diff --git a/src/sammo/Session.php b/src/sammo/Session.php index 5725f8d7..95b854b0 100644 --- a/src/sammo/Session.php +++ b/src/sammo/Session.php @@ -21,7 +21,9 @@ class Session { 'userID'=>true, 'userName'=>true, 'userGrade'=>true, - 'writeClosed'=>true + 'writeClosed'=>true, + 'generalID'=>true, + 'generalName'=>true ]; const GAME_KEY_DATE = '_g_loginDate'; @@ -31,11 +33,9 @@ class Session { private $writeClosed = false; + private $sessionID = null; - /** - * @return \sammo\Session - */ - public static function Instance(){ + public static function Instance(): Session{ static $inst = null; if($inst === null){ $inst = new Session(); @@ -43,10 +43,18 @@ class Session { return $inst; } - /** - * @return \sammo\Session - */ - public static function requireLogin($movePath = ROOT){ + public function restart(): Session{ + //NOTE: logout 프로세스는 아예 세션을 날려버리기도 하므로, 항상 안전하게 session_restart가 가능함을 보장하지 않음. + ini_set('session.use_only_cookies', false); + ini_set('session.use_cookies', false); + ini_set('session.use_trans_sid', false); + ini_set('session.cache_limiter', null); + session_start($this->sessionID); // second session_start + $this->writeClosed = false; + return $this; + } + + public static function requireLogin($movePath = ROOT): Session{ $session = Session::Instance(); if($session->isLoggedIn()){ return $session; @@ -71,6 +79,7 @@ class Session { // 세션 변수의 등록 if (session_id() == ""){ session_start(); + $this->sessionID = session_id(); } //첫 등장 @@ -81,10 +90,7 @@ class Session { } } - /** - * @return \sammo\Session - */ - public function setReadOnly(){ + public function setReadOnly(): Session{ if(!$this->writeClosed){ session_write_close(); $this->writeClosed = true; @@ -111,6 +117,12 @@ class Session { } public function __get(string $name){ + if($name == 'generalID'){ + return $this->get(DB::prefix().static::GAME_KEY_GENERAL_ID); + } + if($name == 'generalName'){ + return $this->get(DB::prefix().static::GAME_KEY_GENERAL_NAME); + } return $this->get($name); } @@ -118,7 +130,7 @@ class Session { return Util::array_get($_SESSION[$name]); } - public function login(int $userID, string $userName, int $grade) { + public function login(int $userID, string $userName, int $grade): Session { $this->set('userID', $userID); $this->set('userName', $userName); $this->set('ip', Util::get_client_ip(true)); @@ -129,7 +141,10 @@ class Session { } - public function logout() { + public function logout(): Session { + if($this->writeClosed){ + $this->restart(); + } $this->logoutGame(); $this->set('userID', null); $this->set('userName', null); @@ -138,7 +153,7 @@ class Session { return $this; } - public function loginGame(&$result = null){ + public function loginGame(&$result = null): Session{ $userID = $this->userID; if(!$userID){ if($result !== null){ @@ -167,7 +182,7 @@ class Session { $generalID && $generalName && $loginDate && $deateTime && $loginDate + 600 > $now && $deadTime > $now ){ - //로그인 정보는 5분간 유지한다. + //로그인 정보는 10분간 유지한다. if($result !== null){ $result = true; } @@ -193,11 +208,28 @@ class Session { $generalID = $general['no']; $generalName = $general['name']; + $nextTurn = new \DateTime($general['turntime']); + $nextTurn = $nextTurn->getTimestamp(); + + $deadTime = $nextTurn + $general['killturn'] * $turnterm; + if($deadTime < $now){ + if($result !== null){ + $result = false; + } + return $this; + } + $this->set($prefix.static::GAME_KEY_DATE, $now); + $this->set($prefix.static::GAME_KEY_GENERAL_ID, $generalID); + $this->set($prefix.static::GAME_KEY_GENERAL_NAME, $generalName); + $this->set($prefix.static::GAME_KEY_EXPECTED_DEADTIME, $deadTime); } - public function logoutGame(){ + public function logoutGame(): Session{ + if($this->writeClosed){ + $this->restart(); + } $prefix = DB::prefix(); $this->set($prefix.static::GAME_KEY_DATE, null); $this->set($prefix.static::GAME_KEY_GENERAL_ID, null); diff --git a/twe/_admin2_submit.php b/twe/_admin2_submit.php index e79ffb94..b80796ba 100644 --- a/twe/_admin2_submit.php +++ b/twe/_admin2_submit.php @@ -4,15 +4,18 @@ namespace sammo; include "lib.php"; include "func.php"; //로그인 검사 -CheckLogin(); -$connect = dbConn(); +$session = Session::requireLogin()->loginGame(); -if(Session::getUserGrade() < 5) { - //echo ""; - echo '_admin2.php';//TODO:debug all and replace +if($session->userGrade < 5) { + header('location:_admin2.php'); } -$generalID = getGeneralID(); +$generalID = $session->generalID; +if(!