diff --git a/module/common/model.php b/module/common/model.php index 49a6cae306..fdc8d26032 100644 --- a/module/common/model.php +++ b/module/common/model.php @@ -1645,7 +1645,6 @@ EOD; public function checkEntry() { $this->loadModel('entry'); - if($this->session->valid_entry) { if(!$this->session->entry_code) $this->response('SESSION_CODE_MISSING'); @@ -1661,7 +1660,7 @@ EOD; if(!$entry->key) $this->response('EMPTY_KEY'); if(empty($entry->account)) $this->response('ACCOUNT_UNBOUND'); if(!$this->checkIP($entry->ip)) $this->response('IP_DENIED'); - if(!$this->checkEntryToken($entry->key)) $this->response('INVALID_TOKEN'); + if(!$this->checkEntryToken($entry)) $this->response('INVALID_TOKEN'); $this->loadModel('user'); $user = $this->dao->findByAccount($entry->account)->from(TABLE_USER)->fetch(); @@ -1676,23 +1675,43 @@ EOD; $this->session->set('VALID_ENTRY', md5(md5($this->get->code) . $this->server->remote_addr)); $this->loadModel('entry')->saveLog($entry->id, $this->server->request_uri); + /* Add for task #5384. */ + if($_SERVER['REQUEST_METHOD'] == 'POST' and empty($_POST)) + { + $post = file_get_contents("php://input"); + if(!empty($post)) $post = json_decode($post, true); + if(!empty($post)) $_POST = $post; + } + unset($_GET['code']); unset($_GET['token']); + unset($_GET['time']); } /** * Check token of an entry. * - * @param string $key + * @param object $entry * @access public - * @return void + * @return bool */ - public function checkEntryToken($key) + public function checkEntryToken($entry) { parse_str($this->server->query_String, $queryString); unset($queryString['token']); - $queryString = http_build_query($queryString); - return $this->get->token == md5(md5($queryString) . $key); + /* Change for task #5384. */ + if(isset($queryString['time'])) + { + if($queryString['time'] <= $entry->calledTime) $this->response('CALLED_TIME'); + $result = $this->get->token == md5($entry->code . $entry->key . $queryString['time']); + if($result) $this->loadModel('entry')->updateTime($entry->code, $queryString['time']); + return $result; + } + else + { + $queryString = http_build_query($queryString); + return $this->get->token == md5(md5($queryString) . $entry->key); + } } /** diff --git a/module/entry/config.php b/module/entry/config.php index 850e01d109..98913d48b4 100644 --- a/module/entry/config.php +++ b/module/entry/config.php @@ -17,3 +17,4 @@ $config->entry->errcode['SESSION_VERIFY_FAILED'] = 401; $config->entry->errcode['IP_DENIED'] = 403; $config->entry->errcode['ACCOUNT_UNBOUND'] = 403; $config->entry->errcode['EMPTY_ENTRY'] = 404; +$config->entry->errcode['CALLED_TIME'] = 405; diff --git a/module/entry/lang/zh-cn.php b/module/entry/lang/zh-cn.php index d11bf4bd68..f964fafdb7 100644 --- a/module/entry/lang/zh-cn.php +++ b/module/entry/lang/zh-cn.php @@ -46,3 +46,4 @@ $lang->entry->errmsg['SESSION_VERIFY_FAILED'] = 'session验证失败'; $lang->entry->errmsg['IP_DENIED'] = '该IP被限制访问'; $lang->entry->errmsg['ACCOUNT_UNBOUND'] = '未绑定用户'; $lang->entry->errmsg['EMPTY_ENTRY'] = '应用不存在'; +$lang->entry->errmsg['CALLED_TIME'] = '已经访问过'; diff --git a/module/entry/model.php b/module/entry/model.php index 240b65981c..7aaff645a8 100644 --- a/module/entry/model.php +++ b/module/entry/model.php @@ -125,6 +125,20 @@ class entryModel extends model return common::createChanges($oldEntry, $entry); } + /** + * Update called time. + * + * @param string $code + * @param int $time + * @access public + * @return bool + */ + public function updateTime($code, $time) + { + $this->dao->update(TABLE_ENTRY)->set('calledTime')->eq($time)->where('code')->eq($code)->exec(); + return !dao::isError(); + } + /** * Save log of an entry. * diff --git a/module/user/model.php b/module/user/model.php index 9c30eac2a1..51dab65d77 100644 --- a/module/user/model.php +++ b/module/user/model.php @@ -1332,7 +1332,9 @@ class userModel extends model $userView = $this->dao->select('*')->from(TABLE_USERVIEW)->where('account')->eq($account)->fetch(); if(empty($userView)) $userView = $this->computeUserView($account); - if(!empty($acls['products']) and !$this->session->user->admin) + if(isset($_SESSION['user']->admin)) $isadmin = $this->session->user->admin; + if(!isset($isadmin)) $isadmin = strpos($this->app->company->admins, ",{$account},") !== false; + if(!empty($acls['products']) and !$isadmin) { $grantProducts = ''; foreach($acls['products'] as $productID) @@ -1341,7 +1343,7 @@ class userModel extends model } $userView->products = $grantProducts; } - if(!empty($acls['projects']) and !$this->session->user->admin) + if(!empty($acls['projects']) and !$isadmin) { $grantProjects = ''; foreach($acls['projects'] as $projectID)