138 lines
4.0 KiB
PHP
138 lines
4.0 KiB
PHP
<?php
|
|
declare(strict_types=1);
|
|
|
|
function isLocalDevelopmentRequest(): bool
|
|
{
|
|
$host = strtolower((string) ($_SERVER['HTTP_HOST'] ?? ''));
|
|
$host = preg_replace('/:\d+$/', '', $host) ?? $host;
|
|
$remoteAddr = strtolower((string) ($_SERVER['REMOTE_ADDR'] ?? ''));
|
|
|
|
$localHosts = ['localhost', '127.0.0.1', '::1'];
|
|
$localAddresses = ['127.0.0.1', '::1', ''];
|
|
|
|
return in_array($host, $localHosts, true) && in_array($remoteAddr, $localAddresses, true);
|
|
}
|
|
|
|
function applyLocalDevLoginBypass(): void
|
|
{
|
|
if (!isLocalDevelopmentRequest()) {
|
|
return;
|
|
}
|
|
|
|
if ((string) ($_GET['dev_logout'] ?? '') === '1') {
|
|
unset($_SESSION['user_id'], $_SESSION['username'], $_SESSION['role']);
|
|
return;
|
|
}
|
|
|
|
if (isset($_SESSION['user_id']) || (string) ($_GET['dev_login'] ?? '') !== '1') {
|
|
return;
|
|
}
|
|
|
|
try {
|
|
$cfg = require __DIR__ . '/../config/database.php';
|
|
$pdo = new PDO(
|
|
sprintf('mysql:host=%s;dbname=%s;charset=%s', $cfg['host'], $cfg['dbname'], $cfg['charset'] ?? 'utf8mb4'),
|
|
$cfg['user'],
|
|
$cfg['pass'],
|
|
[PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC]
|
|
);
|
|
|
|
$stmt = $pdo->query("
|
|
SELECT `id`, `username`, `role`
|
|
FROM `app_users`
|
|
WHERE `is_active` = 1
|
|
AND `role` IN ('master', 'admin')
|
|
ORDER BY CASE WHEN `role` = 'master' THEN 0 ELSE 1 END, `id` ASC
|
|
LIMIT 1
|
|
");
|
|
$user = $stmt->fetch();
|
|
|
|
if (is_array($user)) {
|
|
$_SESSION['user_id'] = (int) $user['id'];
|
|
$_SESSION['username'] = (string) $user['username'];
|
|
$_SESSION['role'] = (string) $user['role'];
|
|
}
|
|
} catch (Throwable $e) {
|
|
return;
|
|
}
|
|
}
|
|
|
|
function currentUserRole(): string
|
|
{
|
|
return trim((string) ($_SESSION['role'] ?? ''));
|
|
}
|
|
|
|
function isMasterRole(?string $role): bool
|
|
{
|
|
return trim((string) $role) === 'master';
|
|
}
|
|
|
|
function isAdminLikeRole(?string $role): bool
|
|
{
|
|
$normalizedRole = trim((string) $role);
|
|
|
|
return $normalizedRole === 'admin' || $normalizedRole === 'master';
|
|
}
|
|
|
|
function currentUserIsAdminLike(): bool
|
|
{
|
|
return isAdminLikeRole(currentUserRole());
|
|
}
|
|
|
|
function publicAccessAllowlist(): array
|
|
{
|
|
return [
|
|
'login.php',
|
|
'register.php',
|
|
'logout.php',
|
|
];
|
|
}
|
|
|
|
function currentPublicPageKey(): string
|
|
{
|
|
$scriptName = str_replace('\\', '/', (string) ($_SERVER['SCRIPT_NAME'] ?? ''));
|
|
$scriptName = ltrim($scriptName, '/');
|
|
|
|
if ($scriptName === '') {
|
|
return '';
|
|
}
|
|
|
|
$publicMarker = 'public/';
|
|
$publicPosition = strpos($scriptName, $publicMarker);
|
|
if ($publicPosition !== false) {
|
|
return substr($scriptName, $publicPosition + strlen($publicMarker));
|
|
}
|
|
|
|
return $scriptName;
|
|
}
|
|
|
|
function manageablePublicPages(): array
|
|
{
|
|
return [
|
|
'index.php' => 'Startseite',
|
|
'settings.php' => 'Einstellungen',
|
|
'my_favorites.php' => 'Favoriten',
|
|
'moonphase.php' => 'Mondphase',
|
|
'planetensichtbarkeit.php' => 'Planetensichtbarkeit',
|
|
'comets.php' => 'Kometen',
|
|
'astronomical_conversions.php' => 'Astronomical Conversions',
|
|
'tcrb_lightcurve.php' => 'T CrB Lichtkurve',
|
|
'solarsystem.php' => 'Sonnensystem',
|
|
'mars.php' => 'Mars',
|
|
'jupitersystem.php' => 'Jupitersystem',
|
|
'tagbogen.php' => 'Tagbogen',
|
|
'sternenhimmel.php' => 'Sternenhimmel',
|
|
'meteorshowers.php' => 'Meteorströme',
|
|
'geocron/index.php' => 'Geocron',
|
|
'geocron3d.php' => 'Geocron 3D',
|
|
'geocron3d_C.php' => 'Geocron 3D Cesium',
|
|
'mondfinsternis.php' => 'Mondfinsternis',
|
|
'sonnenfinsternis.php' => 'Sonnenfinsternis',
|
|
'bedeckung.php' => 'Bedeckungsphänomene',
|
|
'sternbedeckungen.php' => 'Mond-Stern-Bedeckungen',
|
|
'monatsvorhersage.php' => 'Monatsvorhersage',
|
|
'wochenvorhersage.php' => 'Wochenvorhersage',
|
|
'satellitenhimmel.php' => 'Satellitenhimmel',
|
|
];
|
|
}
|