summaryrefslogtreecommitdiff
path: root/include/sessions.php
AgeCommit message (Expand)Author
2021-11-11Address PHPStan warnings in 'include/sessions.php'.wn_
2021-11-10add two helper account access levels:Andrew Dolgov
2021-06-25prolong PHP session cookie automatically to stop hard logouts after SESSION_C...Andrew Dolgov
2021-05-11use database-backed sessions in single user modeAndrew Dolgov
2021-03-05sessions: stop validating against hash of user agent because chromium is sendingAndrew Dolgov
2021-03-04bring back web dbupdate using new migrations systemAndrew Dolgov
2021-03-04sessions: don't check schema versionAndrew Dolgov
2021-03-01userhelper: use orm for a few more user-related thingsAndrew Dolgov
2021-03-01move startup checks to Config, set a bunch of @deprecated annotationsAndrew Dolgov
2021-02-25cache schema version betterAndrew Dolgov
2021-02-25stop caching schema version entirely, fix some session_start() related warningsAndrew Dolgov
2021-02-23rename TTRSS_SESSION_NAME to SESSION_NAMEAndrew Dolgov
2021-02-23cleanup some defined-stuffAndrew Dolgov
2021-02-22don't include config.php everywhereAndrew Dolgov
2021-02-22wip: initial for config objectAndrew Dolgov
2021-02-22fix several issues reported by phpstanAndrew Dolgov
2021-02-16move session-related functions to their own namespaceAndrew Dolgov
2021-02-15remove the rest of db.php; rename some leftover methods in feedsAndrew Dolgov
2021-02-12add HTTP_ACCEPT_LANGUAGE handling for php8Andrew Dolgov
2021-02-08remove PHPMD.UnusedFormalParameterAndrew Dolgov
2021-02-06more php8 fixes mostly related to loginAndrew Dolgov
2020-09-30set session.cookie_lifetime to 0 initially instead of a rather useless min()Andrew Dolgov
2020-09-17rename gettext.inc to gettext.inc.php (cosmetic)Andrew Dolgov
2019-12-18remove version.php and VERSION global constant, do version-related things in ...Andrew Dolgov
2019-04-11add hidden _SKIP_SESSION_UA_CHECKS tunableAndrew Dolgov
2018-10-16fix session write handler always assuming that database entry exists and fail...Andrew Dolgov
2018-10-16remove session REMOTE_ADDR checksAndrew Dolgov
2018-10-15do not use separate _ssl cookie for secure sessionsAndrew Dolgov
2018-10-15force regenerate session id on successful login, remove previous blank SID checkAndrew Dolgov
2018-10-15if empty session is autostarted because of a cookie, immediately destroy itAndrew Dolgov
2018-10-15validate_session: bring back IP session binding (enabled by default) and UA c...Andrew Dolgov
2017-12-01sessions: PDOAndrew Dolgov
2017-07-17sessions: use is_server_https() for secure cookie settingAndrew Dolgov
2017-07-17$_SERVER['HTTPS'] can be exists and 'off' for non-https connectiosNatan Frei
2017-07-13rework previous 32 bit session stuffAndrew Dolgov
2017-07-13sessions: clip max expiry value to a 32bit integerAndrew Dolgov
2017-04-26remove some redundant php closing tagsAndrew Dolgov
2017-04-26fix various issues reported by static analysisAndrew Dolgov
2015-12-07ttrss_gc: return trueAndrew Dolgov
2015-08-21remove SESSION_CHECK_ADDRESSAndrew Dolgov
2015-01-31session: don't try to validate session schema version on empty sessionsAndrew Dolgov
2015-01-30do not invalidate session when version_static and user agent changesAndrew Dolgov
2013-07-06better error reporting in session validationAndrew Dolgov
2013-04-24use static version for session checking, show latest changeset for git versio...Andrew Dolgov
2013-04-17remove $linkAndrew Dolgov
2013-04-17more work on singleton-based DBAndrew Dolgov
2013-04-16experimental SQL-based error loggerAndrew Dolgov
2013-04-04implement some tweaks to session handling; properly remove session cookie if ...Andrew Dolgov
2013-04-04session validation: check for tt-rss versionAndrew Dolgov
2013-04-03remove session check/destroy stuff, looks problematicAndrew Dolgov