PHPSessionHandler: Suppress warnings in initialize()
[lhc/web/wiklou.git] / includes / session / PHPSessionHandler.php
1 <?php
2 /**
3 * Session storage in object cache.
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 * http://www.gnu.org/copyleft/gpl.html
19 *
20 * @file
21 * @ingroup Session
22 */
23
24 namespace MediaWiki\Session;
25
26 use Psr\Log\LoggerInterface;
27 use BagOStuff;
28
29 /**
30 * Adapter for PHP's session handling
31 * @ingroup Session
32 * @since 1.27
33 */
34 class PHPSessionHandler implements \SessionHandlerInterface {
35 /** @var PHPSessionHandler */
36 protected static $instance = null;
37
38 /** @var bool Whether PHP session handling is enabled */
39 protected $enable = false;
40 protected $warn = true;
41
42 /** @var SessionManager|null */
43 protected $manager;
44
45 /** @var BagOStuff|null */
46 protected $store;
47
48 /** @var LoggerInterface */
49 protected $logger;
50
51 /** @var array Track original session fields for later modification check */
52 protected $sessionFieldCache = [];
53
54 protected function __construct( SessionManager $manager ) {
55 $this->setEnableFlags(
56 \RequestContext::getMain()->getConfig()->get( 'PHPSessionHandling' )
57 );
58 $manager->setupPHPSessionHandler( $this );
59 }
60
61 /**
62 * Set $this->enable and $this->warn
63 *
64 * Separate just because there doesn't seem to be a good way to test it
65 * otherwise.
66 *
67 * @param string $PHPSessionHandling See $wgPHPSessionHandling
68 */
69 private function setEnableFlags( $PHPSessionHandling ) {
70 switch ( $PHPSessionHandling ) {
71 case 'enable':
72 $this->enable = true;
73 $this->warn = false;
74 break;
75
76 case 'warn':
77 $this->enable = true;
78 $this->warn = true;
79 break;
80
81 case 'disable':
82 $this->enable = false;
83 $this->warn = false;
84 break;
85 }
86 }
87
88 /**
89 * Test whether the handler is installed
90 * @return bool
91 */
92 public static function isInstalled() {
93 return (bool)self::$instance;
94 }
95
96 /**
97 * Test whether the handler is installed and enabled
98 * @return bool
99 */
100 public static function isEnabled() {
101 return self::$instance && self::$instance->enable;
102 }
103
104 /**
105 * Install a session handler for the current web request
106 * @param SessionManager $manager
107 */
108 public static function install( SessionManager $manager ) {
109 if ( self::$instance ) {
110 $manager->setupPHPSessionHandler( self::$instance );
111 return;
112 }
113
114 // @codeCoverageIgnoreStart
115 if ( defined( 'MW_NO_SESSION_HANDLER' ) ) {
116 throw new \BadMethodCallException( 'MW_NO_SESSION_HANDLER is defined' );
117 }
118 // @codeCoverageIgnoreEnd
119
120 self::$instance = new self( $manager );
121
122 // Close any auto-started session, before we replace it
123 session_write_close();
124
125 try {
126 \Wikimedia\suppressWarnings();
127
128 // Tell PHP not to mess with cookies itself
129 ini_set( 'session.use_cookies', 0 );
130 ini_set( 'session.use_trans_sid', 0 );
131
132 // T124510: Disable automatic PHP session related cache headers.
133 // MediaWiki adds it's own headers and the default PHP behavior may
134 // set headers such as 'Pragma: no-cache' that cause problems with
135 // some user agents.
136 session_cache_limiter( '' );
137
138 // Also set a sane serialization handler
139 \Wikimedia\PhpSessionSerializer::setSerializeHandler();
140
141 // Register this as the save handler, and register an appropriate
142 // shutdown function.
143 session_set_save_handler( self::$instance, true );
144 } finally {
145 \Wikimedia\restoreWarnings();
146 }
147 }
148
149 /**
150 * Set the manager, store, and logger
151 * @private Use self::install().
152 * @param SessionManager $manager
153 * @param BagOStuff $store
154 * @param LoggerInterface $logger
155 */
156 public function setManager(
157 SessionManager $manager, BagOStuff $store, LoggerInterface $logger
158 ) {
159 if ( $this->manager !== $manager ) {
160 // Close any existing session before we change stores
161 if ( $this->manager ) {
162 session_write_close();
163 }
164 $this->manager = $manager;
165 $this->store = $store;
166 $this->logger = $logger;
167 \Wikimedia\PhpSessionSerializer::setLogger( $this->logger );
168 }
169 }
170
171 /**
172 * Initialize the session (handler)
173 * @private For internal use only
174 * @param string $save_path Path used to store session files (ignored)
175 * @param string $session_name Session name (ignored)
176 * @return true
177 */
178 public function open( $save_path, $session_name ) {
179 if ( self::$instance !== $this ) {
180 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
181 }
182 if ( !$this->enable ) {
183 throw new \BadMethodCallException( 'Attempt to use PHP session management' );
184 }
185 return true;
186 }
187
188 /**
189 * Close the session (handler)
190 * @private For internal use only
191 * @return true
192 */
193 public function close() {
194 if ( self::$instance !== $this ) {
195 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
196 }
197 $this->sessionFieldCache = [];
198 return true;
199 }
200
201 /**
202 * Read session data
203 * @private For internal use only
204 * @param string $id Session id
205 * @return string Session data
206 */
207 public function read( $id ) {
208 if ( self::$instance !== $this ) {
209 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
210 }
211 if ( !$this->enable ) {
212 throw new \BadMethodCallException( 'Attempt to use PHP session management' );
213 }
214
215 $session = $this->manager->getSessionById( $id, false );
216 if ( !$session ) {
217 return '';
218 }
219 $session->persist();
220
221 $data = iterator_to_array( $session );
222 $this->sessionFieldCache[$id] = $data;
223 return (string)\Wikimedia\PhpSessionSerializer::encode( $data );
224 }
225
226 /**
227 * Write session data
228 * @private For internal use only
229 * @param string $id Session id
230 * @param string $dataStr Session data. Not that you should ever call this
231 * directly, but note that this has the same issues with code injection
232 * via user-controlled data as does PHP's unserialize function.
