Del
OK
ajax.tickets.php
79.7 KB
Del
OK
ajax.tips.php
1.66 KB
Del
OK
ajax.upgrader.php
2.24 KB
Del
OK
ajax.users.php
18.33 KB
Del
OK
api.cron.php
1.06 KB
Del
OK
api.tickets.php
10.36 KB
Del
OK
class.2fa.php
7.76 KB
Del
OK
class.ajax.php
1.45 KB
Del
OK
class.api.php
15.31 KB
Del
OK
class.app.php
1.49 KB
Del
OK
class.attachment.php
6.95 KB
Del
OK
class.auth.php
50.73 KB
Del
OK
class.avatar.php
6.44 KB
Del
OK
class.banlist.php
2.58 KB
Del
OK
class.base32.php
4.07 KB
Del
OK
class.businesshours.php
7.08 KB
Del
OK
class.canned.php
9.05 KB
Del
OK
class.captcha.php
1.73 KB
Del
OK
class.category.php
11.14 KB
Del
OK
class.charset.php
3.41 KB
Del
OK
class.cli.php
9.48 KB
Del
OK
class.client.php
15.39 KB
Del
OK
class.collaborator.php
5.65 KB
Del
OK
class.company.php
2.65 KB
Del
OK
class.config.php
60.36 KB
Del
OK
class.controller.php
1.15 KB
Del
OK
class.cron.php
3.6 KB
Del
OK
class.crypto.php
18.92 KB
Del
OK
class.csrf.php
2.38 KB
Del
OK
class.dept.php
33.21 KB
Del
OK
class.dispatcher.php
7.12 KB
Del
OK
class.draft.php
6.23 KB
Del
OK
class.dynamic_forms.php
64.98 KB
Del
OK
class.email.php
49 KB
Del
OK
class.error.php
1.69 KB
Del
OK
class.export.php
32.92 KB
Del
OK
class.faq.php
15.05 KB
Del
OK
class.file.php
34.59 KB
Del
OK
class.filter.php
31.9 KB
Del
OK
class.filter_action.php
23.67 KB
Del
OK
class.format.php
44.3 KB
Del
OK
class.forms.php
195.58 KB
Del
OK
class.http.php
7.16 KB
Del
OK
class.i18n.php
24.28 KB
Del
OK
class.import.php
6.9 KB
Del
OK
class.json.php
2.71 KB
Del
OK
class.knowledgebase.php
5.8 KB
Del
OK
class.list.php
42 KB
Del
OK
class.lock.php
4.05 KB
Del
OK
class.log.php
1.55 KB
Del
OK
class.mail.php
35.76 KB
Del
OK
class.mailer.php
25.75 KB
Del
OK
class.mailfetch.php
9.72 KB
Del
OK
class.mailparse.php
30.99 KB
Del
OK
class.message.php
6.42 KB
Del
OK
class.migrater.php
5.2 KB
Del
OK
class.misc.php
7.5 KB
Del
OK
class.model.php
2.3 KB
Del
OK
class.nav.php
14.15 KB
Del
OK
class.note.php
2.39 KB
Del
OK
class.oauth2.php
4.04 KB
Del
OK
class.organization.php
22.45 KB
Del
OK
class.orm.php
120.9 KB
Del
OK
class.osticket.php
20.64 KB
Del
OK
class.ostsession.php
21.86 KB
Del
OK
class.page.php
10.59 KB
Del
OK
class.pagenate.php
5.53 KB
Del
OK
class.passwd.php
1.21 KB
Del
OK
class.pdf.php
3.83 KB
Del
OK
class.plugin.php
36.13 KB
Del
OK
class.priority.php
1.81 KB
Del
OK
class.queue.php
103.51 KB
Del
OK
class.report.php
11.76 KB
Del
OK
class.role.php
11.27 KB
Del
OK
class.schedule.php
46.28 KB
Del
OK
class.search.php
61.66 KB
Del
OK
class.sequence.php
7.27 KB
Del
OK
class.session.php
19.25 KB
Del
OK
class.setup.php
3.55 KB
Del
OK
class.signal.php
4.16 KB
Del
OK
class.sla.php
9.11 KB
Del
OK
class.staff.php
60.21 KB
Del
OK
class.task.php
56.21 KB
Del
OK
class.team.php
12.31 KB
Del
OK
class.template.php
23.45 KB
Del
OK
class.thread.php
108.96 KB
Del
OK
class.thread_actions.php
17.08 KB
Del
OK
class.ticket.php
167.39 KB
Del
OK
class.timezone.php
21.94 KB
Del
OK
class.topic.php
20.06 KB
Del
OK
class.translation.php
34.79 KB
Del
OK
class.upgrader.php
13.76 KB
Del
OK
class.user.php
43.4 KB
Del
OK
class.usersession.php
7.55 KB
Del
OK
class.util.php
10.07 KB
Del
OK
class.validator.php
12.94 KB
Del
OK
class.variable.php
11.93 KB
Del
OK
class.xml.php
3.23 KB
Del
OK
class.yaml.php
1.15 KB
Del
OK
cli
-
Del
OK
client
-
Del
OK
config
-
Del
OK
fpdf
-
Del
OK
htmLawed.php
