session.php 7.22 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
<?php
/**
 * This program is part of Mahara
 *
 *  This program is free software; you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation; either version 2 of the License, or
 *  (at your option) any later version.
 *
 *  This program is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *  GNU General Public License for more details.
 *
 *  You should have received a copy of the GNU General Public License
 *  along with this program; if not, write to the Free Software
 *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301 USA
 *
 * @package    mahara
Nigel McNie's avatar
Nigel McNie committed
20
 * @subpackage core
21 22 23 24 25 26 27 28
 * @author     Nigel McNie <nigel@catalyst.net.nz>
 * @license    http://www.gnu.org/copyleft/gpl.html GNU GPL
 * @copyright  (C) 2006,2007 Catalyst IT Ltd http://catalyst.net.nz
 *
 */

defined('INTERNAL') || die();

29 30 31
//
// Set session settings
//
32
session_name(get_config('cookieprefix') . 'mahara');
33 34 35 36 37 38 39
ini_set('session.save_path', '3;' . get_config('dataroot') . 'sessions');
ini_set('session.gc_divisor', 1000);
// Session timeout is stored in minutes in the database
ini_set('session.gc_maxlifetime', get_config('session_timeout') * 60);
ini_set('session.use_only_cookies', true);
ini_set('session.cookie_path', get_mahara_install_subdirectory());
ini_set('session.cookie_httponly', 1);
40
ini_set('session.hash_bits_per_session', 4);
41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61


// TEMPORARY: this will be REMOVED after the session path changing
// has been around for a bit.
// Attempt to create session directories
$sessionpath = get_config('dataroot') . 'sessions';
if (!is_dir("$sessionpath/0")) {
    // Create three levels of directories, named 0-9, a-f
    $characters = array('0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'a', 'b', 'c', 'd', 'e', 'f');
    foreach ($characters as $c1) {
        check_dir_exists("$sessionpath/$c1");
        foreach ($characters as $c2) {
            check_dir_exists("$sessionpath/$c1/$c2");
            foreach ($characters as $c3) {
                check_dir_exists("$sessionpath/$c1/$c2/$c3");
            }
        }
    }
}


62
/**
63
 * The session class handles session data and messages.
64
 *
65 66 67 68
 * This class stores information across page loads, using only a cookie to
 * remember the info. User information is stored in the session so it does
 * not have to be requested each time the page is loaded, however any other
 * information can also be stored using this class.
69 70 71 72
 *
 * This class also is smart about giving out sessions - if a visitor
 * has not logged in (e.g. they are a guest, searchbot or a simple
 * 'curl' request), a session will not be created for them.
73
 *
74 75
 * Messages are stored in the session and are displayed the next time
 * a page is displayed to a user, even over multiple requests.
76 77 78
 */
class Session {

79
    /**
80
     * Resumes an existing session, only if there is one
81 82 83
     */
    public function __construct() {
        // Resume an existing session if required
84
        if (isset($_COOKIE[session_name()])) {
85 86 87 88 89 90 91 92 93 94 95 96 97 98
            session_start();
        }
    }

    /**
     * Gets the session property keyed by $key.
     *
     * @param string $key The key to get the value of
     * @return mixed
     */
    public function get($key) {
        if (isset($_SESSION[$key])) {
            return $_SESSION[$key];
        }
Penny Leach's avatar
Penny Leach committed
99 100 101
        return null;
    }

102 103 104 105 106 107 108
    /**
     * Sets the session property keyed by $key.
     *
     * @param string $key   The key to set.
     * @param string $value The value to set for the key
     */
    public function set($key, $value) {
109
        $this->ensure_session();
110
        $_SESSION[$key] = $value;
111 112
    }

Martyn Smith's avatar
Martyn Smith committed
113 114 115 116 117
    /**
     * Clears the session property keyed by $key (by setting it to null).
     *
     * @param string $key   The key to set.
     */
Martyn Smith's avatar
Martyn Smith committed
118
    public function clear($key) {
Martyn Smith's avatar
Martyn Smith committed
119 120 121 122
        $this->ensure_session();
        $_SESSION[$key] = null;
    }

123 124 125 126 127 128 129
    /**
     * Adds a message that indicates something was successful
     *
     * @param string $message The message to add
     * @param boolean $escape Whether to HTML escape the message
     */
    public function add_ok_msg($message, $escape=true) {
130
        $this->ensure_session();
131
        if ($escape) {
132
            $message = self::escape_message($message);
133 134 135 136 137 138 139 140 141 142 143
        }
        $_SESSION['messages'][] = array('type' => 'ok', 'msg' => $message);
    }

    /**
     * Adds a message that indicates an informational message
     *
     * @param string $message The message to add
     * @param boolean $escape Whether to HTML escape the message
     */
    public function add_info_msg($message, $escape=true) {
144
        $this->ensure_session();
145
        if ($escape) {
146
            $message = self::escape_message($message);
147 148 149 150 151 152 153 154 155 156
        }
        $_SESSION['messages'][] = array('type' => 'info', 'msg' => $message);
    }

    /**
     * Adds a message that indicates a failure to do something
     *
     * @param string $message The message to add
     * @param boolean $escape Whether to HTML escape the message
     */
157
    public function add_error_msg($message, $escape=true) {
158
        $this->ensure_session();
159
        if ($escape) {
160
            $message = self::escape_message($message);
161
        }
162
        $_SESSION['messages'][] = array('type' => 'error', 'msg' => $message);
163 164 165 166 167 168 169 170 171 172 173 174 175
    }

    /**
     * Builds HTML that represents all of the messages and returns it.
     *
     * This is designed to let smarty templates hook in any session messages.
     *
     * Calling this function will destroy the session messages that were
     * rendered, so they do not inadvertently get displayed again.
     *
     * @return string The HTML representing all of the session messages.
     */
    public function render_messages() {
176
        $result = '<div id="messages">';
177 178
        if (isset($_SESSION['messages'])) {
            foreach ($_SESSION['messages'] as $data) {
179
                $result .= '<div class="' . $data['type'] . '">';
180
                $result .= '<div class="fr"><a href="" onclick="removeElement(this.parentNode.parentNode);return false;">';
181
                $result .= '<img src="' . theme_get_url('images/icon_close.gif') . '" alt="[X]"></a></div>';
182
                $result .= $data['msg'] . '</div>';
183
            }
184
            $_SESSION['messages'] = array();
185
        }
186
        $result .= '</div>';
187 188 189
        return $result;
    }

190
    /**
191
     * Create a session, by initialising the $_SESSION array.
192
     */
193 194 195
    private function ensure_session() {
        if (empty($_SESSION)) {
            if (!session_id()) {
196
                @session_start();
197 198 199 200
            }
            $_SESSION = array(
                'messages' => array()
            );
201
        }
202 203 204 205 206 207 208 209 210 211 212 213
    }

    /**
     * Escape a message for HTML output
     * 
     * @param string $message The message to escape
     * @return string         The message, escaped for output as HTML
     */
    private static function escape_message($message) {
        $message = hsc($message);
        $message = str_replace('  ', '&nbsp; ', $message);
        return $message;
214
    }
215

216 217 218 219 220 221 222 223 224 225 226 227 228
}

/**
 * A smarty callback to insert page messages
 *
 * @return string The HTML represening all of the session messages.
 */
function insert_messages() {
    global $SESSION;
    return $SESSION->render_messages();
}

?>