%FORCE_IP%

master
BodgeMaster 2020-02-21 13:14:22 +01:00
parent 9f9877b8b4
commit 58f97c8d49
3 changed files with 15 additions and 11 deletions

View File

@ -10,6 +10,8 @@ echo "Deployment script for repository \"web-deployment\"
==============================================================================" =============================================================================="
rewrite_code %CONTENT_DIR% "\/common\/threadr" rewrite_code %CONTENT_DIR% "\/common\/threadr"
rewrite_code %ENFORCE_IP% `cat enforce_ip.template`
echo "============================================================================== echo "==============================================================================
Done." Done."

12
enforce_ip.template Normal file
View File

@ -0,0 +1,12 @@
if ($_SESSION['user_ip']!=$_SERVER['REMOTE_ADDR']){
// force logout
$_SESSION = array();
if (ini_get("session.use_cookies")) {
$params = session_get_cookie_params();
setcookie(session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"]);
}
session_destroy();
header("Location: https://lostcave.ddnss.de/common/threadr/login/?error=session");
die();
}

View File

@ -1,17 +1,7 @@
<?php <?php
session_start(); session_start();
//Todo: make this a setting for users that use VPNs/Proxies and seem to jump around the world rather quickly... //Todo: make this a setting for users that use VPNs/Proxies and seem to jump around the world rather quickly...
if ($_SESSION['user_ip']!=$_SERVER['REMOTE_ADDR']){ %ENFORCE_IP%
// force logout
$_SESSION = array();
if (ini_get("session.use_cookies")) {
$params = session_get_cookie_params();
setcookie(session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"]);
}
session_destroy();
header("Location: https://lostcave.ddnss.de/common/threadr/login/?error=session");
die();
}
$pdo = new PDO('mysql:host=localhost;dbname=web', 'webstuff', 'Schei// auf Pa$$w0rter!'); $pdo = new PDO('mysql:host=localhost;dbname=web', 'webstuff', 'Schei// auf Pa$$w0rter!');
$statement = $pdo->prepare('SELECT name FROM users WHERE id = :user_id;'); // to be replaced with optional user name off the user data table $statement = $pdo->prepare('SELECT name FROM users WHERE id = :user_id;'); // to be replaced with optional user name off the user data table