summaryrefslogtreecommitdiff
path: root/core/session.php
blob: aa4b251647c7d7680b5e80bb48db78fe511ad807 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
<?php

namespace Core;

class Session
{
    const SESSION_LIFETIME = 86400; // 1 day

    public function open($base_path = '/', $save_path = '')
    {
        if ($save_path !== '') session_save_path($save_path);

        // HttpOnly and secure flags for session cookie
        session_set_cookie_params(
            self::SESSION_LIFETIME,
            $base_path ?: '/',
            null,
            isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] === 'on',
            true
        );

        // Avoid session id in the URL
        ini_set('session.use_only_cookies', true);

        // Ensure session ID integrity
        ini_set('session.entropy_file', '/dev/urandom');
        ini_set('session.entropy_length', '32');
        ini_set('session.hash_bits_per_character', 6);

        // Custom session name
        session_name('__S');

        session_start();

        // Regenerate the session id to avoid session fixation issue
        if (empty($_SESSION['__validated'])) {
            session_regenerate_id(true);
            $_SESSION['__validated'] = 1;
        }
    }

    public function close()
    {
        session_destroy();
    }

    public function flash($message)
    {
        $_SESSION['flash_message'] = $message;
    }

    public function flashError($message)
    {
        $_SESSION['flash_error_message'] = $message;
    }
}