61d9ec71 |
1 | <?php |
2 | |
3 | /** |
4 | * globals.php |
5 | * |
76911253 |
6 | * Copyright (c) 1999-2003 The SquirrelMail Project Team |
61d9ec71 |
7 | * Licensed under the GNU GPL. For full terms see the file COPYING. |
8 | * |
9 | * This includes code to update < 4.1.0 globals to the newer format |
242342d0 |
10 | * It also has some session register functions that work across various |
61d9ec71 |
11 | * php versions. |
12 | * |
242342d0 |
13 | * $Id$ |
61d9ec71 |
14 | */ |
15 | |
ebabf3f5 |
16 | require_once(SM_PATH . 'config/config.php'); |
17 | |
18 | /* set the name of the session cookie */ |
19 | if(isset($session_name) && $session_name) { |
20 | ini_set('session.name' , $session_name); |
21 | } else { |
22 | ini_set('session.name' , 'SQMSESSID'); |
23 | } |
24 | |
388c855c |
25 | /* If magic_quotes_runtime is on, SquirrelMail breaks in new and creative ways. |
26 | * Force magic_quotes_runtime off. |
27 | * chilts@birdbrained.org - I put it here in the hopes that all SM code includes this. |
28 | * If there's a better place, please let me know. |
29 | */ |
5f660901 |
30 | ini_set('magic_quotes_runtime','0'); |
61d9ec71 |
31 | |
32 | /* convert old-style superglobals to current method |
33 | * this is executed if you are running PHP 4.0.x. |
34 | * it is run via a require_once directive in validate.php |
35 | * and redirect.php. Patch submitted by Ray Black. |
36 | */ |
37 | |
9697c5ab |
38 | if ( !check_php_version(4,1) ) { |
61d9ec71 |
39 | global $_COOKIE, $_ENV, $_FILES, $_GET, $_POST, $_SERVER, $_SESSION; |
40 | global $HTTP_COOKIE_VARS, $HTTP_ENV_VARS, $HTTP_POST_FILES, $HTTP_GET_VARS, |
41 | $HTTP_POST_VARS, $HTTP_SERVER_VARS, $HTTP_SESSION_VARS; |
42 | $_COOKIE =& $HTTP_COOKIE_VARS; |
43 | $_ENV =& $HTTP_ENV_VARS; |
44 | $_FILES =& $HTTP_POST_FILES; |
45 | $_GET =& $HTTP_GET_VARS; |
46 | $_POST =& $HTTP_POST_VARS; |
47 | $_SERVER =& $HTTP_SERVER_VARS; |
48 | $_SESSION =& $HTTP_SESSION_VARS; |
49 | } |
50 | |
180239ca |
51 | /* if running with magic_quotes_gpc then strip the slashes |
a32985a5 |
52 | from POST and GET global arrays */ |
53 | |
54 | if (get_magic_quotes_gpc()) { |
180239ca |
55 | sqstripslashes($_GET); |
56 | sqstripslashes($_POST); |
a32985a5 |
57 | } |
58 | |
59 | /* strip any tags added to the url from PHP_SELF. |
60 | This fixes hand crafted url XXS expoits for any |
61 | page that uses PHP_SELF as the FORM action */ |
62 | |
388c855c |
63 | $_SERVER['PHP_SELF'] = strip_tags($_SERVER['PHP_SELF']); |
a32985a5 |
64 | |
97bdc607 |
65 | /** |
66 | * returns true if current php version is at mimimum a.b.c |
67 | * |
68 | * Called: check_php_version(4,1) |
69 | */ |
9697c5ab |
70 | function check_php_version ($a = '0', $b = '0', $c = '0') |
71 | { |
3aa17cf9 |
72 | global $SQ_PHP_VERSION; |
97bdc607 |
73 | |
3aa17cf9 |
74 | if(!isset($SQ_PHP_VERSION)) |
5123154f |
75 | $SQ_PHP_VERSION = substr( str_pad( preg_replace('/\D/','', PHP_VERSION), 3, '0'), 0, 3); |
9697c5ab |
76 | |
3aa17cf9 |
77 | return $SQ_PHP_VERSION >= ($a.$b.$c); |
9697c5ab |
78 | } |
79 | |
97bdc607 |
80 | /** |
81 | * returns true if the current internal SM version is at minimum a.b.c |
82 | * These are plain integer comparisons, as our internal version is |
83 | * constructed by us, as an array of 3 ints. |
84 | * |
85 | * Called: check_sm_version(1,3,3) |
86 | */ |
