Deployed 2063d78 to 5.4 with MkDocs 1.1.2 and mike 0.5.5
[GitHub/WoltLab/woltlab.github.io.git] / 5.4 / migration / wsc53 / session / index.html
1
2 <!doctype html>
3 <html lang="en" class="no-js">
4 <head>
5
6 <meta charset="utf-8">
7 <meta name="viewport" content="width=device-width,initial-scale=1">
8
9
10
11
12 <link rel="shortcut icon" href="../../../assets/default.favicon.ico">
13 <meta name="generator" content="mkdocs-1.1.2, mkdocs-material-7.0.5">
14
15
16
17 <title>Session Handling and Authentication - WoltLab Suite Documentation</title>
18
19
20
21 <link rel="stylesheet" href="../../../assets/stylesheets/main.77f3fd56.min.css">
22
23
24 <link rel="stylesheet" href="../../../assets/stylesheets/palette.7fa14f5b.min.css">
25
26
27
28 <meta name="theme-color" content="#009485">
29
30
31
32
33
34
35
36
37
38 <link rel="stylesheet" href="../../../stylesheets/extra.css">
39
40
41
42
43
44 </head>
45
46
47
48
49
50
51
52 <body dir="ltr" data-md-color-scheme="" data-md-color-primary="teal" data-md-color-accent="">
53
54
55
56 <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
57 <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
58 <label class="md-overlay" for="__drawer"></label>
59 <div data-md-component="skip">
60
61
62 <a href="#migrating-from-wsc-53-session-handling-and-authentication" class="md-skip">
63 Skip to content
64 </a>
65
66 </div>
67 <div data-md-component="announce">
68
69 <aside class="md-announce">
70 <div class="md-announce__inner md-grid md-typeset">
71
72 <a href="https://www.woltlab.com">Back to <strong>woltlab.com</strong></a>
73
74 </div>
75 </aside>
76
77 </div>
78
79
80
81 <header class="md-header" data-md-component="header">
82 <nav class="md-header__inner md-grid" aria-label="Header">
83 <a href="../../.." title="WoltLab Suite Documentation" class="md-header__button md-logo" aria-label="WoltLab Suite Documentation">
84
85 <img src="../../../assets/logo.png" alt="logo">
86
87 </a>
88 <label class="md-header__button md-icon" for="__drawer">
89 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3V6m0 5h18v2H3v-2m0 5h18v2H3v-2z"/></svg>
90 </label>
91 <div class="md-header__title" data-md-component="header-title">
92 <div class="md-header__ellipsis">
93 <div class="md-header__topic">
94 <span class="md-ellipsis">
95 WoltLab Suite Documentation
96 </span>
97 </div>
98 <div class="md-header__topic" data-md-component="header-topic">
99 <span class="md-ellipsis">
100
101 Session Handling and Authentication
102
103 </span>
104 </div>
105 </div>
106 </div>
107 <div class="md-header__options">
108
109 </div>
110
111
112 <div class="md-header__source">
113
114 <a href="https://github.com/WoltLab/docs.woltlab.com/" title="Go to repository" class="md-source" data-md-component="source">
115 <div class="md-source__icon md-icon">
116
117 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><path d="M439.55 236.05L244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
118 </div>
119 <div class="md-source__repository">
120 GitHub
121 </div>
122 </a>
123 </div>
124
125 </nav>
126 </header>
127
128 <div class="md-container" data-md-component="container">
129
130
131
132
133 <main class="md-main" data-md-component="main">
134 <div class="md-main__inner md-grid">
135
136
137
138 <div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
139 <div class="md-sidebar__scrollwrap">
140 <div class="md-sidebar__inner">
141
142
143
144
145
146 <nav class="md-nav md-nav--primary" aria-label="Navigation" data-md-level="0">
147 <label class="md-nav__title" for="__drawer">
148 <a href="../../.." title="WoltLab Suite Documentation" class="md-nav__button md-logo" aria-label="WoltLab Suite Documentation">
149
150 <img src="../../../assets/logo.png" alt="logo">
151
152 </a>
153 WoltLab Suite Documentation
154 </label>
155
156 <div class="md-nav__source">
157
158 <a href="https://github.com/WoltLab/docs.woltlab.com/" title="Go to repository" class="md-source" data-md-component="source">
159 <div class="md-source__icon md-icon">
160
161 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><path d="M439.55 236.05L244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
162 </div>
163 <div class="md-source__repository">
164 GitHub
165 </div>
166 </a>
167 </div>
168
169 <ul class="md-nav__list" data-md-scrollfix>
170
171
172
173
174
175
176
177
178 <li class="md-nav__item">
179 <a href="../../../getting-started/" class="md-nav__link">
180 Getting Started
181 </a>
182 </li>
183
184
185
186
187
188
189
190
191
192
193
194 <li class="md-nav__item md-nav__item--nested">
195
196
