]> git.wh0rd.org - tt-rss.git/blame - sessions.php
filters: cast score expression as integer on save to prevent misscoring
[tt-rss.git] / sessions.php
CommitLineData
1d3a17c7 1<?php
36bfab86
AD
2 // Original from http://www.daniweb.com/code/snippet43.html
3
4 require_once "config.php";
5 require_once "db.php";
6
898a9cdb 7 $session_expire = SESSION_EXPIRE_TIME; //seconds
3dd46f19 8 $session_name = (!defined('TTRSS_SESSION_NAME')) ? "ttrss_sid" : TTRSS_SESSION_NAME;
36bfab86 9
3d72afa1
AD
10 if ($_SERVER['HTTPS'] == "on") {
11 $session_name .= "_ssl";
12 ini_set("session.cookie_secure", true);
13 }
14
36bfab86 15 ini_set("session.gc_probability", 50);
3dd46f19 16 ini_set("session.name", $session_name);
c5466b7f 17 ini_set("session.use_only_cookies", true);
5bd977a1 18 ini_set("session.gc_maxlifetime", SESSION_EXPIRE_TIME);
36bfab86 19
5be00836 20 function ttrss_open ($s, $n) {
3d72afa1 21
36bfab86 22 global $session_connection;
3d72afa1 23
36bfab86 24 $session_connection = db_connect(DB_HOST, DB_USER, DB_PASS, DB_NAME);
3d72afa1 25
36bfab86
AD
26 return true;
27 }
28
5be00836 29 function ttrss_read ($id){
3d72afa1
AD
30
31 global $session_connection,$session_read;
36bfab86 32
7a293008 33 $query = "SELECT data FROM ttrss_sessions WHERE id='$id'";
36bfab86
AD
34
35 $res = db_query($session_connection, $query);
3d72afa1 36
36bfab86
AD
37 if (db_num_rows($res) != 1) {
38 return "";
39 } else {
40 $session_read = db_fetch_assoc($res);
41 $session_read["data"] = base64_decode($session_read["data"]);
42 return $session_read["data"];
43 }
44 }
45
5be00836 46 function ttrss_write ($id, $data) {
3d72afa1
AD
47
48 if (! $data) {
49 return false;
36bfab86 50 }
3d72afa1 51
36bfab86 52 global $session_connection, $session_read, $session_expire;
3d72afa1 53
36bfab86 54 $expire = time() + $session_expire;
3d72afa1 55
36bfab86 56 $data = db_escape_string(base64_encode($data), $session_connection);
3d72afa1 57
36bfab86 58 if ($session_read) {
3d72afa1
AD
59 $query = "UPDATE ttrss_sessions SET data='$data',
60 expire='$expire' WHERE id='$id'";
36bfab86 61 } else {
a2e9b457
AD
62 $query = "INSERT INTO ttrss_sessions (id, data, expire)
63 VALUES ('$id', '$data', '$expire')";
36bfab86 64 }
3d72afa1 65
36bfab86
AD
66 db_query($session_connection, $query);
67 return true;
68 }
69
5be00836 70 function ttrss_close () {
3d72afa1 71
36bfab86 72 global $session_connection;
3d72afa1 73
36bfab86 74 db_close($session_connection);
3d72afa1 75
36bfab86
AD
76 return true;
77 }
78
5be00836 79 function ttrss_destroy ($id) {
3d72afa1 80
36bfab86 81 global $session_connection;
09018e95 82
7a293008 83 $query = "DELETE FROM ttrss_sessions WHERE id = '$id'";
3d72afa1 84
36bfab86 85 db_query($session_connection, $query);
3d72afa1 86
36bfab86
AD
87 return true;
88 }
89
5be00836 90 function ttrss_gc ($expire) {
3d72afa1 91
36bfab86 92 global $session_connection;
3d72afa1 93
36bfab86 94 $query = "DELETE FROM ttrss_sessions WHERE expire < " . time();
3d72afa1 95
36bfab86
AD
96 db_query($session_connection, $query);
97 }
98
8fd92701 99 if (DATABASE_BACKED_SESSIONS) {
3d72afa1
AD
100 session_set_save_handler("ttrss_open",
101 "ttrss_close", "ttrss_read", "ttrss_write",
5be00836 102 "ttrss_destroy", "ttrss_gc");
8fd92701 103 }
d620cfe7 104
1df0f48b 105 session_set_cookie_params(SESSION_COOKIE_LIFETIME);
d620cfe7 106
36bfab86
AD
107 session_start();
108?>