summaryrefslogtreecommitdiff
path: root/include/sessions.php
blob: bf2cec0a0cf89d9353d017a68de0bd352216f2d9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
<?php
	require_once "common.php";

	$session_name = Config::get(Config::SESSION_NAME);
	$session_expire = Config::get(Config::SESSION_LIFETIME);

	if (Config::is_server_https())
		ini_set("session.cookie_secure", "true");

	ini_set("session.name", "epube_sid");
	ini_set("session.use_only_cookies", "true");
	ini_set("session.gc_maxlifetime", $session_expire);
	ini_set("session.cookie_lifetime", "0");

	session_set_cookie_params($session_expire);

	session_save_path(dirname(__DIR__) . "/sessions");

	// prolong PHP session cookie
	if (isset($_COOKIE[$session_name]))
	setcookie($session_name,
		$_COOKIE[$session_name],
		time() + $session_expire,
		ini_get("session.cookie_path"),
		ini_get("session.cookie_domain"),
		ini_get("session.cookie_secure"),
		ini_get("session.cookie_httponly"));

	function validate_session() : bool {
		if (!empty($_SESSION["owner"])) {

			$user = ORM::for_table('epube_users')
				->where('user', $_SESSION['owner'])
				->find_one();

			if ($user && sha1($user->pass) == $_SESSION['pass_hash']) {
				return true;
			}
		}

		return false;
	}

	function logout_user() : void {
		if (session_status() == PHP_SESSION_ACTIVE) {
			session_destroy();

			if (isset($_COOKIE[session_name()])) {
				setcookie(session_name(), '', time()-42000, '/');
			}

			if (isset($_COOKIE["epube_csrf_token"])) {
				setcookie("epube_csrf_token", '', time()-42000, '/');
			}

			session_commit();
		}
	}

	register_shutdown_function('session_write_close');

	if (isset($_COOKIE[session_name()])) {
		if (session_status() != PHP_SESSION_ACTIVE)
			session_start();
	}