197 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2" type="checkbox" id="__nav_2" >
198
199 <label class="md-nav__link" for="__nav_2">
200 PHP API
201 <span class="md-nav__icon md-icon"></span>
202 </label>
203 <nav class="md-nav" aria-label="PHP API" data-md-level="1">
204 <label class="md-nav__title" for="__nav_2">
205 <span class="md-nav__icon md-icon"></span>
206 PHP API
207 </label>
208 <ul class="md-nav__list" data-md-scrollfix>
209
210
211
212
213
214 <li class="md-nav__item">
215 <a href="../../../php/pages/" class="md-nav__link">
216 Pages
217 </a>
218 </li>
219
220
221
222
223
224
225
226 <li class="md-nav__item">
227 <a href="../../../php/database-objects/" class="md-nav__link">
228 Database Objects
229 </a>
230 </li>
231
232
233
234
235
236
237
238 <li class="md-nav__item">
239 <a href="../../../php/database-access/" class="md-nav__link">
240 Database Access
241 </a>
242 </li>
243
244
245
246
247
248
249
250 <li class="md-nav__item">
251 <a href="../../../php/exceptions/" class="md-nav__link">
252 Exceptions
253 </a>
254 </li>
255
256
257
258
259
260
261
262
263 <li class="md-nav__item md-nav__item--nested">
264
265
266 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2_5" type="checkbox" id="__nav_2_5" >
267
268 <label class="md-nav__link" for="__nav_2_5">
269 API
270 <span class="md-nav__icon md-icon"></span>
271 </label>
272 <nav class="md-nav" aria-label="API" data-md-level="2">
273 <label class="md-nav__title" for="__nav_2_5">
274 <span class="md-nav__icon md-icon"></span>
275 API
276 </label>
277 <ul class="md-nav__list" data-md-scrollfix>
278
279
280
281
282
283 <li class="md-nav__item">
284 <a href="../../../php/api/caches/" class="md-nav__link">
285 Caches
286 </a>
287 </li>
288
289
290
291
292
293
294
295 <li class="md-nav__item">
296 <a href="../../../php/api/comments/" class="md-nav__link">
297 Comments
298 </a>
299 </li>
300
301
302
303
304
305
306
307 <li class="md-nav__item">
308 <a href="../../../php/api/cronjobs/" class="md-nav__link">
309 Cronjobs
310 </a>
311 </li>
312
313
314
315
316
317
318
319 <li class="md-nav__item">
320 <a href="../../../php/api/events/" class="md-nav__link">
321 Events
322 </a>
323 </li>
324
325
326
327
328
329
330
331
332 <li class="md-nav__item md-nav__item--nested">
333
334
335 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2_5_5" type="checkbox" id="__nav_2_5_5" >
336
337 <label class="md-nav__link" for="__nav_2_5_5">
338 Form Builder
339 <span class="md-nav__icon md-icon"></span>
340 </label>
341 <nav class="md-nav" aria-label="Form Builder" data-md-level="3">
342 <label class="md-nav__title" for="__nav_2_5_5">
343 <span class="md-nav__icon md-icon"></span>
344 Form Builder
345 </label>
346 <ul class="md-nav__list" data-md-scrollfix>
347
348
349
350
351
352 <li class="md-nav__item">
353 <a href="../../../php/api/form_builder/overview/" class="md-nav__link">
354 Overview
355 </a>
356 </li>
357
358
359
360
361
362
363
364 <li class="md-nav__item">
365 <a href="../../../php/api/form_builder/structure/" class="md-nav__link">
366 Structure
367 </a>
368 </li>
369
370
371
372
373
374
375
376 <li class="md-nav__item">
377 <a href="../../../php/api/form_builder/form_fields/" class="md-nav__link">
378 Fields
379 </a>
380 </li>
381
382
383
384
385
386
387
388 <li class="md-nav__item">
389 <a href="../../../php/api/form_builder/validation_data/" class="md-nav__link">
390 Validation and Data
391 </a>
392 </li>
393
394
395
396
397
398
399
400 <li class="md-nav__item">
401 <a href="../../../php/api/form_builder/dependencies/" class="md-nav__link">
402 Dependencies
403 </a>
404 </li>
405
406
407
408 </ul>
409 </nav>
410 </li>
411
412
413
414
415
416
417
418 <li class="md-nav__item">
419 <a href="../../../php/api/package_installation_plugins/" class="md-nav__link">
420 Package Installation Plugins
421 </a>
422 </li>
423
424
425
426
427
428
429
430 <li class="md-nav__item">
431 <a href="../../../php/api/user_activity_points/" class="md-nav__link">
432 User Activity Points
433 </a>
434 </li>
435
436
437
438
439
440
441
442 <li class="md-nav__item">
443 <a href="../../../php/api/user_notifications/" class="md-nav__link">
444 User Notifications
445 </a>
446 </li>
447
448
449
450
451
452
453
454 <li class="md-nav__item">
455 <a href="../../../php/api/sitemaps/" class="md-nav__link">
456 Sitemaps
457 </a>
458 </li>
459
460
461
462 </ul>
463 </nav>
464 </li>
465
466
467
468
469
470
471
472 <li class="md-nav__item">
473 <a href="../../../php/code-style/" class="md-nav__link">
474 Code Style
475 </a>
476 </li>
477
478
479
480
481
482
483
484 <li class="md-nav__item">