53.53 KB
Del
OK
html2text.php
33.71 KB
Del
OK
i18n
-
Del
OK
index.php
37 B
Del
OK
laminas-mail
-
Del
OK
mpdf
-
Del
OK
mysqli.php
9.55 KB
Del
OK
ost-config.php
5.63 KB
Del
OK
ost-sampleconfig.php
6.24 KB
Del
OK
pear
-
Del
OK
plugins
-
Del
OK
staff
-
Del
OK
tnef_decoder.php
19.82 KB
Del
OK
upgrader
-
Del
OK
Edit: class.usersession.php
<?php /********************************************************************* class.usersession.php User (client and staff) sessions manager User-Space session management, not to confused with Session Storage Backends. Peter Rotich <peter@osticket.com> Copyright (c) 2022 osTicket http://www.osticket.com Released under the GNU General Public License WITHOUT ANY WARRANTY. See LICENSE.TXT for details. vim: expandtab sw=4 ts=4 sts=4: **********************************************************************/ include_once(INCLUDE_DIR.'class.client.php'); include_once(INCLUDE_DIR.'class.staff.php'); class UserSession { var $session_id = ''; var $userID = 0; var $browser = ''; var $ip = ''; var $validated = false; function __construct($userid) { $this->browser = (!empty($_SERVER['HTTP_USER_AGENT'])) ? $_SERVER['HTTP_USER_AGENT'] : $_ENV['HTTP_USER_AGENT']; $this->ip = (!empty($_SERVER['REMOTE_ADDR'])) ? $_SERVER['REMOTE_ADDR'] : getenv('REMOTE_ADDR'); $this->session_id = session_id(); $this->userID = $userid; } function isStaff() { return false; } function isClient() { return false; } function getSessionId() { return $this->session_id; } function getIP() { return $this->ip; } function getBrowser() { return $this->browser; } function sessionToken(){ // Please note that user-space token is not meant to be secure at all // we're simply encoding stuff we want to track as we refresh the // session. $time = time(); $hash = md5($time.SESSION_SECRET.$this->userID); $token = "$hash:$time:".MD5($this->getIP()); return $token; } function getLastUpdate($htoken) { if (!$htoken) return 0; @list($hash, $expire, $ip) = explode(":", $htoken); return $expire; } function isvalidSession($htoken, $maxidletime=0, $checkip=false){ global $cfg; // Compare session ids if (strcmp($this->getSessionId(), session_id())) return false; $token = rawurldecode($htoken); // Check if we got what we expected.... if ($token && !strstr($token,":")) return false; // Get the goodies list($hash, $expire, $ip) = explode(':', $token); // Make sure the session hash is valid if ((md5($expire . SESSION_SECRET . $this->userID) != $hash)) return false; // is it expired?? if ($maxidletime && ((time()-$expire) > $maxidletime)) return false; // Make sure IP is still same - if requested if ($checkip && strcmp($ip, MD5($this->getIP()))) return false; $this->validated = true; return true; } function isValid() { return ($this->validated); } } trait UserSessionTrait { // User Session Object var $session; // Session Token var $token; // Maximum idle time before session is considered invalid var $maxidletime = 0; // Indicates if session is bound to the IP address var $checkip = false; // User class var $class = ''; public function getMaxIdleTime() { return $this->maxidletime ; } function refreshSession($refreshRate=60) { // Check Time To Die (TTD) if any - OLD people.. I mean sessions, // must die! Don't fight it bro! if (isset($_SESSION['TTD']) && $_SESSION['TTD'] < time()) { error_log(sprintf('Session %s with TTD %s was used', session_id(), $_SESSION['TTD'])); return (session_destroy() && false); } // If TIME_BOMB is set and less than the current time we need to regenerate // session id to help mitigate session fixation attacks. // Only regenerate on GET to avoid invalidating data in-flight on a // POST request if ($_SERVER['REQUEST_METHOD'] === 'GET' && isset($_SESSION['TIME_BOMB']) && ($_SESSION['TIME_BOMB'] < time()) && ($id=$this->regenerateSession())) { // unset timer and set next one based on maxlife for the user or // 24 hrs later // TODO: Make regenerate frequency configurable in 2032 /j // PS: Living and dying and the stories that are true Secrets to // a good life is knowing when you're through ~ time bomb $ttl = ($this->getMaxIdleTime() ?: 86400); $_SESSION['TIME_BOMB'] = time() + $ttl; // Set new id locally $this->session_id = $id; // Force cookie renewal NOW! $refreshRate = -1; } // Deadband session token updates to once / 30-seconds $updated = $this->session->getLastUpdate($this->token); if ($updated + $refreshRate < time()) { // Renew the session token $this->token = $this->getSessionToken(); // Update the expire time for the session cookie osTicketSession::renewCookie(time(), $this->getMaxIdleTime()); } } function regenerateSession(int $ttl = 120) { // Set TTD (Time To Die) on current session // If ttl is 0 then session is destroyed immediatetly $_SESSION['TTD'] = time() + $ttl; // now + ttl if (($id=osTicketSession::regenerate($ttl))) $this->session->session_id = $id; // unset TTD on the new session - new life my boy! unset($_SESSION['TTD']); return $id; } function getSession() { return $this->session; } function getSessionToken() { return $this->session->sessionToken(); } function setSessionToken($token=null) { // Assign memory to token variable $this->token = &$_SESSION[':token'][$this->class]; // Set token $token = $token ?: $this->token; $this->token = $token ?: $this->getSessionToken(); } function getIP() { return $this->session->getIP(); } function isValidSession() { return ($this->getId() && $this->session->isvalidSession($this->token, $this->getMaxIdleTime(), $this->checkip)); } abstract function isValid(); } class ClientSession extends EndUser { use UserSessionTrait; function __construct($user) { global $cfg; parent::__construct($user); $this->class ='client'; // XXX: Change the key to user-id $this->session = new UserSession($user->getUserId()); $this->setSessionToken(); $this->maxidletime = $cfg->getClientTimeout(); } function getSessionUser() { return $this->user; } function isValid() { return $this->isValidSession(); } } class StaffSession extends Staff { use UserSessionTrait; static function lookup($var) { global $cfg; if (($staff = parent::lookup($var))) { $staff->class = 'staff'; $staff->session = new UserSession($staff->getId()); $staff->setSessionToken(); $staff->maxidletime = $cfg->getStaffTimeout(); $staff->checkip = $cfg->enableStaffIPBinding(); } return $staff; } function clear2FA() { unset($_SESSION['_auth']['staff']['2fa']); $_SESSION['_auth']['staff']['2fa'] = null; return true; } // If 2fa is set then it means it's pending function is2FAPending() { return isset($_SESSION['_auth']['staff']['2fa']); } function isValid() { return (!$this->is2FAPending() && $this->isValidSession()); } } ?>
Save