From 00de82df281e2a76767432c3ba0a5ad44fd9feeb Mon Sep 17 00:00:00 2001
From: skodak
Date: Mon, 18 Apr 2005 20:13:36 +0000
Subject: [PATCH] Session test to detect user switching, error counter is
displayed in healthcenter - please test, test, test; TODO - move string from
setup.php to language file
---
admin/cron.php | 3 +++
admin/health.php | 32 ++++++++++++++++++++++++++++++++
lib/setup.php | 36 ++++++++++++++++++++++++++++++++++++
login/logout.php | 1 +
4 files changed, 72 insertions(+)
diff --git a/admin/cron.php b/admin/cron.php
index 0be85ce9a71..dc2c877c548 100644
--- a/admin/cron.php
+++ b/admin/cron.php
@@ -36,6 +36,9 @@
$USER = get_admin(); /// Temporarily, to provide environment for this script
}
+ //unset test cookie, user must login again anyway
+ setcookie('MoodleSessionTest'.$CFG->sessioncookie, '', time() - 3600, '/');
+
/// Start output log
$timenow = time();
diff --git a/admin/health.php b/admin/health.php
index 20872918bb8..1bbd9bb459b 100644
--- a/admin/health.php
+++ b/admin/health.php
@@ -477,6 +477,38 @@ class problem_000010 extends problem_base {
}
}
+class problem_000011 extends problem_base {
+ function title() {
+ return 'Session errors detected';
+ }
+ function exists() {
+ global $CFG;
+ return isset($CFG->session_error_counter);
+ }
+ function severity() {
+ return SEVERITY_ANNOYANCE;
+ }
+ function description() {
+ global $CFG;
+ if (isset($CFG->session_error_counter)) {
+ return 'Session problems were detected. Total count: '.$CFG->session_error_counter;
+ } else {
+ return 'No session errors detected.';
+ }
+ }
+ function solution() {
+ global $CFG;
+ if (isset($_GET['resetsesserrorcounter'])) {
+ if (get_field('config', 'name', 'name', 'session_error_counter')) {
+ delete_records('config', 'name', 'session_error_counter');
+ }
+ return 'Error counter was cleared.';
+ } else {
+ return 'Session errors can be caused by:
- unresolved problem in server software (aka random switching of users),
- blocked or modified cookies,
- deleting of active session files.
Reset counter.
';
+ }
+ }
+}
+
class problem_00000x extends problem_base {
function title() {
diff --git a/lib/setup.php b/lib/setup.php
index b26f00a5bf9..e76166b176c 100644
--- a/lib/setup.php
+++ b/lib/setup.php
@@ -280,6 +280,13 @@ global $THEME;
@session_start();
if (! isset($_SESSION['SESSION'])) {
$_SESSION['SESSION'] = new object;
+ $_SESSION['SESSION']->session_test = random_string(10);
+ if (empty($_COOKIE['MoodleSessionTest'.$CFG->sessioncookie])) {
+ setcookie('MoodleSessionTest'.$CFG->sessioncookie, $_SESSION['SESSION']->session_test, 0, '/');
+ $_COOKIE['MoodleSessionTest'.$CFG->sessioncookie] = $_SESSION['SESSION']->session_test;
+ } else {
+ $_COOKIE['MoodleSessionTest'.$CFG->sessioncookie] = 'error!!';
+ }
}
if (! isset($_SESSION['USER'])) {
$_SESSION['USER'] = new object;
@@ -329,6 +336,35 @@ global $THEME;
theme_setup(); // Sets up theme global variables
+/// now do a session test to prevent random user switching
+ function report_session_error() {
+ global $CFG;
+ if (empty($CFG->lang)) {
+ $CFG->lang = "en";
+ }
+ moodle_setlocale();
+ //clear session cookies
+ setcookie('MoodleSession'.$CFG->sessioncookie, '', time() - 3600, '/');
+ setcookie('MoodleSessionTest'.$CFG->sessioncookie, '', time() - 3600, '/');
+ //increment database error counters
+ if (!isset($CFG->session_error_counter)) {
+ set_config('session_error_counter', 1);
+ } else {
+ set_config('session_error_counter', 1 + $CFG->session_error_counter);
+ }
+ //TODO: move string to lang/en/error.php
+ $strsessionerroruser = 'Serious session error occured, please login again.';
+ redirect($CFG->wwwroot, $strsessionerroruser, 5);
+ }
+
+ if ($SESSION != NULL) {
+ if (empty($_COOKIE['MoodleSessionTest'.$CFG->sessioncookie])) {
+ report_session_error();
+ } else if ($_COOKIE['MoodleSessionTest'.$CFG->sessioncookie] != $SESSION->session_test) {
+ report_session_error();
+ }
+ }
+
/// Set language/locale of printed times. If user has chosen a language that
diff --git a/login/logout.php b/login/logout.php
index a7de02faedd..0fac4d3dc22 100644
--- a/login/logout.php
+++ b/login/logout.php
@@ -18,6 +18,7 @@
session_unregister("SESSION");
}
+ setcookie('MoodleSessionTest'.$CFG->sessioncookie, '', time() - 3600, '/');
unset($_SESSION['USER']);
unset($_SESSION['SESSION']);