[*] Installer : added cookie mode instead of session for the installer

This commit is contained in:
Damien Metzger
2013-06-13 15:28:16 +02:00
parent fafb7fdef7
commit 534c10562f
8 changed files with 77 additions and 42 deletions
+1 -1
View File
@@ -42,7 +42,7 @@ class BlowfishCore extends Crypt_Blowfish
$piece = substr($paddedtext, $x, 8);
$cipher_piece = parent::encrypt($piece);
$encoded = base64_encode($cipher_piece);
$ciphertext = $ciphertext.$encoded;
$ciphertext = $ciphertext.$encoded;
}
return $ciphertext.sprintf('%06d', $length);
}
+17 -17
View File
@@ -44,15 +44,13 @@ class CookieCore
/** @var array cipher tool instance */
protected $_cipherTool;
/** @var array cipher tool initialization key */
protected $_key;
/** @var array cipher tool initilization vector */
protected $_iv;
protected $_modified = false;
protected $_allow_writing;
protected $_salt;
protected $_standalone;
/**
* Get data if the cookie exists and else initialize an new one
@@ -60,24 +58,26 @@ class CookieCore
* @param $name Cookie name before encrypting
* @param $path
*/
public function __construct($name, $path = '', $expire = null, $shared_urls = null)
public function __construct($name, $path = '', $expire = null, $shared_urls = null, $standalone = false)
{
$this->_content = array();
$this->_standalone = $standalone;
$this->_expire = is_null($expire) ? time() + 1728000 : (int)$expire;
$this->_name = md5(_PS_VERSION_.$name);
$this->_path = trim(Context::getContext()->shop->physical_uri.$path, '/\\').'/';
$this->_name = md5(($this->_standalone ? '' : _PS_VERSION_).$name);
$this->_path = trim(($this->_standalone ? '' : Context::getContext()->shop->physical_uri).$path, '/\\').'/';
if ($this->_path{0} != '/') $this->_path = '/'.$this->_path;
$this->_path = rawurlencode($this->_path);
$this->_path = str_replace('%2F', '/', $this->_path);
$this->_path = str_replace('%7E', '~', $this->_path);
$this->_key = _COOKIE_KEY_;
$this->_iv = _COOKIE_IV_;
$this->_domain = $this->getDomain($shared_urls);
$this->_allow_writing = true;
if (Configuration::get('PS_CIPHER_ALGORITHM'))
$this->_cipherTool = new Rijndael(_RIJNDAEL_KEY_, _RIJNDAEL_IV_);
$this->_salt = $this->_standalone ? str_pad('', 8, md5('ps'.__FILE__)) : _COOKIE_IV_;
if ($this->_standalone)
$this->_cipherTool = new Blowfish(str_pad('', 56, md5('ps'.__FILE__)), str_pad('', 56, md5('iv'.__FILE__)));
elseif (!Configuration::get('PS_CIPHER_ALGORITHM'))
$this->_cipherTool = new Blowfish(_COOKIE_KEY_, _COOKIE_IV_);
else
$this->_cipherTool = new Blowfish($this->_key, $this->_iv);
$this->_cipherTool = new Rijndael(_RIJNDAEL_KEY_, _RIJNDAEL_IV_);
$this->update();
}
@@ -270,7 +270,7 @@ class CookieCore
//printf("\$content = %s<br />", $content);
/* Get cookie checksum */
$checksum = crc32($this->_iv.substr($content, 0, strrpos($content, '¤') + 2));
$checksum = crc32($this->_salt.substr($content, 0, strrpos($content, '¤') + 2));
//printf("\$checksum = %s<br />", $checksum);
/* Unserialize cookie content */
@@ -297,7 +297,7 @@ class CookieCore
$this->_content['date_add'] = date('Y-m-d H:i:s');
//checks if the language exists, if not choose the default language
if (!Language::getLanguage((int)$this->id_lang))
if (!$this->_standalone && !Language::getLanguage((int)$this->id_lang))
$this->id_lang = Configuration::get('PS_LANG_DEFAULT');
}
@@ -344,7 +344,7 @@ class CookieCore
$cookie .= $key.'|'.$value.'¤';
/* Add checksum to cookie */
$cookie .= 'checksum|'.crc32($this->_iv.$cookie);
$cookie .= 'checksum|'.crc32($this->_salt.$cookie);
$this->_modified = false;
/* Cookies are encrypted for evident security reasons */
return $this->_setcookie($cookie);
+1 -1
View File
@@ -580,7 +580,7 @@ class LanguageCore extends ObjectModel
public static function getLanguage($id_lang)
{
if (!array_key_exists((int)($id_lang), self::$_LANGUAGES))
if (!array_key_exists((int)$id_lang, self::$_LANGUAGES))
return false;
return self::$_LANGUAGES[(int)($id_lang)];
}
+3 -3
View File
@@ -53,9 +53,6 @@ require_once(dirname(__FILE__).'/settings.inc.php');
require_once(dirname(__FILE__).'/autoload.php');
if (Tools::isPHPCLI())