87 | function check_sm_version($a = 0, $b = 0, $c = 0) |
88 | { |
89 | global $SQM_INTERNAL_VERSION; |
90 | if ( !isset($SQM_INTERNAL_VERSION) || |
91 | $SQM_INTERNAL_VERSION[0] < $a || |
92 | $SQM_INTERNAL_VERSION[1] < $b || |
93 | ( $SQM_INTERNAL_VERSION[1] == $b && |
94 | $SQM_INTERNAL_VERSION[2] < $c ) ) { |
95 | return FALSE; |
96 | } |
97 | return TRUE; |
98 | } |
99 | |
100 | |
3aa17cf9 |
101 | /* recursively strip slashes from the values of an array */ |
a32985a5 |
102 | function sqstripslashes(&$array) { |
3aa17cf9 |
103 | if(count($array) > 0) { |
104 | foreach ($array as $index=>$value) { |
105 | if (is_array($array[$index])) { |
106 | sqstripslashes($array[$index]); |
107 | } |
108 | else { |
109 | $array[$index] = stripslashes($value); |
110 | } |
a32985a5 |
111 | } |
112 | } |
113 | } |
114 | |
61d9ec71 |
115 | function sqsession_register ($var, $name) { |
281c3d5b |
116 | |
117 | sqsession_is_active(); |
118 | |
9697c5ab |
119 | if ( !check_php_version(4,1) ) { |
61d9ec71 |
120 | global $HTTP_SESSION_VARS; |
9697c5ab |
121 | $HTTP_SESSION_VARS[$name] = $var; |
61d9ec71 |
122 | } |
123 | else { |
d7c82551 |
124 | $_SESSION["$name"] = $var; |
61d9ec71 |
125 | } |
3658a999 |
126 | session_register("$name"); |
61d9ec71 |
127 | } |
3aa17cf9 |
128 | |
61d9ec71 |
129 | function sqsession_unregister ($name) { |
281c3d5b |
130 | |
131 | sqsession_is_active(); |
132 | |
9697c5ab |
133 | if ( !check_php_version(4,1) ) { |
d7c82551 |
134 | global $HTTP_SESSION_VARS; |
9697c5ab |
135 | unset($HTTP_SESSION_VARS[$name]); |
61d9ec71 |
136 | } |
137 | else { |
9697c5ab |
138 | unset($_SESSION[$name]); |
61d9ec71 |
139 | } |
3658a999 |
140 | session_unregister("$name"); |
61d9ec71 |
141 | } |
3aa17cf9 |
142 | |
d7c82551 |
143 | function sqsession_is_registered ($name) { |
144 | $test_name = &$name; |
145 | $result = false; |
9697c5ab |
146 | if ( !check_php_version(4,1) ) { |
d7c82551 |
147 | global $HTTP_SESSION_VARS; |
148 | if (isset($HTTP_SESSION_VARS[$test_name])) { |
149 | $result = true; |
150 | } |
151 | } |
152 | else { |
153 | if (isset($_SESSION[$test_name])) { |
154 | $result = true; |
155 | } |
156 | } |
157 | return $result; |
158 | } |
159 | |
61d9ec71 |
160 | |
4cd8ae7d |
161 | define('SQ_INORDER',0); |
162 | define('SQ_GET',1); |
163 | define('SQ_POST',2); |
164 | define('SQ_SESSION',3); |
27d0841c |
165 | define('SQ_COOKIE',4); |
166 | define('SQ_SERVER',5); |
4cd8ae7d |
167 | |
168 | /** |
27d0841c |
169 | * Search for the var $name in $_SESSION, $_POST, $_GET, |
170 | * $_COOKIE, or $_SERVER and set it in provided var. |
4cd8ae7d |
171 | * If $search is not provided, or == SQ_INORDER, it will search |
172 | * $_SESSION, then $_POST, then $_GET. Otherwise, |
173 | * use one of the defined constants to look for |
174 | * a var in one place specifically. |
175 | * Returns FALSE if variable is not found. |
176 | * Returns TRUE if it is. |
177 | */ |
178 | function sqgetGlobalVar($name, &$value, $search = SQ_INORDER) { |
179 | if ( !check_php_version(4,1) ) { |
27d0841c |
180 | global $_SESSION, $_GET, $_POST, $_COOKIE, $_SERVER; |
4cd8ae7d |
181 | } |
182 | |
183 | switch ($search) { |
184 | /* we want the default case to be first here, |
185 | so that if a valid value isn't specified, |
186 | all three arrays will be searched. */ |
187 | default: |