485 <a href="../../../php/apps/" class="md-nav__link">
486 Apps
487 </a>
488 </li>
489
490
491
492
493
494
495
496 <li class="md-nav__item">
497 <a href="../../../php/gdpr/" class="md-nav__link">
498 GDPR
499 </a>
500 </li>
501
502
503
504 </ul>
505 </nav>
506 </li>
507
508
509
510
511
512
513
514
515
516
517
518 <li class="md-nav__item md-nav__item--nested">
519
520
521 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_3" type="checkbox" id="__nav_3" >
522
523 <label class="md-nav__link" for="__nav_3">
524 Languages, Templates & CSS
525 <span class="md-nav__icon md-icon"></span>
526 </label>
527 <nav class="md-nav" aria-label="Languages, Templates & CSS" data-md-level="1">
528 <label class="md-nav__title" for="__nav_3">
529 <span class="md-nav__icon md-icon"></span>
530 Languages, Templates & CSS
531 </label>
532 <ul class="md-nav__list" data-md-scrollfix>
533
534
535
536
537
538 <li class="md-nav__item">
539 <a href="../../../view/languages/" class="md-nav__link">
540 Languages
541 </a>
542 </li>
543
544
545
546
547
548
549
550 <li class="md-nav__item">
551 <a href="../../../view/templates/" class="md-nav__link">
552 Templates
553 </a>
554 </li>
555
556
557
558
559
560
561
562 <li class="md-nav__item">
563 <a href="../../../view/css/" class="md-nav__link">
564 CSS
565 </a>
566 </li>
567
568
569
570 </ul>
571 </nav>
572 </li>
573
574
575
576
577
578
579
580
581
582
583
584 <li class="md-nav__item md-nav__item--nested">
585
586
587 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_4" type="checkbox" id="__nav_4" >
588
589 <label class="md-nav__link" for="__nav_4">
590 JavaScript API
591 <span class="md-nav__icon md-icon"></span>
592 </label>
593 <nav class="md-nav" aria-label="JavaScript API" data-md-level="1">
594 <label class="md-nav__title" for="__nav_4">
595 <span class="md-nav__icon md-icon"></span>
596 JavaScript API
597 </label>
598 <ul class="md-nav__list" data-md-scrollfix>
599
600
601
602
603
604 <li class="md-nav__item">
605 <a href="../../../javascript/general-usage/" class="md-nav__link">
606 General Usage
607 </a>
608 </li>
609
610
611
612
613
614
615
616
617 <li class="md-nav__item md-nav__item--nested">
618
619
620 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_4_2" type="checkbox" id="__nav_4_2" >
621
622 <label class="md-nav__link" for="__nav_4_2">
623 New API
624 <span class="md-nav__icon md-icon"></span>
625 </label>
626 <nav class="md-nav" aria-label="New API" data-md-level="2">
627 <label class="md-nav__title" for="__nav_4_2">
628 <span class="md-nav__icon md-icon"></span>
629 New API
630 </label>
631 <ul class="md-nav__list" data-md-scrollfix>
632
633
634
635
636
637 <li class="md-nav__item">
638 <a href="../../../javascript/new-api_writing-a-module/" class="md-nav__link">
639 Writing a module
640 </a>
641 </li>
642
643
644
645
646
647
648
649 <li class="md-nav__item">
650 <a href="../../../javascript/new-api_data-structures/" class="md-nav__link">
651 Data Structures
652 </a>
653 </li>
654
655
656
657
658
659
660
661 <li class="md-nav__item">
662 <a href="../../../javascript/new-api_core/" class="md-nav__link">
663 Core Functions
664 </a>
665 </li>
666
667
668
669
670
671
672
673 <li class="md-nav__item">
674 <a href="../../../javascript/new-api_dom/" class="md-nav__link">
675 DOM
676 </a>
677 </li>
678
679
680
681
682
683
684
685 <li class="md-nav__item">
686 <a href="../../../javascript/new-api_events/" class="md-nav__link">
687 Event Handling
688 </a>
689 </li>
690
691
692
693
694
695
696
697 <li class="md-nav__item">
698 <a href="../../../javascript/new-api_ajax/" class="md-nav__link">
699 Ajax
700 </a>
701 </li>
702
703
704
705
706
707
708
709 <li class="md-nav__item">
710 <a href="../../../javascript/new-api_dialogs/" class="md-nav__link">
711 Dialogs
712 </a>
713 </li>
714
715
716
717
718
719
720
721 <li class="md-nav__item">
722 <a href="../../../javascript/new-api_browser/" class="md-nav__link">
723 Browser and Screen Sizes
724 </a>
725 </li>
726
727
728
729
730
731
732
733 <li class="md-nav__item">
734 <a href="../../../javascript/new-api_ui/" class="md-nav__link">
735 User Interface
736 </a>
737 </li>
738
739
740
741 </ul>
742 </nav>
743 </li>
744
745
746
747
748
749
750
751 <li class="md-nav__item">
752 <a href="../../../javascript/legacy-api/" class="md-nav__link">
753 Legacy API
754 </a>
755 </li>
756
757
758
759
760
761
762
763 <li class="md-nav__item">
764 <a href="../../../javascript/helper-functions/" class="md-nav__link">
765 Helper Functions
766 </a>
767 </li>
768
769
770
771
772
773
774
775 <li class="md-nav__item">
