/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
constchar **includes = (constchar **) conf->includes->elts; constchar **excludes = (constchar **) conf->excludes->elts; int included = 1; /* defaults to included */ int i;
if (conf->includes->nelts) {
included = 0; for (i = 0; !included && i < conf->includes->nelts; i++) { constchar *include = includes[i]; if (strncmp(r->uri, include, strlen(include)) == 0) {
included = 1;
}
}
}
if (conf->excludes->nelts) { for (i = 0; included && i < conf->excludes->nelts; i++) { constchar *exclude = excludes[i]; if (strncmp(r->uri, exclude, strlen(exclude)) == 0) {
included = 0;
}
}
}
/* is the session enabled? */ if (!dconf || !dconf->enabled) { return APR_SUCCESS;
}
/* should the session be loaded at all? */ if (!session_included(r, dconf)) {
ap_log_rerror(APLOG_MARK, APLOG_DEBUG, 0, r, APLOGNO(01814) "excluded by configuration for: %s", r->uri); return APR_SUCCESS;
}
/* load the session from the session hook */
rv = ap_run_session_load(r, &zz); if (DECLINED == rv) {
ap_log_rerror(APLOG_MARK, APLOG_WARNING, 0, r, APLOGNO(01815) "session is enabled but no session modules have been configured, " "session not loaded: %s", r->uri); return APR_EGENERAL;
} elseif (OK != rv) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, rv, r, APLOGNO(01816) "error while loading the session, " "session not loaded: %s", r->uri); return rv;
}
/* found a session that hasn't expired? */
now = apr_time_now();
if (zz) { /* load the session attributes */
rv = ap_run_session_decode(r, zz);
/* having a session we cannot decode is just as good as having
none at all */ if (OK != rv) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, rv, r, APLOGNO(01817) "error while decoding the session, " "session not loaded: %s", r->uri);
zz = NULL;
}
/* invalidate session if session is expired */ if (zz && zz->expiry && zz->expiry < now) {
ap_log_rerror(APLOG_MARK, APLOG_TRACE2, 0, r, "session is expired");
zz = NULL;
}
}
/* no luck, create a blank session */ if (!zz) {
zz = (session_rec *) apr_pcalloc(r->pool, sizeof(session_rec));
zz->pool = r->pool;
zz->entries = apr_table_make(zz->pool, 10);
}
/* make sure the expiry and maxage are set, if present */ if (dconf->maxage) { if (!zz->expiry) {
zz->expiry = now + dconf->maxage * APR_USEC_PER_SEC;
}
zz->maxage = dconf->maxage;
}
/* sanity checks, should we try save at all? */ if (z->written) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, 0, r, APLOGNO(01818) "attempt made to save the session twice, " "session not saved: %s", r->uri); return APR_EGENERAL;
} if (z->expiry && z->expiry < now) {
ap_log_rerror(APLOG_MARK, APLOG_WARNING, 0, r, APLOGNO(01819) "attempt made to save a session when the session had already expired, " "session not saved: %s", r->uri); return APR_EGENERAL;
}
/* reset the expiry back to maxage, if the expiry is present */ if (dconf->maxage) {
z->expiry = now + dconf->maxage * APR_USEC_PER_SEC;
z->maxage = dconf->maxage;
}
/* reset the expiry before saving if present */ if (z->dirty && z->maxage) {
z->expiry = now + z->maxage * APR_USEC_PER_SEC;
}
/* don't save if the only change is the expiry by a small amount */ if (!z->dirty && dconf->expiry_update_time
&& (z->expiry - initialExpiry < dconf->expiry_update_time)) { return APR_SUCCESS;
}
/* also don't save sessions that didn't change at all */ if (!z->dirty && !z->maxage) { return APR_SUCCESS;
}
/* encode the session */