188 | case SQ_INORDER: |
189 | case SQ_SESSION: |
190 | if( isset($_SESSION[$name]) ) { |
191 | $value = $_SESSION[$name]; |
192 | return TRUE; |
193 | } elseif ( $search == SQ_SESSION ) { |
194 | break; |
195 | } |
196 | case SQ_POST: |
197 | if( isset($_POST[$name]) ) { |
198 | $value = $_POST[$name]; |
199 | return TRUE; |
200 | } elseif ( $search == SQ_POST ) { |
201 | break; |
202 | } |
203 | case SQ_GET: |
204 | if ( isset($_GET[$name]) ) { |
205 | $value = $_GET[$name]; |
206 | return TRUE; |
27d0841c |
207 | } |
208 | /* NO IF HERE. FOR DEFAULT CASE, EXIT after GET */ |
209 | break; |
210 | case SQ_COOKIE: |
211 | if ( isset($_COOKIE[$name]) ) { |
212 | $value = $_COOKIE[$name]; |
213 | return TRUE; |
214 | } |
215 | break; |
216 | case SQ_SERVER: |
217 | if ( isset($_SERVER[$name]) ) { |
218 | $value = $_SERVER[$name]; |
219 | return TRUE; |
220 | } |
221 | break; |
4cd8ae7d |
222 | } |
223 | return FALSE; |
224 | } |
225 | |
226 | |
61d9ec71 |
227 | /** |
228 | * Search for the var $name in $_SESSION, $_POST, $_GET |
229 | * (in that order) and register it as a global var. |
230 | */ |
231 | function sqextractGlobalVar ($name) { |
9697c5ab |
232 | if ( !check_php_version(4,1) ) { |
a32985a5 |
233 | global $_SESSION, $_GET, $_POST; |
234 | } |
235 | global $$name; |
61d9ec71 |
236 | if( isset($_SESSION[$name]) ) { |
237 | $$name = $_SESSION[$name]; |
238 | } |
239 | if( isset($_POST[$name]) ) { |
240 | $$name = $_POST[$name]; |
241 | } |
242 | else if ( isset($_GET[$name]) ) { |
243 | $$name = $_GET[$name]; |
244 | } |
245 | } |
513db22c |
246 | |
247 | function sqsession_destroy() { |
242342d0 |
248 | |
281c3d5b |
249 | /* |
250 | * php.net says we can kill the cookie by setting just the name: |
251 | * http://www.php.net/manual/en/function.setcookie.php |
252 | * maybe this will help fix the session merging again. |
253 | * |
254 | * Changed the theory on this to kill the cookies first starting |
255 | * a new session will provide a new session for all instances of |
256 | * the browser, we don't want that, as that is what is causing the |
257 | * merging of sessions. |
258 | */ |
242342d0 |
259 | |
f9902ccb |
260 | global $base_uri; |
f31687f6 |
261 | |
262 | if (isset($_COOKIE[session_name()])) setcookie(session_name(), '', time() - 5, $base_uri); |
263 | if (isset($_COOKIE['username'])) setcookie('username','',time() - 5,$base_uri); |
264 | if (isset($_COOKIE['key'])) setcookie('key','',time() - 5,$base_uri); |
281c3d5b |
265 | |
266 | $sessid = session_id(); |
267 | if (!empty( $sessid )) { |
268 | if ( !check_php_version(4,1) ) { |
269 | global $HTTP_SESSION_VARS; |
270 | $HTTP_SESSION_VARS = array(); |
271 | } else { |
272 | $_SESSION = array(); |
273 | } |
274 | @session_destroy; |
242342d0 |
275 | } |
276 | |
281c3d5b |
277 | } |
242342d0 |
278 | |
281c3d5b |
279 | /* |
280 | * Function to verify a session has been started. If it hasn't |
281 | * start a session up. php.net doesn't tell you that $_SESSION |
282 | * (even though autoglobal), is not created unless a session is |
283 | * started, unlike $_POST, $_GET and such |
284 | */ |
285 | |
286 | function sqsession_is_active() { |
287 | |
288 | $sessid = session_id(); |
289 | if ( empty( $sessid ) ) { |
290 | session_start(); |
291 | } |
513db22c |
292 | } |
293 | |
281c3d5b |
294 | |
61d9ec71 |
295 | ?> |