776 <a href="../../../javascript/code-snippets/" class="md-nav__link">
777 Code Snippets
778 </a>
779 </li>
780
781
782
783 </ul>
784 </nav>
785 </li>
786
787
788
789
790
791
792
793
794
795
796
797 <li class="md-nav__item md-nav__item--nested">
798
799
800 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_5" type="checkbox" id="__nav_5" >
801
802 <label class="md-nav__link" for="__nav_5">
803 Package Components
804 <span class="md-nav__icon md-icon"></span>
805 </label>
806 <nav class="md-nav" aria-label="Package Components" data-md-level="1">
807 <label class="md-nav__title" for="__nav_5">
808 <span class="md-nav__icon md-icon"></span>
809 Package Components
810 </label>
811 <ul class="md-nav__list" data-md-scrollfix>
812
813
814
815
816
817 <li class="md-nav__item">
818 <a href="../../../package/package-xml/" class="md-nav__link">
819 package.xml
820 </a>
821 </li>
822
823
824
825
826
827
828
829
830 <li class="md-nav__item md-nav__item--nested">
831
832
833 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_5_2" type="checkbox" id="__nav_5_2" >
834
835 <label class="md-nav__link" for="__nav_5_2">
836 PIPs
837 <span class="md-nav__icon md-icon"></span>
838 </label>
839 <nav class="md-nav" aria-label="PIPs" data-md-level="2">
840 <label class="md-nav__title" for="__nav_5_2">
841 <span class="md-nav__icon md-icon"></span>
842 PIPs
843 </label>
844 <ul class="md-nav__list" data-md-scrollfix>
845
846
847
848
849
850 <li class="md-nav__item">
851 <a href="../../../package/pip/" class="md-nav__link">
852 Overview
853 </a>
854 </li>
855
856
857
858
859
860
861
862 <li class="md-nav__item">
863 <a href="../../../package/pip/acl-option/" class="md-nav__link">
864 aclOption
865 </a>
866 </li>
867
868
869
870
871
872
873
874 <li class="md-nav__item">
875 <a href="../../../package/pip/acp-menu/" class="md-nav__link">
876 acpMenu
877 </a>
878 </li>
879
880
881
882
883
884
885
886 <li class="md-nav__item">
887 <a href="../../../package/pip/acp-search-provider/" class="md-nav__link">
888 acpSearchProvider
889 </a>
890 </li>
891
892
893
894
895
896
897
898 <li class="md-nav__item">
899 <a href="../../../package/pip/acp-template/" class="md-nav__link">
900 acpTemplate
901 </a>
902 </li>
903
904
905
906
907
908
909
910 <li class="md-nav__item">
911 <a href="../../../package/pip/bbcode/" class="md-nav__link">
912 bbcode
913 </a>
914 </li>
915
916
917
918
919
920
921
922 <li class="md-nav__item">
923 <a href="../../../package/pip/box/" class="md-nav__link">
924 box
925 </a>
926 </li>
927
928
929
930
931
932
933
934 <li class="md-nav__item">
935 <a href="../../../package/pip/clipboard-action/" class="md-nav__link">
936 clipboardAction
937 </a>
938 </li>
939
940
941
942
943
944
945
946 <li class="md-nav__item">
947 <a href="../../../package/pip/core-object/" class="md-nav__link">
948 coreObject
949 </a>
950 </li>
951
952
953
954
955
956
957
958 <li class="md-nav__item">
959 <a href="../../../package/pip/cronjob/" class="md-nav__link">
960 cronjob
961 </a>
962 </li>
963
964
965
966
967
968
969
970 <li class="md-nav__item">
971 <a href="../../../package/pip/event-listener/" class="md-nav__link">
972 eventListener
973 </a>
974 </li>
975
976
977
978
979
980
981
982 <li class="md-nav__item">
983 <a href="../../../package/pip/file/" class="md-nav__link">
984 file
985 </a>
986 </li>
987
988
989
990
991
992
993
994 <li class="md-nav__item">
995 <a href="../../../package/pip/language/" class="md-nav__link">
996 language
997 </a>
998 </li>
999
1000
1001
1002
1003
1004
1005
1006 <li class="md-nav__item">
1007 <a href="../../../package/pip/media-provider/" class="md-nav__link">
1008 mediaProvider
1009 </a>
1010 </li>
1011
1012
1013
1014
1015
1016
1017
1018 <li class="md-nav__item">
1019 <a href="../../../package/pip/menu/" class="md-nav__link">
1020 menu
1021 </a>
1022 </li>
1023
1024
1025
1026
1027
1028
1029
1030 <li class="md-nav__item">
1031 <a href="../../../package/pip/menu-item/" class="md-nav__link">
1032 menuItem
1033 </a>
1034 </li>
1035
1036
1037
1038
1039
1040
1041
1042 <li class="md-nav__item">
1043 <a href="../../../package/pip/object-type/" class="md-nav__link">
1044 objectType
1045 </a>
1046 </li>
1047
1048
1049
1050
1051
1052
1053
1054 <li class="md-nav__item">
1055 <a href="../../../package/pip/object-type-definition/" class="md-nav__link">
1056 objectTypeDefinition
1057 </a>
1058 </li>
1059
1060
1061
1062
1063
1064
1065
1066 <li class="md-nav__item">
1067 <a href="../../../package/pip/option/" class="md-nav__link">
1068 option
1069 </a>
1070 </li>
1071
1072
1073
1074
1075
1076
1077
1078 <li class="md-nav__item">
