[289] | 1 | <?php |
---|
| 2 | |
---|
| 3 | /* sfDatabaseSessionStorage |
---|
| 4 | * |
---|
| 5 | * @Author: Nguyen Phu Quang |
---|
| 6 | * |
---|
| 7 | */ |
---|
| 8 | class sfDatabaseSessionStorage extends sfSessionStorage { |
---|
| 9 | |
---|
| 10 | public static $new_session = true; |
---|
| 11 | public static $is_bot = false; |
---|
| 12 | |
---|
| 13 | private static $mysql_dsn; |
---|
| 14 | private static $mysql_user; |
---|
| 15 | private static $mysql_password; |
---|
| 16 | public static $pdo; |
---|
| 17 | |
---|
| 18 | /** |
---|
| 19 | * Initialize this Storage. |
---|
| 20 | * |
---|
| 21 | * @param Context A Context instance. |
---|
| 22 | * @param array An associative array of initialization parameters. |
---|
| 23 | */ |
---|
| 24 | public function initialize($context, $parameters = null) { |
---|
| 25 | |
---|
| 26 | $parameters['auto_start'] = false; |
---|
| 27 | parent::initialize($context, $parameters); |
---|
| 28 | if (preg_match('@bot\.html|ia_archiver|msnbot|Slurp;@', @$_SERVER['HTTP_USER_AGENT'])) |
---|
| 29 | self::$is_bot = true; |
---|
| 30 | |
---|
| 31 | self::$mysql_dsn = $parameters['session_dsn']; |
---|
| 32 | self::$mysql_user = $parameters['session_user']; |
---|
| 33 | self::$mysql_password = $parameters['session_password']; |
---|
| 34 | |
---|
| 35 | // use this object as the session handler |
---|
| 36 | session_set_save_handler(array($this, 'sessionOpen'), |
---|
| 37 | array($this, 'sessionClose'), |
---|
| 38 | array($this, 'sessionRead'), |
---|
| 39 | array($this, 'sessionWrite'), |
---|
| 40 | array($this, 'sessionDestroy'), |
---|
| 41 | array($this, 'sessionGC')); |
---|
| 42 | session_start(); |
---|
| 43 | } |
---|
| 44 | |
---|
| 45 | public function sessionOpen($path, $name) { |
---|
| 46 | self::$pdo = new PDO(self::$mysql_dsn, self::$mysql_user, self::$mysql_password); |
---|
| 47 | } |
---|
| 48 | |
---|
| 49 | public function sessionClose() { |
---|
| 50 | return true; |
---|
| 51 | } |
---|
| 52 | |
---|
| 53 | public function sessionDestroy($id) { |
---|
| 54 | self::$pdo->exec('delete from sessions where ss_id="'.$id.'"'); |
---|
| 55 | } |
---|
| 56 | |
---|
| 57 | public function sessionGC($lifetime) { |
---|
| 58 | $last = time() - $lifetime; |
---|
| 59 | self::$pdo->exec("delete from sessions where ss_time<$last"); |
---|
| 60 | self::$pdo->exec("delete from online_guest where og_time<$last"); |
---|
| 61 | self::$pdo->exec("delete from online_user where ou_time<$last"); |
---|
| 62 | return true; |
---|
| 63 | } |
---|
| 64 | |
---|
| 65 | /** |
---|
| 66 | * Read a session. |
---|
| 67 | * |
---|
| 68 | * @param string A session ID. |
---|
| 69 | * |
---|
| 70 | * @return data from database if the session was read else returns string empty |
---|
| 71 | * |
---|
| 72 | */ |
---|
| 73 | public function sessionRead($id) { |
---|
| 74 | if (self::$is_bot) return ''; |
---|
| 75 | $stmt = self::$pdo->query("select ss_data from sessions where ss_id='$id' limit 1"); |
---|
| 76 | if ($stmt && $row = $stmt->fetch(PDO::FETCH_NUM)) { |
---|
| 77 | self::$new_session = false; |
---|
| 78 | if ($row[0]=='vol_lock') { |
---|
| 79 | sfContext::getInstance()->getResponse()->setCookie('vol_lock', 1, time()+86400*5); |
---|
| 80 | $row[0] = ''; |
---|
| 81 | } |
---|
| 82 | return $row[0]; |
---|
| 83 | } |
---|
| 84 | return ''; |
---|
| 85 | } |
---|
| 86 | |
---|
| 87 | /** |
---|
| 88 | * Write session data. |
---|
| 89 | * |
---|
| 90 | * @param string A session ID. |
---|
| 91 | * @param string A serialized chunk of session data. |
---|
| 92 | * |
---|
| 93 | * @return bool true, if the session was written, otherwise an exception is thrown. |
---|
| 94 | */ |
---|
| 95 | public function sessionWrite($id, $data) { |
---|
| 96 | if (self::$is_bot) return true; |
---|
| 97 | $time = time(); |
---|
| 98 | $user = sfContext::getInstance()->getUser(); |
---|
| 99 | $userId = $user->getUserId(); |
---|
| 100 | $userName = $user->getUserName(); |
---|
| 101 | $fullname = $user->getUserFullname(); |
---|
| 102 | |
---|
| 103 | if (self::$new_session==false) { |
---|
| 104 | self::$pdo->exec("update sessions set ss_userid=$userId, ss_username='$userName', ss_user_fullname='$fullname', ". |
---|
| 105 | "ss_time=$time, ss_data='$data' where ss_id='$id'"); |
---|
| 106 | } else { |
---|
| 107 | self::$pdo->exec("insert into sessions values('$id', $userId, '$userName', '$userFullname', $time, '$data')"); |
---|
| 108 | self::$new_session = false; |
---|
| 109 | } |
---|
| 110 | return true; |
---|
| 111 | } |
---|
| 112 | |
---|
| 113 | public static function kickUserByName($user_name, $lock=false) { |
---|
| 114 | $user_name = self::$pdo->quote($user_name); |
---|
| 115 | $stmt = self::$pdo->query('select ss_userid from sessions where ss_username='.$user_name.' limit 1'); |
---|
| 116 | if ($stmt && $row = $stmt->fetch(PDO::FETCH_NUM)) { |
---|
| 117 | if ($lock==false) { |
---|
| 118 | self::$pdo->exec('delete from sessions where ss_username='.$user_name); |
---|
| 119 | } else { |
---|
| 120 | self::$pdo->exec('update sessions set ss_data="vol_lock" where ss_username='.$user_name); |
---|
| 121 | } |
---|
| 122 | self::$pdo->exec('delete from online_user where ou_userid='.$row[0]); |
---|
| 123 | } |
---|
| 124 | } |
---|
| 125 | |
---|
| 126 | /** |
---|
| 127 | * Kick out an user |
---|
| 128 | * |
---|
| 129 | * @param string $session_id |
---|
| 130 | */ |
---|
| 131 | public static function kickUser($session_id) { |
---|
| 132 | self::connect_session_db(); |
---|
| 133 | $stmt = self::$pdo->query('select ss_userid from sessions where ss_id="'.$session_id.'"'); |
---|
| 134 | if ($stmt && $row = $stmt->fetch(PDO::FETCH_NUM) && $row[0] != 0) { |
---|
| 135 | self::$pdo->exec('delete from sessions where ss_id="'.$session_id.'"'); |
---|
| 136 | self::$pdo->exec('delete from online_user where ou_userid='.$row[0]); |
---|
| 137 | } |
---|
| 138 | } |
---|
| 139 | } |
---|