| 1 | <?php |
| 2 | |
| 3 | /** |
| 4 | * globals.php |
| 5 | * |
| 6 | * Copyright (c) 1999-2003 The SquirrelMail Project Team |
| 7 | * Licensed under the GNU GPL. For full terms see the file COPYING. |
| 8 | * |
| 9 | * This includes code to update < 4.1.0 globals to the newer format |
| 10 | * It also has some session register functions that work across various |
| 11 | * php versions. |
| 12 | * |
| 13 | * $Id$ |
| 14 | */ |
| 15 | |
| 16 | require_once(SM_PATH . 'config/config.php'); |
| 17 | |
| 18 | /* set the name of the session cookie */ |
| 19 | if(isset($session_name) && $session_name) { |
| 20 | ini_set('session.name' , $session_name); |
| 21 | } else { |
| 22 | ini_set('session.name' , 'SQMSESSID'); |
| 23 | } |
| 24 | |
| 25 | /* If magic_quotes_runtime is on, SquirrelMail breaks in new and creative ways. |
| 26 | * Force magic_quotes_runtime off. |
| 27 | * chilts@birdbrained.org - I put it here in the hopes that all SM code includes this. |
| 28 | * If there's a better place, please let me know. |
| 29 | */ |
| 30 | ini_set('magic_quotes_runtime','0'); |
| 31 | |
| 32 | /* convert old-style superglobals to current method |
| 33 | * this is executed if you are running PHP 4.0.x. |
| 34 | * it is run via a require_once directive in validate.php |
| 35 | * and redirect.php. Patch submitted by Ray Black. |
| 36 | */ |
| 37 | |
| 38 | if ( !check_php_version(4,1) ) { |
| 39 | global $_COOKIE, $_ENV, $_FILES, $_GET, $_POST, $_SERVER, $_SESSION; |
| 40 | global $HTTP_COOKIE_VARS, $HTTP_ENV_VARS, $HTTP_POST_FILES, $HTTP_GET_VARS, |
| 41 | $HTTP_POST_VARS, $HTTP_SERVER_VARS, $HTTP_SESSION_VARS, $PHP_SELF; |
| 42 | $_COOKIE =& $HTTP_COOKIE_VARS; |
| 43 | $_ENV =& $HTTP_ENV_VARS; |
| 44 | $_FILES =& $HTTP_POST_FILES; |
| 45 | $_GET =& $HTTP_GET_VARS; |
| 46 | $_POST =& $HTTP_POST_VARS; |
| 47 | $_SERVER =& $HTTP_SERVER_VARS; |
| 48 | $_SESSION =& $HTTP_SESSION_VARS; |
| 49 | if (!isset($PHP_SELF) || empty($PHP_SELF)) { |
| 50 | $PHP_SELF = $HTTP_SERVER_VARS['PHP_SELF']; |
| 51 | } |
| 52 | } |
| 53 | |
| 54 | /* if running with magic_quotes_gpc then strip the slashes |
| 55 | from POST and GET global arrays */ |
| 56 | |
| 57 | if (get_magic_quotes_gpc()) { |
| 58 | sqstripslashes($_GET); |
| 59 | sqstripslashes($_POST); |
| 60 | } |
| 61 | |
| 62 | /* strip any tags added to the url from PHP_SELF. |
| 63 | This fixes hand crafted url XXS expoits for any |
| 64 | page that uses PHP_SELF as the FORM action */ |
| 65 | |
| 66 | $_SERVER['PHP_SELF'] = strip_tags($_SERVER['PHP_SELF']); |
| 67 | |
| 68 | /** |
| 69 | * returns true if current php version is at mimimum a.b.c |
| 70 | * |
| 71 | * Called: check_php_version(4,1) |
| 72 | */ |
| 73 | function check_php_version ($a = '0', $b = '0', $c = '0') |
| 74 | { |
| 75 | global $SQ_PHP_VERSION; |
| 76 | |
| 77 | if(!isset($SQ_PHP_VERSION)) |
| 78 | $SQ_PHP_VERSION = substr( str_pad( preg_replace('/\D/','', PHP_VERSION), 3, '0'), 0, 3); |
| 79 | |
| 80 | return $SQ_PHP_VERSION >= ($a.$b.$c); |
| 81 | } |
| 82 | |
| 83 | /** |
| 84 | * returns true if the current internal SM version is at minimum a.b.c |
| 85 | * These are plain integer comparisons, as our internal version is |
| 86 | * constructed by us, as an array of 3 ints. |
| 87 | * |
| 88 | * Called: check_sm_version(1,3,3) |
| 89 | */ |