rv = ap_run_session_encode(r, z); if (OK != rv) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, rv, r, APLOGNO(01820) "error while encoding the session, " "session not saved: %s", r->uri); return rv;
}
/* try the save */
rv = ap_run_session_save(r, z); if (DECLINED == rv) {
ap_log_rerror(APLOG_MARK, APLOG_WARNING, 0, r, APLOGNO(01821) "session is enabled but no session modules have been configured, " "session not saved: %s", r->uri); return APR_EGENERAL;
} elseif (OK != rv) {
ap_log_rerror(APLOG_MARK, APLOG_ERR, rv, r, APLOGNO(01822) "error while saving the session, " "session not saved: %s", r->uri); return rv;
} else {
z->written = 1;
}
}
/* save all the sessions in all the requests */
request_rec *r = f->r->main; if (!r) {
r = f->r;
} while (r) {
session_rec *z = NULL;
session_dir_conf *conf = ap_get_module_config(r->per_dir_config,
&session_module);
/* load the session, or create one if necessary */ /* when unset or on error, z will be NULL */
ap_session_load(r, &z); if (!z || z->written) {
r = r->next; continue;
}
/* if a header was specified, insert the new values from the header */ if (conf->header_set) { constchar *override = apr_table_get(r->err_headers_out, conf->header); if (!override) {
override = apr_table_get(r->headers_out, conf->header);
} if (override) {
apr_table_unset(r->err_headers_out, conf->header);
apr_table_unset(r->headers_out, conf->header);
z->encoded = override;
z->dirty = 1;
session_identity_decode(r, z);
}
}
/* save away the session, and we're done */ /* when unset or on error, we've complained to the log */
ap_session_save(r, z);
r = r->next;
}
/* remove ourselves from the filter chain */
ap_remove_output_filter(f);
/* send the data up the stack */ return ap_pass_brigade(f->next, in);
/* if an error occurs or no session has been configured, we ignore *thebrokensessionandallowittoberecreatedfromscratchonsave *ifnecessary.
*/
ap_session_load(r, &z);
if (conf->env) { if (z) {
session_identity_encode(r, z); if (z->encoded) {
apr_table_set(r->subprocess_env, HTTP_SESSION, z->encoded);
z->encoded = NULL;
}
}
apr_table_unset(r->headers_in, "Session");
}
conf->expiry_update_time = atoi(arg); if (conf->expiry_update_time < 0) { return"SessionExpiryUpdateInterval must be zero (disable) or a positive value";
}
conf->expiry_update_time = apr_time_from_sec(conf->expiry_update_time);
conf->expiry_update_set = 1;
return NULL;
}
staticconst command_rec session_cmds[] =
{
AP_INIT_FLAG("Session", set_session_enable, NULL, RSRC_CONF|OR_AUTHCFG, "on if a session should be maintained for these URLs"),
AP_INIT_TAKE1("SessionMaxAge", set_session_maxage, NULL, RSRC_CONF|OR_AUTHCFG, "length of time for which a session should be valid. Zero to disable"),
AP_INIT_TAKE1("SessionHeader", set_session_header, NULL, RSRC_CONF|OR_AUTHCFG, "output header, if present, whose contents will be injected into the session."),
AP_INIT_FLAG("SessionEnv", set_session_env, NULL, RSRC_CONF|OR_AUTHCFG, "on if a session should be written to the CGI environment. Defaults to off"),
AP_INIT_TAKE1("SessionInclude", add_session_include, NULL, RSRC_CONF|OR_AUTHCFG, "URL prefixes to include in the session. Defaults to all URLs"),
AP_INIT_TAKE1("SessionExclude", add_session_exclude, NULL, RSRC_CONF|OR_AUTHCFG, "URL prefixes to exclude from the session. Defaults to no URLs"),
AP_INIT_TAKE1("SessionExpiryUpdateInterval", set_session_expiry_update, NULL, RSRC_CONF|OR_AUTHCFG, "time interval for which a session's expiry time may change " "without having to be rewritten. Zero to disable"),
{NULL}
};
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.