1079 <a href="../../../package/pip/page/" class="md-nav__link">
1080 page
1081 </a>
1082 </li>
1083
1084
1085
1086
1087
1088
1089
1090 <li class="md-nav__item">
1091 <a href="../../../package/pip/pip/" class="md-nav__link">
1092 pip
1093 </a>
1094 </li>
1095
1096
1097
1098
1099
1100
1101
1102 <li class="md-nav__item">
1103 <a href="../../../package/pip/script/" class="md-nav__link">
1104 script
1105 </a>
1106 </li>
1107
1108
1109
1110
1111
1112
1113
1114 <li class="md-nav__item">
1115 <a href="../../../package/pip/smiley/" class="md-nav__link">
1116 smiley
1117 </a>
1118 </li>
1119
1120
1121
1122
1123
1124
1125
1126 <li class="md-nav__item">
1127 <a href="../../../package/pip/sql/" class="md-nav__link">
1128 sql
1129 </a>
1130 </li>
1131
1132
1133
1134
1135
1136
1137
1138 <li class="md-nav__item">
1139 <a href="../../../package/pip/style/" class="md-nav__link">
1140 style
1141 </a>
1142 </li>
1143
1144
1145
1146
1147
1148
1149
1150 <li class="md-nav__item">
1151 <a href="../../../package/pip/template/" class="md-nav__link">
1152 template
1153 </a>
1154 </li>
1155
1156
1157
1158
1159
1160
1161
1162 <li class="md-nav__item">
1163 <a href="../../../package/pip/template-listener/" class="md-nav__link">
1164 templateListener
1165 </a>
1166 </li>
1167
1168
1169
1170
1171
1172
1173
1174 <li class="md-nav__item">
1175 <a href="../../../package/pip/user-group-option/" class="md-nav__link">
1176 userGroupOption
1177 </a>
1178 </li>
1179
1180
1181
1182
1183
1184
1185
1186 <li class="md-nav__item">
1187 <a href="../../../package/pip/user-menu/" class="md-nav__link">
1188 userMenu
1189 </a>
1190 </li>
1191
1192
1193
1194
1195
1196
1197
1198 <li class="md-nav__item">
1199 <a href="../../../package/pip/user-notification-event/" class="md-nav__link">
1200 userNotificationEvent
1201 </a>
1202 </li>
1203
1204
1205
1206
1207
1208
1209
1210 <li class="md-nav__item">
1211 <a href="../../../package/pip/user-option/" class="md-nav__link">
1212 userOption
1213 </a>
1214 </li>
1215
1216
1217
1218
1219
1220
1221
1222 <li class="md-nav__item">
1223 <a href="../../../package/pip/user-profile-menu/" class="md-nav__link">
1224 userProfileMenu
1225 </a>
1226 </li>
1227
1228
1229
1230 </ul>
1231 </nav>
1232 </li>
1233
1234
1235
1236
1237
1238
1239
1240 <li class="md-nav__item">
1241 <a href="../../../package/database-php-api/" class="md-nav__link">
1242 Database PHP API
1243 </a>
1244 </li>
1245
1246
1247
1248 </ul>
1249 </nav>
1250 </li>
1251
1252
1253
1254
1255
1256
1257
1258
1259
1260
1261
1262
1263
1264 <li class="md-nav__item md-nav__item--active md-nav__item--nested">
1265
1266
1267 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6" type="checkbox" id="__nav_6" checked>
1268
1269 <label class="md-nav__link" for="__nav_6">
1270 Migration
1271 <span class="md-nav__icon md-icon"></span>
1272 </label>
1273 <nav class="md-nav" aria-label="Migration" data-md-level="1">
1274 <label class="md-nav__title" for="__nav_6">
1275 <span class="md-nav__icon md-icon"></span>
1276 Migration
1277 </label>
1278 <ul class="md-nav__list" data-md-scrollfix>
1279
1280
1281
1282
1283
1284
1285
1286
1287 <li class="md-nav__item md-nav__item--active md-nav__item--nested">
1288
1289
1290 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_1" type="checkbox" id="__nav_6_1" checked>
1291
1292 <label class="md-nav__link" for="__nav_6_1">
1293 Migrating from WSC 5.3
1294 <span class="md-nav__icon md-icon"></span>
1295 </label>
1296 <nav class="md-nav" aria-label="Migrating from WSC 5.3" data-md-level="2">
1297 <label class="md-nav__title" for="__nav_6_1">
1298 <span class="md-nav__icon md-icon"></span>
1299 Migrating from WSC 5.3
1300 </label>
1301 <ul class="md-nav__list" data-md-scrollfix>
1302
1303
1304
1305
1306
1307 <li class="md-nav__item">
1308 <a href="../php/" class="md-nav__link">
1309 PHP API
1310 </a>
1311 </li>
1312
1313
1314
1315
1316
1317
1318
1319
1320
1321 <li class="md-nav__item md-nav__item--active">
1322
1323 <input class="md-nav__toggle md-toggle" data-md-toggle="toc" type="checkbox" id="__toc">
1324
1325
1326
1327
1328 <label class="md-nav__link md-nav__link--active" for="__toc">
1329 Session Handling and Authentication
1330 <span class="md-nav__icon md-icon"></span>
1331 </label>
1332
1333 <a href="./" class="md-nav__link md-nav__link--active">
1334 Session Handling and Authentication
1335 </a>
1336
1337
1338 <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
1339
1340
1341
1342
1343
1344 <label class="md-nav__title" for="__toc">
1345 <span class="md-nav__icon md-icon"></span>
1346 Table of contents
1347 </label>