| 90 | function check_sm_version($a = 0, $b = 0, $c = 0) |
| 91 | { |
| 92 | global $SQM_INTERNAL_VERSION; |
| 93 | if ( !isset($SQM_INTERNAL_VERSION) || |
| 94 | $SQM_INTERNAL_VERSION[0] < $a || |
| 95 | $SQM_INTERNAL_VERSION[1] < $b || |
| 96 | ( $SQM_INTERNAL_VERSION[1] == $b && |
| 97 | $SQM_INTERNAL_VERSION[2] < $c ) ) { |
| 98 | return FALSE; |
| 99 | } |
| 100 | return TRUE; |
| 101 | } |
| 102 | |
| 103 | |
| 104 | /* recursively strip slashes from the values of an array */ |
| 105 | function sqstripslashes(&$array) { |
| 106 | if(count($array) > 0) { |
| 107 | foreach ($array as $index=>$value) { |
| 108 | if (is_array($array[$index])) { |
| 109 | sqstripslashes($array[$index]); |
| 110 | } |
| 111 | else { |
| 112 | $array[$index] = stripslashes($value); |
| 113 | } |
| 114 | } |
| 115 | } |
| 116 | } |
| 117 | |
| 118 | function sqsession_register ($var, $name) { |
| 119 | |
| 120 | sqsession_is_active(); |
| 121 | |
| 122 | if ( !check_php_version(4,1) ) { |
| 123 | global $HTTP_SESSION_VARS; |
| 124 | $HTTP_SESSION_VARS[$name] = $var; |
| 125 | } |
| 126 | else { |
| 127 | $_SESSION["$name"] = $var; |
| 128 | } |
| 129 | session_register("$name"); |
| 130 | } |
| 131 | |
| 132 | function sqsession_unregister ($name) { |
| 133 | |
| 134 | sqsession_is_active(); |
| 135 | |
| 136 | if ( !check_php_version(4,1) ) { |
| 137 | global $HTTP_SESSION_VARS; |
| 138 | unset($HTTP_SESSION_VARS[$name]); |
| 139 | } |
| 140 | else { |
| 141 | unset($_SESSION[$name]); |
| 142 | } |
| 143 | session_unregister("$name"); |
| 144 | } |
| 145 | |
| 146 | function sqsession_is_registered ($name) { |
| 147 | $test_name = &$name; |
| 148 | $result = false; |
| 149 | if ( !check_php_version(4,1) ) { |
| 150 | global $HTTP_SESSION_VARS; |
| 151 | if (isset($HTTP_SESSION_VARS[$test_name])) { |
| 152 | $result = true; |
| 153 | } |
| 154 | } |
| 155 | else { |
| 156 | if (isset($_SESSION[$test_name])) { |
| 157 | $result = true; |
| 158 | } |
| 159 | } |
| 160 | return $result; |
| 161 | } |
| 162 | |
| 163 | |
| 164 | define('SQ_INORDER',0); |
| 165 | define('SQ_GET',1); |
| 166 | define('SQ_POST',2); |
| 167 | define('SQ_SESSION',3); |
| 168 | define('SQ_COOKIE',4); |
| 169 | define('SQ_SERVER',5); |
| 170 | define('SQ_FORM',6); |
| 171 | |
| 172 | /** |
| 173 | * Search for the var $name in $_SESSION, $_POST, $_GET, |
| 174 | * $_COOKIE, or $_SERVER and set it in provided var. |
| 175 | * |
| 176 | * If $search is not provided, or == SQ_INORDER, it will search |
| 177 | * $_SESSION, then $_POST, then $_GET. Otherwise, |
| 178 | * use one of the defined constants to look for |
| 179 | * a var in one place specifically. |
| 180 | * |
| 181 | * Note: $search is an int value equal to one of the |
| 182 | * constants defined above. |
| 183 | * |
| 184 | * example: |
| 185 | * sqgetGlobalVar('username',$username,SQ_SESSION); |
| 186 | * -- no quotes around last param! |
| 187 | * |
| 188 | * Returns FALSE if variable is not found. |
| 189 | * Returns TRUE if it is. |
| 190 | */ |
| 191 | function sqgetGlobalVar($name, &$value, $search = SQ_INORDER) { |
| 192 | |
| 193 | if ( !check_php_version(4,1) ) { |
| 194 | global $HTTP_COOKIE_VARS, $HTTP_GET_VARS, $HTTP_POST_VARS, |
| 195 | $HTTP_SERVER_VARS, $HTTP_SESSION_VARS; |
| 196 | |
| 197 | $_COOKIE =& $HTTP_COOKIE_VARS; |
| 198 | $_GET =& $HTTP_GET_VARS; |
