Files

85 lines
3.3 KiB
PHP

<?php
// app/session.php
// Every page and API engine starts its session through this file, so the cookie
// flags and the idle timeout below apply to the whole app, not only the login routes.
ob_start(); // ensure output buffering is on regardless of php.ini — prevents stray output from corrupting JSON API responses
// The buffer is still flushed, so notices would still land in front of the JSON
// body and break the client's parse ("Server error occurred."). The login API
// engines load this file instead of db_auth.php, so apply the same policy here.
ini_set('display_errors', '0');
ini_set('log_errors', '1');
// Signed-in sessions end after this many seconds without a request.
if (!defined('SESSION_IDLE_SECONDS')) {
define('SESSION_IDLE_SECONDS', 1800);
}
if (session_status() === PHP_SESSION_NONE) {
// Derive cookie path dynamically from the current script location.
// e.g. /wms/app/login/api/engine/login_otp.php → /wms/
// This relies on the app always living one level under the repo root:
// DOCUMENT_ROOT/
// wms/ ← repo root (cookie path)
// app/
// session.php ← this file is always inside app/
$parts = explode('/', trim($_SERVER['SCRIPT_NAME'], '/'));
$repo_name = '/' . $parts[0] . '/'; // e.g. /wms/
// HTTPS directly, or TLS terminated by a reverse proxy in front of Apache.
$is_https = (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on')
|| strtolower($_SERVER['HTTP_X_FORWARDED_PROTO'] ?? '') === 'https';
ini_set('session.use_strict_mode', 1);
ini_set('session.use_only_cookies', 1);
ini_set('session.gc_maxlifetime', 3600);
ini_set('session.cookie_path', $repo_name);
ini_set('session.cookie_httponly', 1);
ini_set('session.cookie_samesite', 'Lax');
session_set_cookie_params([
'lifetime' => 0,
'path' => $repo_name,
'domain' => '',
'secure' => $is_https,
'httponly' => true,
'samesite' => 'Lax',
]);
session_start();
// Idle timeout: a signed-in session untouched for SESSION_IDLE_SECONDS is
// cleared here, so pages redirect to the login form and API engines answer
// 401 (db_auth.php) exactly as for a visitor who never signed in.
if (!empty($_SESSION['login_company_id'])) {
$last = (int)($_SESSION['_last_activity'] ?? 0);
if ($last > 0 && (time() - $last) > SESSION_IDLE_SECONDS) {
$_SESSION = [];
session_regenerate_id(true);
$_SESSION['_idle_expired'] = true;
} else {
$_SESSION['_last_activity'] = time();
}
}
}
/**
* End the current session completely: server data, the session file and the
* browser cookie. Used by logout and by any flow that must force a new sign-in.
*/
if (!function_exists('session_end_completely')) {
function session_end_completely(): void {
if (session_status() !== PHP_SESSION_ACTIVE) return;
$_SESSION = [];
$p = session_get_cookie_params();
setcookie(session_name(), '', [
'expires' => time() - 42000,
'path' => $p['path'],
'domain' => $p['domain'],
'secure' => $p['secure'],
'httponly' => $p['httponly'],
'samesite' => $p['samesite'] ?? 'Lax',
]);
session_destroy();
}
}