1348 <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
1349
1350 <li class="md-nav__item">
1351 <a href="#summary-and-concepts" class="md-nav__link">
1352 Summary and Concepts
1353 </a>
1354
1355 <nav class="md-nav" aria-label="Summary and Concepts">
1356 <ul class="md-nav__list">
1357
1358 <li class="md-nav__item">
1359 <a href="#legacy-persistent-login" class="md-nav__link">
1360 Legacy Persistent Login
1361 </a>
1362
1363 </li>
1364
1365 <li class="md-nav__item">
1366 <a href="#multiple-sessions" class="md-nav__link">
1367 Multiple Sessions
1368 </a>
1369
1370 </li>
1371
1372 <li class="md-nav__item">
1373 <a href="#merged-acp-and-frontend-sessions" class="md-nav__link">
1374 Merged ACP and Frontend Sessions
1375 </a>
1376
1377 </li>
1378
1379 <li class="md-nav__item">
1380 <a href="#improved-authentication-and-reauthentication" class="md-nav__link">
1381 Improved Authentication and Reauthentication
1382 </a>
1383
1384 </li>
1385
1386 </ul>
1387 </nav>
1388
1389 </li>
1390
1391 <li class="md-nav__item">
1392 <a href="#additions-and-changes" class="md-nav__link">
1393 Additions and Changes
1394 </a>
1395
1396 <nav class="md-nav" aria-label="Additions and Changes">
1397 <ul class="md-nav__list">
1398
1399 <li class="md-nav__item">
1400 <a href="#password-hashing" class="md-nav__link">
1401 Password Hashing
1402 </a>
1403
1404 </li>
1405
1406 <li class="md-nav__item">
1407 <a href="#session-storage" class="md-nav__link">
1408 Session Storage
1409 </a>
1410
1411 </li>
1412
1413 <li class="md-nav__item">
1414 <a href="#reauthentication" class="md-nav__link">
1415 Reauthentication
1416 </a>
1417
1418 </li>
1419
1420 <li class="md-nav__item">
1421 <a href="#multi-factor-authentication" class="md-nav__link">
1422 Multi-factor Authentication
1423 </a>
1424
1425 <nav class="md-nav" aria-label="Multi-factor Authentication">
1426 <ul class="md-nav__list">
1427
1428 <li class="md-nav__item">
1429 <a href="#adding-multi-factor-methods" class="md-nav__link">
1430 Adding Multi-factor Methods
1431 </a>
1432
1433 </li>
1434
1435 </ul>
1436 </nav>
1437
1438 </li>
1439
1440 </ul>
1441 </nav>
1442
1443 </li>
1444
1445 <li class="md-nav__item">
1446 <a href="#deprecations-and-removals" class="md-nav__link">
1447 Deprecations and Removals
1448 </a>
1449
1450 <nav class="md-nav" aria-label="Deprecations and Removals">
1451 <ul class="md-nav__list">
1452
1453 <li class="md-nav__item">
1454 <a href="#sessionhandler" class="md-nav__link">
1455 SessionHandler
1456 </a>
1457
1458 </li>
1459
1460 <li class="md-nav__item">
1461 <a href="#acp-sessions" class="md-nav__link">
1462 ACP Sessions
1463 </a>
1464
1465 </li>
1466
1467 <li class="md-nav__item">
1468 <a href="#cookies" class="md-nav__link">
1469 Cookies
1470 </a>
1471
1472 </li>
1473
1474 <li class="md-nav__item">
1475 <a href="#virtual-sessions" class="md-nav__link">
1476 Virtual Sessions
1477 </a>
1478
1479 </li>
1480
1481 <li class="md-nav__item">
1482 <a href="#security-token-constants" class="md-nav__link">
1483 Security Token Constants
1484 </a>
1485
1486 </li>
1487
1488 <li class="md-nav__item">
1489 <a href="#passwordutil-and-double-bcrypt-hashes" class="md-nav__link">
1490 PasswordUtil and Double BCrypt Hashes
1491 </a>
1492
1493 </li>
1494
1495 </ul>
1496 </nav>
1497
1498 </li>
1499
1500 </ul>
1501
1502 </nav>
1503
1504 </li>
1505
1506
1507
1508
1509
1510
1511
1512 <li class="md-nav__item">
1513 <a href="../javascript/" class="md-nav__link">
1514 JavaScript
1515 </a>
1516 </li>
1517
1518
1519
1520
1521
1522
1523
1524 <li class="md-nav__item">
1525 <a href="../templates/" class="md-nav__link">
1526 Templates
1527 </a>
1528 </li>
1529
1530
1531
1532
1533
1534
1535
1536 <li class="md-nav__item">
1537 <a href="../libraries/" class="md-nav__link">
1538 Third Party Libraries
1539 </a>
1540 </li>
1541
1542
1543
1544 </ul>
1545 </nav>
1546 </li>
1547
1548
1549
1550
1551
1552
1553
1554
1555 <li class="md-nav__item md-nav__item--nested">
1556
1557
1558 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_2" type="checkbox" id="__nav_6_2" >
1559
1560 <label class="md-nav__link" for="__nav_6_2">
1561 Migrating from WSC 5.2
1562 <span class="md-nav__icon md-icon"></span>
1563 </label>
1564 <nav class="md-nav" aria-label="Migrating from WSC 5.2" data-md-level="2">
1565 <label class="md-nav__title" for="__nav_6_2">
1566 <span class="md-nav__icon md-icon"></span>
1567 Migrating from WSC 5.2
1568 </label>
1569 <ul class="md-nav__list" data-md-scrollfix>
1570
1571
1572
1573
1574
1575 <li class="md-nav__item">
1576 <a href="../../wsc52/php/" class="md-nav__link">