Tools::argvToGET($argc, $argv);
if (_PS_DEBUG_PROFILING_)
{
include_once(_PS_TOOL_DIR_.'profiling/Controller.php');
@@ -65,6 +62,9 @@ if (_PS_DEBUG_PROFILING_)
include_once(_PS_TOOL_DIR_.'profiling/Tools.php');
}
if (Tools::isPHPCLI())
Tools::argvToGET($argc, $argv);
/* Redefine REQUEST_URI if empty (on some webservers...) */
if (!isset($_SERVER['REQUEST_URI']) || empty($_SERVER['REQUEST_URI']))
{
+45 -10
View File
@@ -30,6 +30,8 @@
class InstallSession
{
protected static $_instance;
protected static $_cookie_mode = false;
protected static $_cookie = false;
public static function getInstance()
{
@@ -41,39 +43,72 @@ class InstallSession
public function __construct()
{
session_name('install_'.md5(__PS_BASE_URI__));
session_start();
if (!session_start() || (!isset($_SESSION['session_mode']) && (count($_POST) || count($_GET))))
{
InstallSession::$_cookie_mode = true;
InstallSession::$_cookie = new Cookie('ps_install', null, time() + 7200, null, true);
}
else
$_SESSION['session_mode'] = 'session';
}
public function clean()
{
foreach ($_SESSION as $k => $v)
unset($_SESSION[$k]);
if (InstallSession::$_cookie_mode)
InstallSession::$_cookie->logout();
else
foreach ($_SESSION as $k => $v)
unset($_SESSION[$k]);
}
public function &__get($varname)
{
if (isset($_SESSION[$varname]))
$ref = &$_SESSION[$varname];
if (InstallSession::$_cookie_mode)
{
$ref = InstallSession::$_cookie->{$varname};
if (0 === strncmp($ref, 'serialized_array:', strlen('serialized_array:')))
$ref = unserialize(substr($ref, strlen('serialized_array:')));
}
else
{
$null = null;
$ref = &$null;
if (isset($_SESSION[$varname]))
$ref = &$_SESSION[$varname];
else
{
$null = null;
$ref = &$null;
}
}
return $ref;
}
public function __set($varname, $value)
{
$_SESSION[$varname] = $value;
if (InstallSession::$_cookie_mode)
{
if ($varname == 'xml_loader_ids')
return;
if (is_array($value))
$value = 'serialized_array:'.serialize($value);
InstallSession::$_cookie->{$varname} = $value;
}
else
$_SESSION[$varname] = $value;
}
public function __isset($varname)
{
return isset($_SESSION[$varname]);
if (InstallSession::$_cookie_mode)
return isset(InstallSession::$_cookie->{$varname});
else
return isset($_SESSION[$varname]);
}
public function __unset($varname)
{
unset($_SESSION[$varname]);
if (InstallSession::$_cookie_mode)
unset(InstallSession::$_cookie->{$varname});
else
unset($_SESSION[$varname]);
}
}
+1 -1
View File
@@ -78,7 +78,7 @@ class InstallControllerHttpProcess extends InstallControllerHttp
public function process()
{
if (file_exists(_PS_ROOT_DIR_.'/'.self::SETTINGS_FILE))
@require_once _PS_ROOT_DIR_.'/'.self::SETTINGS_FILE;
require_once _PS_ROOT_DIR_.'/'.self::SETTINGS_FILE;
if (!$this->session->process_validated)
$this->session->process_validated = array();
+5 -8
View File
@@ -20,8 +20,8 @@ function start_install()
$('.stepList li:last-child').removeClass('ok').removeClass('ko');
process_pixel = parseInt($('#progress_bar .total').css('width')) / process_steps.length;
$('#tabs li a').each(function() {
this.rel=$(this).attr('href');
this.href='#';
this.rel = $(this).attr('href');
this.href = '#';
});
process_install();
}
@@ -31,11 +31,11 @@ function process_install(step)
if (!step)
step = process_steps[0];
$('.installing').hide().html(step.lang+' ...').fadeIn('slow');
$('.installing').hide().html(step.lang + ' ...').fadeIn('slow');
$.ajax({
url: 'index.php',
data: step.key+'=true',
data: step.key + '=true',
dataType: 'json',
cache: false,
success: function(json)
@@ -51,10 +51,7 @@ function process_install(step)
$('#progress_bar .total span').html('100%');
// Installation finished
setTimeout(function()
{
install_success();
}, 700)
setTimeout(function(){install_success();}, 700);
}
else
{
+4 -1
View File
@@ -83,4 +83,7 @@
<li <?php if ($this->isStepFinished($step)): ?>class="ok"<?php endif; ?>><?php echo $this->l('menu_'.$this->step) ?></li>
<?php endforeach; ?>
</ul>
</div>
</div>
<noscript>
<h3 class="errorBlock" style="margin-bottom:10px"><?php echo $this->l('To install PrestaShop, you need to have JavaScript enabled in your browser.') ?></h3>
</noscript>