MediaWiki REL1_32
ImmutableSessionProviderWithCookie.php
Go to the documentation of this file.
1<?php
24namespace MediaWiki\Session;
25
26use WebRequest;
27
41
43 protected $sessionCookieName = null;
44 protected $sessionCookieOptions = [];
45
52 public function __construct( $params = [] ) {
53 parent::__construct();
54
55 if ( isset( $params['sessionCookieName'] ) ) {
56 if ( !is_string( $params['sessionCookieName'] ) ) {
57 throw new \InvalidArgumentException( 'sessionCookieName must be a string' );
58 }
59 $this->sessionCookieName = $params['sessionCookieName'];
60 }
61 if ( isset( $params['sessionCookieOptions'] ) ) {
62 if ( !is_array( $params['sessionCookieOptions'] ) ) {
63 throw new \InvalidArgumentException( 'sessionCookieOptions must be an array' );
64 }
65 $this->sessionCookieOptions = $params['sessionCookieOptions'];
66 }
67 }
68
81 if ( $this->sessionCookieName === null ) {
82 throw new \BadMethodCallException(
83 __METHOD__ . ' may not be called when $this->sessionCookieName === null'
84 );
85 }
86
87 $prefix = $this->sessionCookieOptions['prefix'] ?? $this->config->get( 'CookiePrefix' );
88 $id = $request->getCookie( $this->sessionCookieName, $prefix );
89 return SessionManager::validateSessionId( $id ) ? $id : null;
90 }
91
92 public function persistsSessionId() {
93 return $this->sessionCookieName !== null;
94 }
95
96 public function canChangeUser() {
97 return false;
98 }
99
100 public function persistSession( SessionBackend $session, WebRequest $request ) {
101 if ( $this->sessionCookieName === null ) {
102 return;
103 }
104
105 $response = $request->response();
106 if ( $response->headersSent() ) {
107 // Can't do anything now
108 $this->logger->debug( __METHOD__ . ': Headers already sent' );
109 return;
110 }
111
113 if ( $session->shouldForceHTTPS() || $session->getUser()->requiresHTTPS() ) {
114 $response->setCookie( 'forceHTTPS', 'true', null,
115 [ 'prefix' => '', 'secure' => false ] + $options );
116 $options['secure'] = true;
117 }
118
119 $response->setCookie( $this->sessionCookieName, $session->getId(), null, $options );
120 }
121
123 if ( $this->sessionCookieName === null ) {
124 return;
125 }
126
127 $response = $request->response();
128 if ( $response->headersSent() ) {
129 // Can't do anything now
130 $this->logger->debug( __METHOD__ . ': Headers already sent' );
131 return;
132 }
133
134 $response->clearCookie( $this->sessionCookieName, $this->sessionCookieOptions );
135 }
136
137 public function getVaryCookies() {
138 if ( $this->sessionCookieName === null ) {
139 return [];
140 }
141
142 $prefix = $this->sessionCookieOptions['prefix'] ?? $this->config->get( 'CookiePrefix' );
143 return [ $prefix . $this->sessionCookieName ];
144 }
145
146 public function whyNoSession() {
147 return wfMessage( 'sessionprovider-nocookies' );
148 }
149}
An ImmutableSessionProviderWithCookie doesn't persist the user, but optionally can use a cookie to su...
whyNoSession()
Return a Message for why sessions might not be being persisted.
canChangeUser()
Indicate whether the user associated with the request can be changed.
persistsSessionId()
Indicate whether self::persistSession() can save arbitrary session IDs.
unpersistSession(WebRequest $request)
Remove any persisted session from a request/response.
persistSession(SessionBackend $session, WebRequest $request)
Persist a session into a request/response.
getVaryCookies()
Return the list of cookies that need varying on.
getSessionIdFromCookie(WebRequest $request)
Get the session ID from the cookie, if any.
This is the actual workhorse for Session.
shouldForceHTTPS()
Whether HTTPS should be forced.
getId()
Returns the session ID.
getUser()
Returns the authenticated user for this session.
static validateSessionId( $id)
Validate a session ID.
A SessionProvider provides SessionInfo and support for Session.
The WebRequest class encapsulates getting at data passed in the URL or via a POSTed form stripping il...
do that in ParserLimitReportFormat instead use this to modify the parameters of the image all existing parser cache entries will be invalid To avoid you ll need to handle that somehow(e.g. with the RejectParserCacheValue hook) because MediaWiki won 't do it for you. & $defaults also a ContextSource after deleting those rows but within the same transaction you ll probably need to make sure the header is varied on $request
Definition hooks.txt:2880
null means default in associative array with keys and values unescaped Should be merged with default with a value of false meaning to suppress the attribute in associative array with keys and values unescaped & $options
Definition hooks.txt:2050
either a unescaped string or a HtmlArmor object after in associative array form externallinks including delete and has completed for all link tables whether this was an auto creation use $formDescriptor instead default is conds Array Extra conditions for the No matching items in log is displayed if loglist is empty msgKey Array If you want a nice box with a set this to the key of the message First element is the message additional optional elements are parameters for the key that are processed with wfMessage() -> params() ->parseAsBlock() - offset Set to overwrite offset parameter in $wgRequest set to '' to unset offset - wrap String Wrap the message in html(usually something like "&lt;div ...>$1&lt;/div>"). - flags Integer display flags(NO_ACTION_LINK, NO_EXTRA_USER_LINKS) 'LogException':Called before an exception(or PHP error) is logged. This is meant for integration with external error aggregation services
this hook is for auditing only $response
Definition hooks.txt:813
$params