1577 PHP API
1578 </a>
1579 </li>
1580
1581
1582
1583
1584
1585
1586
1587 <li class="md-nav__item">
1588 <a href="../../wsc52/templates/" class="md-nav__link">
1589 Templates and Languages
1590 </a>
1591 </li>
1592
1593
1594
1595
1596
1597
1598
1599 <li class="md-nav__item">
1600 <a href="../../wsc52/libraries/" class="md-nav__link">
1601 Third Party Libraries
1602 </a>
1603 </li>
1604
1605
1606
1607 </ul>
1608 </nav>
1609 </li>
1610
1611
1612
1613
1614
1615
1616
1617
1618 <li class="md-nav__item md-nav__item--nested">
1619
1620
1621 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_3" type="checkbox" id="__nav_6_3" >
1622
1623 <label class="md-nav__link" for="__nav_6_3">
1624 Migrating from WSC 3.1
1625 <span class="md-nav__icon md-icon"></span>
1626 </label>
1627 <nav class="md-nav" aria-label="Migrating from WSC 3.1" data-md-level="2">
1628 <label class="md-nav__title" for="__nav_6_3">
1629 <span class="md-nav__icon md-icon"></span>
1630 Migrating from WSC 3.1
1631 </label>
1632 <ul class="md-nav__list" data-md-scrollfix>
1633
1634
1635
1636
1637
1638 <li class="md-nav__item">
1639 <a href="../../wsc31/php/" class="md-nav__link">
1640 PHP API
1641 </a>
1642 </li>
1643
1644
1645
1646 </ul>
1647 </nav>
1648 </li>
1649
1650
1651
1652
1653
1654
1655
1656
1657 <li class="md-nav__item md-nav__item--nested">
1658
1659
1660 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_4" type="checkbox" id="__nav_6_4" >
1661
1662 <label class="md-nav__link" for="__nav_6_4">
1663 Migrating from WSC 3.0
1664 <span class="md-nav__icon md-icon"></span>
1665 </label>
1666 <nav class="md-nav" aria-label="Migrating from WSC 3.0" data-md-level="2">
1667 <label class="md-nav__title" for="__nav_6_4">
1668 <span class="md-nav__icon md-icon"></span>
1669 Migrating from WSC 3.0
1670 </label>
1671 <ul class="md-nav__list" data-md-scrollfix>
1672
1673
1674
1675
1676
1677 <li class="md-nav__item">
1678 <a href="../../wsc30/php/" class="md-nav__link">
1679 PHP API
1680 </a>
1681 </li>
1682
1683
1684
1685
1686
1687
1688
1689 <li class="md-nav__item">
1690 <a href="../../wsc30/javascript/" class="md-nav__link">
1691 JavaScript API
1692 </a>
1693 </li>
1694
1695
1696
1697
1698
1699
1700
1701 <li class="md-nav__item">
1702 <a href="../../wsc30/templates/" class="md-nav__link">
1703 Templates
1704 </a>
1705 </li>
1706
1707
1708
1709
1710
1711
1712
1713 <li class="md-nav__item">
1714 <a href="../../wsc30/css/" class="md-nav__link">
1715 CSS
1716 </a>
1717 </li>
1718
1719
1720
1721
1722
1723
1724
1725 <li class="md-nav__item">
1726 <a href="../../wsc30/package/" class="md-nav__link">
1727 Package Components
1728 </a>
1729 </li>
1730
1731
1732
1733 </ul>
1734 </nav>
1735 </li>
1736
1737
1738
1739
1740
1741
1742
1743
1744 <li class="md-nav__item md-nav__item--nested">
1745
1746
1747 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_5" type="checkbox" id="__nav_6_5" >
1748
1749 <label class="md-nav__link" for="__nav_6_5">
1750 Migrating from WCF 2.1
1751 <span class="md-nav__icon md-icon"></span>
1752 </label>
1753 <nav class="md-nav" aria-label="Migrating from WCF 2.1" data-md-level="2">
1754 <label class="md-nav__title" for="__nav_6_5">
1755 <span class="md-nav__icon md-icon"></span>
1756 Migrating from WCF 2.1
1757 </label>
1758 <ul class="md-nav__list" data-md-scrollfix>
1759
1760
1761
1762
1763
1764 <li class="md-nav__item">
1765 <a href="../../wcf21/php/" class="md-nav__link">
1766 PHP API
1767 </a>
1768 </li>
1769
1770
1771
1772
1773
1774
1775
1776 <li class="md-nav__item">
1777 <a href="../../wcf21/templates/" class="md-nav__link">
1778 Templates
1779 </a>
1780 </li>
1781
1782
1783
1784
1785
1786
1787
1788 <li class="md-nav__item">
1789 <a href="../../wcf21/css/" class="md-nav__link">
1790 CSS
1791 </a>
1792 </li>
1793
1794
1795
1796
1797
1798
1799
1800 <li class="md-nav__item">
1801 <a href="../../wcf21/package/" class="md-nav__link">
1802 Package Components
1803 </a>
1804 </li>
1805
1806
1807
1808 </ul>
1809 </nav>
1810 </li>
1811
1812
1813
1814 </ul>
1815 </nav>
1816 </li>
1817
1818
1819
1820
1821
1822
1823
1824
1825
1826
1827
1828 <li class="md-nav__item md-nav__item--nested">
1829
1830
1831 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_7" type="checkbox" id="__nav_7" >
1832
1833 <label class="md-nav__link" for="__nav_7">
1834 Tutorials
1835 <span class="md-nav__icon md-icon"></span>
1836 </label>
1837 <nav class="md-nav" aria-label="Tutorials" data-md-level="1">
1838 <label class="md-nav__title" for="__nav_7">
1839 <span class="md-nav__icon md-icon"></span>
1840 Tutorials
1841 </label>
