From: "Daniel P. Zepeda" Date: 2001-12-13T13:05:14+09:00 Subject: [ruby-talk:28383] Fixes/Enhancements to CGI::Session Hi, I submitted these to the ruby-bugs database a while back (id:incoming/212) . I haven't seen any reaction there, so I'm going to post them here, I'm sorta anxious to see what people have to say about it. I did a quick search on the mailing list ( I haven't been subscribing for long, I've only been using Ruby for less than a month ) and didn't find anything *directly* related... So here it goes: I didn't know whether to provide a diff from session.rb (what version?) or what so here this is just to get the ball rolling. Let me know what is the preferred way of submitting stuff like this. =begin = Introduction This CGI::Session class extension provides * A way to determine if session to be restored has successfully opened the underlying database. It implements the CGI::Session#success? method * Disables sending the session keys via hidden fields when a cookie expiry is set, because the keys in the hidden field defeated the cookies timeout, preventing session time out. * Compensates for when the session_id gets stored in a multipart-form element. * Enables setting the 'expire' value of the cookie that forwards the session information = Added methods The single New instance method is --- CGI::Session#success? Returns true or false depending on whether the underlying database actually restored the connection to the data. =end require 'cgi/session' class CGI class Session def initialize(request, option={}) $stderr.puts "begin" session_key = option['session_key'] || '_session_id' id, = option['session_id'] $stderr.print "option attempt:id: ", id, "\n" unless id $stderr.puts "Continue 1 ( before create new id)" if option['new_session'] id = Session::create_new_id $stderr.print "create_new_id:id: ", id, "\n" end $stderr.puts "Continue 2 ( after create new id)" end unless id $stderr.puts "Continue 3 ( before cookie attempt )" id, = request.cookies[session_key] $stderr.print "cookie attempt:id:" , id, "\n" unless id $stderr.puts "Continue 4 ( before hidden tag attempt )" id, = request[session_key] $stderr.print "hidden tag attempt:id " , id, "\n" end # Check for multipart-form element if ( id.type.to_s == 'Tempfile' ) then $stderr.puts "Continue 5 ( multipart attempt )" id = id.read $stderr.print "multipart form attempt:id:" , id, "\n" end unless id $stderr.puts "bomb" if option.key?('new_session') and not option['new_session'] raise ArgumentError, "session_key `%s' should be supplied"%session_key end $stderr.puts "created_new_id 2" id = Session::create_new_id end end $stderr.puts "End of id hunt" @session_id = id dbman = option['database_manager'] || FileStore @dbman = dbman::new(self, option) request.instance_eval do unless ( option['expires'] ) then @output_hidden = {session_key => id} @output_cookies = [ Cookie::new("name" => session_key, "value" => id, "path" => if option['session_path'] then option['session_path'] elsif ENV["SCRIPT_NAME"] then File::dirname(ENV["SCRIPT_NAME"]) else "" end ) ] else @output_cookies = [ Cookie::new("name" => session_key, "value" => id, "expires" => option['expires'], "path" => if option['session_path'] then option['session_path'] elsif ENV["SCRIPT_NAME"] then File::dirname(ENV["SCRIPT_NAME"]) else "" end ) ] end end ObjectSpace::define_finalizer(self, Session::callback(@dbman)) end def success? @dbman.success? end class FileStore def initialize(session, option={}) dir = option['tmpdir'] || ENV['TMP'] || '/tmp' prefix = option['prefix'] || '' id = session.session_id unless check_id(id) raise ArgumentError, "session_id `%s' is invalid" % id end path = dir+"/"+prefix+id path.untaint unless File::exist? path @hash = {} end begin return @f = open(path, "w+" ) if ( option['new_session'] ) @f = open(path, "r+") rescue Errno::ENOENT @f = nil end end def success? if( @f ) then true else false end end end class MemoryStore def success? true end end end # class Session end # class CGI -- Daniel P. Zepeda daniel@zepeda-zone.net