$generalID){ + header('location:_admin2.php'); +} + +$connect = dbConn(); switch($btn) { case "전체 접속허용": diff --git a/twe/func_legacy.php b/twe/func_legacy.php index 4ead6ac3..78db793a 100644 --- a/twe/func_legacy.php +++ b/twe/func_legacy.php @@ -3,15 +3,17 @@ namespace sammo; function CheckLogin($type=0) { - if(!isset($_SESSION['userID'])) { - if($type == 0) { - header('Location: ../'); - } - else { - header('Location: index.php'); - } - exit(); + //TODO: 직접해라. setReadOnly() 호출이 필요하다. + if(Session::Instance()->loginGame()->generalID){ + return; } + if($type == 0) { + header('Location: ../'); + } + else { + header('Location: index.php'); + } + exit(); } diff --git a/twe/index.php b/twe/index.php index 80fcf219..63ea1dd8 100644 --- a/twe/index.php +++ b/twe/index.php @@ -4,33 +4,28 @@ namespace sammo; include "lib.php"; include "func.php"; +$session = Session::Instance()->loginGame(); $connect = dbConn(); -increaseRefresh("메인", 2); +increaseRefresh("메인", 1); checkTurn($connect); $db = DB::db(); -//로그인 검사 -if(!isSigned()){ - header('Location:../'); +if(!$session->userID){ + header('Location:..'); die(); } -$userID = Session::getUserID(); -if(!$userID){ - header('Location:../'); - die(); -} - -$me = $db->queryFirstRow('select no,con,turntime,newmsg,newvote,map from general where owner = %i', $userID); +$me = $db->queryFirstRow('SELECT no,con,turntime,newmsg,newvote,map from general where owner = %i', $userID); //그새 사망이면 if($me === null) { - resetSessionGeneralValues(); + $session->loginGame(); header('Location: ../'); die(); } +$session->setReadOnly(); if($me['newmsg'] == 1 && $me['newvote'] == 1) { $query = "update general set newmsg=0,newvote=0 where owner='{$_SESSION['userID']}'"; diff --git a/twe/j_msgsubmit.php b/twe/j_msgsubmit.php index 2f8c6e62..981b1256 100644 --- a/twe/j_msgsubmit.php +++ b/twe/j_msgsubmit.php @@ -28,7 +28,7 @@ if(!isset($post['genlist']) || !isset($post['msg'])){ $destMailbox = $post['dest_mailbox']; $msg = $post['msg']; -$datetime = new DateTime(); +$datetime = new \DateTime(); $date = $datetime->format('Y-m-d H:i:s'); //로그인 검사 @@ -120,7 +120,7 @@ if($destMailbox == 9999) { // 개인 메세지 } elseif($destMailbox > 0) { - $last_msg = new DateTime(Util::array_get($_SESSION['last_msg'], '0000-00-00')); + $last_msg = new \DateTime(Util::array_get($_SESSION['last_msg'], '0000-00-00')); $msg_interval = $datetime->getTimestamp() - $last_msg->getTimestamp(); //NOTE: 여기서 유저 레벨을 구별할 코드가 필요할까? diff --git a/twe/lib.php b/twe/lib.php index dfa70b7c..ec24cc97 100644 --- a/twe/lib.php +++ b/twe/lib.php @@ -96,11 +96,9 @@ $_taxrate = 0.01; // 군량 매매시 세율 //$images = "http://jwh1807.vipweb.kr/images"; //$image = "http://jwh1807.vipweb.kr/image"; $image1 = "../d_pic"; - $images = "/images"; - $image = "/image"; +$images = "/images"; +$image = "/image"; -unset($member); -unset($setup); // Data, Icon, 세션디렉토리의 쓰기 권한이 없다면 에러 처리 // 단, 폴더가 없는 경우라면 폴더를 생성 할 필요가 있음. @@ -113,26 +111,6 @@ if(is_dir(__DIR__."/data")){ session_cache_limiter('nocache, must_revalidate');//NOTE: 캐시가 가능하도록 설정해야 할 수도 있음. 주의! -// 세션 변수의 등록 -//NOTE: ajax등의 경우에는 session_write_close로 빠르게 끝낼 수 있어야한다. -session_start(); - -//첫 등장 -if(!Util::array_get($_SESSION['p_ip'], null)) { - $_SESSION['p_ip'] = getenv("REMOTE_ADDR"); - $_SESSION['p_time'] = time(); -} - -//id, 이름, 국가는 로그인에서 -//초과된 세션은 로그아웃(1시간) -//TODO: 로그아웃 원리를 다시 확인 -if($_SESSION['p_time']+3600 < time()) { - resetSessionGeneralValues(); - $_SESSION['p_time'] = time(); -} else { - $_SESSION['p_time'] = time(); -} - /** * Session에 보관된 장수 정보를 제거함. * _prefix_p_no, _prefix_p_name 두 값임