* code for task #5384.

This commit is contained in:
wangyidong
2019-04-29 08:57:00 +08:00
parent 8c78ea1612
commit 726a412270
5 changed files with 46 additions and 9 deletions

View File

@@ -1645,7 +1645,6 @@ EOD;
public function checkEntry()
{
$this->loadModel('entry');
if($this->session->valid_entry)
{
if(!$this->session->entry_code) $this->response('SESSION_CODE_MISSING');
@@ -1661,7 +1660,7 @@ EOD;
if(!$entry->key) $this->response('EMPTY_KEY');
if(empty($entry->account)) $this->response('ACCOUNT_UNBOUND');
if(!$this->checkIP($entry->ip)) $this->response('IP_DENIED');
if(!$this->checkEntryToken($entry->key)) $this->response('INVALID_TOKEN');
if(!$this->checkEntryToken($entry)) $this->response('INVALID_TOKEN');
$this->loadModel('user');
$user = $this->dao->findByAccount($entry->account)->from(TABLE_USER)->fetch();
@@ -1676,23 +1675,43 @@ EOD;
$this->session->set('VALID_ENTRY', md5(md5($this->get->code) . $this->server->remote_addr));
$this->loadModel('entry')->saveLog($entry->id, $this->server->request_uri);
/* Add for task #5384. */
if($_SERVER['REQUEST_METHOD'] == 'POST' and empty($_POST))
{
$post = file_get_contents("php://input");
if(!empty($post)) $post = json_decode($post, true);
if(!empty($post)) $_POST = $post;
}
unset($_GET['code']);
unset($_GET['token']);
unset($_GET['time']);
}
/**
* Check token of an entry.
*
* @param string $key
* @param object $entry
* @access public
* @return void
* @return bool
*/
public function checkEntryToken($key)
public function checkEntryToken($entry)
{
parse_str($this->server->query_String, $queryString);
unset($queryString['token']);
/* Change for task #5384. */
if(isset($queryString['time']))
{
if($queryString['time'] <= $entry->calledTime) $this->response('CALLED_TIME');
$result = $this->get->token == md5($entry->code . $entry->key . $queryString['time']);
if($result) $this->loadModel('entry')->updateTime($entry->code, $queryString['time']);
return $result;
}
else
{
$queryString = http_build_query($queryString);
return $this->get->token == md5(md5($queryString) . $key);
return $this->get->token == md5(md5($queryString) . $entry->key);
}
}
/**

View File

@@ -17,3 +17,4 @@ $config->entry->errcode['SESSION_VERIFY_FAILED'] = 401;
$config->entry->errcode['IP_DENIED'] = 403;
$config->entry->errcode['ACCOUNT_UNBOUND'] = 403;
$config->entry->errcode['EMPTY_ENTRY'] = 404;
$config->entry->errcode['CALLED_TIME'] = 405;

View File

@@ -46,3 +46,4 @@ $lang->entry->errmsg['SESSION_VERIFY_FAILED'] = 'session验证失败';
$lang->entry->errmsg['IP_DENIED'] = '该IP被限制访问';
$lang->entry->errmsg['ACCOUNT_UNBOUND'] = '未绑定用户';
$lang->entry->errmsg['EMPTY_ENTRY'] = '应用不存在';
$lang->entry->errmsg['CALLED_TIME'] = '已经访问过';

View File

@@ -125,6 +125,20 @@ class entryModel extends model
return common::createChanges($oldEntry, $entry);
}
/**
* Update called time.
*
* @param string $code
* @param int $time
* @access public
* @return bool
*/
public function updateTime($code, $time)
{
$this->dao->update(TABLE_ENTRY)->set('calledTime')->eq($time)->where('code')->eq($code)->exec();
return !dao::isError();
}
/**
* Save log of an entry.
*

View File

@@ -1332,7 +1332,9 @@ class userModel extends model
$userView = $this->dao->select('*')->from(TABLE_USERVIEW)->where('account')->eq($account)->fetch();
if(empty($userView)) $userView = $this->computeUserView($account);
if(!empty($acls['products']) and !$this->session->user->admin)
if(isset($_SESSION['user']->admin)) $isadmin = $this->session->user->admin;
if(!isset($isadmin)) $isadmin = strpos($this->app->company->admins, ",{$account},") !== false;
if(!empty($acls['products']) and !$isadmin)
{
$grantProducts = '';
foreach($acls['products'] as $productID)
@@ -1341,7 +1343,7 @@ class userModel extends model
}
$userView->products = $grantProducts;
}
if(!empty($acls['projects']) and !$this->session->user->admin)
if(!empty($acls['projects']) and !$isadmin)
{
$grantProjects = '';
foreach($acls['projects'] as $projectID)