| 199 | $_POST =& $HTTP_POST_VARS; |
| 200 | $_SERVER =& $HTTP_SERVER_VARS; |
| 201 | $_SESSION =& $HTTP_SESSION_VARS; |
| 202 | } |
| 203 | |
| 204 | /* NOTE: DO NOT enclose the constants in the switch |
| 205 | statement with quotes. They are constant values, |
| 206 | enclosing them in quotes will cause them to evaluate |
| 207 | as strings. */ |
| 208 | switch ($search) { |
| 209 | /* we want the default case to be first here, |
| 210 | so that if a valid value isn't specified, |
| 211 | all three arrays will be searched. */ |
| 212 | default: |
| 213 | case SQ_INORDER: // check session, post, get |
| 214 | case SQ_SESSION: |
| 215 | if( isset($_SESSION[$name]) ) { |
| 216 | $value = $_SESSION[$name]; |
| 217 | return TRUE; |
| 218 | } elseif ( $search == SQ_SESSION ) { |
| 219 | break; |
| 220 | } |
| 221 | case SQ_FORM: // check post, get |
| 222 | case SQ_POST: |
| 223 | if( isset($_POST[$name]) ) { |
| 224 | $value = $_POST[$name]; |
| 225 | return TRUE; |
| 226 | } elseif ( $search == SQ_POST ) { |
| 227 | break; |
| 228 | } |
| 229 | case SQ_GET: |
| 230 | if ( isset($_GET[$name]) ) { |
| 231 | $value = $_GET[$name]; |
| 232 | return TRUE; |
| 233 | } |
| 234 | /* NO IF HERE. FOR SQ_INORDER CASE, EXIT after GET */ |
| 235 | break; |
| 236 | case SQ_COOKIE: |
| 237 | if ( isset($_COOKIE[$name]) ) { |
| 238 | $value = $_COOKIE[$name]; |
| 239 | return TRUE; |
| 240 | } |
| 241 | break; |
| 242 | case SQ_SERVER: |
| 243 | if ( isset($_SERVER[$name]) ) { |
| 244 | $value = $_SERVER[$name]; |
| 245 | return TRUE; |
| 246 | } |
| 247 | break; |
| 248 | } |
| 249 | return FALSE; |
| 250 | } |
| 251 | |
| 252 | function sqsession_destroy() { |
| 253 | |
| 254 | /* |
| 255 | * php.net says we can kill the cookie by setting just the name: |
| 256 | * http://www.php.net/manual/en/function.setcookie.php |
| 257 | * maybe this will help fix the session merging again. |
| 258 | * |
| 259 | * Changed the theory on this to kill the cookies first starting |
| 260 | * a new session will provide a new session for all instances of |
| 261 | * the browser, we don't want that, as that is what is causing the |
| 262 | * merging of sessions. |
| 263 | */ |
| 264 | |
| 265 | global $base_uri; |
| 266 | |
| 267 | if (isset($_COOKIE[session_name()])) setcookie(session_name(), '', time() - 5, $base_uri); |
| 268 | if (isset($_COOKIE['username'])) setcookie('username','',time() - 5,$base_uri); |
| 269 | if (isset($_COOKIE['key'])) setcookie('key','',time() - 5,$base_uri); |
| 270 | |
| 271 | $sessid = session_id(); |
| 272 | if (!empty( $sessid )) { |
| 273 | if ( !check_php_version(4,1) ) { |
| 274 | global $HTTP_SESSION_VARS; |
| 275 | $HTTP_SESSION_VARS = array(); |
| 276 | } else { |
| 277 | $_SESSION = array(); |
| 278 | } |
| 279 | @session_destroy(); |
| 280 | } |
| 281 | |
| 282 | } |
| 283 | |
| 284 | /* |
| 285 | * Function to verify a session has been started. If it hasn't |
| 286 | * start a session up. php.net doesn't tell you that $_SESSION |
| 287 | * (even though autoglobal), is not created unless a session is |
| 288 | * started, unlike $_POST, $_GET and such |
| 289 | */ |
| 290 | |
| 291 | function sqsession_is_active() { |
| 292 | |
| 293 | $sessid = session_id(); |
| 294 | if ( empty( $sessid ) ) { |
| 295 | session_start(); |
| 296 | } |
| 297 | } |
| 298 | |
| 299 | |
| 300 | ?> |