233 * @return bool
234 */
235 public function write( $id, $dataStr ) {
236 if ( self::$instance !== $this ) {
237 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
238 }
239 if ( !$this->enable ) {
240 throw new \BadMethodCallException( 'Attempt to use PHP session management' );
241 }
242
243 $session = $this->manager->getSessionById( $id, true );
244 if ( !$session ) {
245 // This can happen under normal circumstances, if the session exists but is
246 // invalid. Let's emit a log warning instead of a PHP warning.
247 $this->logger->warning(
248 __METHOD__ . ': Session "{session}" cannot be loaded, skipping write.',
249 [
250 'session' => $id,
251 ] );
252 return true;
253 }
254
255 // First, decode the string PHP handed us
256 $data = \Wikimedia\PhpSessionSerializer::decode( $dataStr );
257 if ( $data === null ) {
258 // @codeCoverageIgnoreStart
259 return false;
260 // @codeCoverageIgnoreEnd
261 }
262
263 // Now merge the data into the Session object.
264 $changed = false;
265 $cache = $this->sessionFieldCache[$id] ?? [];
266 foreach ( $data as $key => $value ) {
267 if ( !array_key_exists( $key, $cache ) ) {
268 if ( $session->exists( $key ) ) {
269 // New in both, so ignore and log
270 $this->logger->warning(
271 __METHOD__ . ": Key \"$key\" added in both Session and \$_SESSION!"
272 );
273 } else {
274 // New in $_SESSION, keep it
275 $session->set( $key, $value );
276 $changed = true;
277 }
278 } elseif ( $cache[$key] === $value ) {
279 // Unchanged in $_SESSION, so ignore it
280 } elseif ( !$session->exists( $key ) ) {
281 // Deleted in Session, keep but log
282 $this->logger->warning(
283 __METHOD__ . ": Key \"$key\" deleted in Session and changed in \$_SESSION!"
284 );
285 $session->set( $key, $value );
286 $changed = true;
287 } elseif ( $cache[$key] === $session->get( $key ) ) {
288 // Unchanged in Session, so keep it
289 $session->set( $key, $value );
290 $changed = true;
291 } else {
292 // Changed in both, so ignore and log
293 $this->logger->warning(
294 __METHOD__ . ": Key \"$key\" changed in both Session and \$_SESSION!"
295 );
296 }
297 }
298 // Anything deleted in $_SESSION and unchanged in Session should be deleted too
299 // (but not if $_SESSION can't represent it at all)
300 \Wikimedia\PhpSessionSerializer::setLogger( new \Psr\Log\NullLogger() );
301 foreach ( $cache as $key => $value ) {
302 if ( !array_key_exists( $key, $data ) && $session->exists( $key ) &&
303 \Wikimedia\PhpSessionSerializer::encode( [ $key => true ] )
304 ) {
305 if ( $cache[$key] === $session->get( $key ) ) {
306 // Unchanged in Session, delete it
307 $session->remove( $key );
308 $changed = true;
309 } else {
310 // Changed in Session, ignore deletion and log
311 $this->logger->warning(
312 __METHOD__ . ": Key \"$key\" changed in Session and deleted in \$_SESSION!"
313 );
314 }
315 }
316 }
317 \Wikimedia\PhpSessionSerializer::setLogger( $this->logger );
318
319 // Save and update cache if anything changed
320 if ( $changed ) {
321 if ( $this->warn ) {
322 wfDeprecated( '$_SESSION', '1.27' );
323 $this->logger->warning( 'Something wrote to $_SESSION!' );
324 }
325
326 $session->save();
327 $this->sessionFieldCache[$id] = iterator_to_array( $session );
328 }
329
330 $session->persist();
331
332 return true;
333 }
334
335 /**
336 * Destroy a session
337 * @private For internal use only
338 * @param string $id Session id
339 * @return true
340 */
341 public function destroy( $id ) {
342 if ( self::$instance !== $this ) {
343 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
344 }
345 if ( !$this->enable ) {
346 throw new \BadMethodCallException( 'Attempt to use PHP session management' );
347 }
348 $session = $this->manager->getSessionById( $id, false );
349 if ( $session ) {
350 $session->clear();
351 }
352 return true;
353 }
354
355 /**
356 * Execute garbage collection.
357 * @private For internal use only
358 * @param int $maxlifetime Maximum session life time (ignored)
359 * @return true
360 * @codeCoverageIgnore See T135576
361 */
362 public function gc( $maxlifetime ) {
363 if ( self::$instance !== $this ) {
364 throw new \UnexpectedValueException( __METHOD__ . ': Wrong instance called!' );
365 }
366 $before = date( 'YmdHis', time() );
367 $this->store->deleteObjectsExpiringBefore( $before );
368 return true;
369 }
370 }