1842 <ul class="md-nav__list" data-md-scrollfix>
1843
1844
1845
1846
1847
1848
1849 <li class="md-nav__item md-nav__item--nested">
1850
1851
1852 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_7_1" type="checkbox" id="__nav_7_1" >
1853
1854 <label class="md-nav__link" for="__nav_7_1">
1855 Tutorial Series
1856 <span class="md-nav__icon md-icon"></span>
1857 </label>
1858 <nav class="md-nav" aria-label="Tutorial Series" data-md-level="2">
1859 <label class="md-nav__title" for="__nav_7_1">
1860 <span class="md-nav__icon md-icon"></span>
1861 Tutorial Series
1862 </label>
1863 <ul class="md-nav__list" data-md-scrollfix>
1864
1865
1866
1867
1868
1869 <li class="md-nav__item">
1870 <a href="../../../tutorial/series/overview/" class="md-nav__link">
1871 Overview
1872 </a>
1873 </li>
1874
1875
1876
1877
1878
1879
1880
1881 <li class="md-nav__item">
1882 <a href="../../../tutorial/series/part_1/" class="md-nav__link">
1883 Part 1
1884 </a>
1885 </li>
1886
1887
1888
1889
1890
1891
1892
1893 <li class="md-nav__item">
1894 <a href="../../../tutorial/series/part_2/" class="md-nav__link">
1895 Part 2
1896 </a>
1897 </li>
1898
1899
1900
1901
1902
1903
1904
1905 <li class="md-nav__item">
1906 <a href="../../../tutorial/series/part_3/" class="md-nav__link">
1907 Part 3
1908 </a>
1909 </li>
1910
1911
1912
1913 </ul>
1914 </nav>
1915 </li>
1916
1917
1918
1919 </ul>
1920 </nav>
1921 </li>
1922
1923
1924
1925 </ul>
1926 </nav>
1927 </div>
1928 </div>
1929 </div>
1930
1931
1932
1933 <div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
1934 <div class="md-sidebar__scrollwrap">
1935 <div class="md-sidebar__inner">
1936
1937 <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
1938
1939
1940
1941
1942
1943 <label class="md-nav__title" for="__toc">
1944 <span class="md-nav__icon md-icon"></span>
1945 Table of contents
1946 </label>
1947 <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
1948
1949 <li class="md-nav__item">
1950 <a href="#summary-and-concepts" class="md-nav__link">
1951 Summary and Concepts
1952 </a>
1953
1954 <nav class="md-nav" aria-label="Summary and Concepts">
1955 <ul class="md-nav__list">
1956
1957 <li class="md-nav__item">
1958 <a href="#legacy-persistent-login" class="md-nav__link">
1959 Legacy Persistent Login
1960 </a>
1961
1962 </li>
1963
1964 <li class="md-nav__item">
1965 <a href="#multiple-sessions" class="md-nav__link">
1966 Multiple Sessions
1967 </a>
1968
1969 </li>
1970
1971 <li class="md-nav__item">
1972 <a href="#merged-acp-and-frontend-sessions" class="md-nav__link">
1973 Merged ACP and Frontend Sessions
1974 </a>
1975
1976 </li>
1977
1978 <li class="md-nav__item">
1979 <a href="#improved-authentication-and-reauthentication" class="md-nav__link">
1980 Improved Authentication and Reauthentication
1981 </a>
1982
1983 </li>
1984
1985 </ul>
1986 </nav>
1987
1988 </li>
1989
1990 <li class="md-nav__item">
1991 <a href="#additions-and-changes" class="md-nav__link">
1992 Additions and Changes
1993 </a>
1994
1995 <nav class="md-nav" aria-label="Additions and Changes">
1996 <ul class="md-nav__list">
1997
1998 <li class="md-nav__item">
1999 <a href="#password-hashing" class="md-nav__link">
2000 Password Hashing
2001 </a>
2002
2003 </li>
2004
2005 <li class="md-nav__item">
2006 <a href="#session-storage" class="md-nav__link">
2007 Session Storage
2008 </a>
2009
2010 </li>
2011
2012 <li class="md-nav__item">
2013 <a href="#reauthentication" class="md-nav__link">
2014 Reauthentication
2015 </a>
2016
2017 </li>
2018
2019 <li class="md-nav__item">
2020 <a href="#multi-factor-authentication" class="md-nav__link">
2021 Multi-factor Authentication
2022 </a>
2023
2024 <nav class="md-nav" aria-label="Multi-factor Authentication">
2025 <ul class="md-nav__list">
2026
2027 <li class="md-nav__item">
2028 <a href="#adding-multi-factor-methods" class="md-nav__link">
2029 Adding Multi-factor Methods
2030 </a>
2031
2032 </li>
2033
2034 </ul>
2035 </nav>
2036
2037 </li>
2038
2039 </ul>
2040 </nav>
2041
2042 </li>
2043
2044 <li class="md-nav__item">
2045 <a href="#deprecations-and-removals" class="md-nav__link">
2046 Deprecations and Removals
2047 </a>
2048
2049 <nav class="md-nav" aria-label="Deprecations and Removals">
2050 <ul class="md-nav__list">
2051
2052 <li class="md-nav__item">
2053 <a href="#sessionhandler" class="md-nav__link">
2054 SessionHandler
2055 </a>
2056
2057 </li>
2058
2059 <li class="md-nav__item">
2060 <a href="#acp-sessions" class="md-nav__link">
2061 ACP Sessions
2062 </a>
2063
2064 </li>
2065
2066 <li class="md-nav__item">
2067 <a href="#cookies" class="md-nav__link">
2068 Cookies
2069 </a>
2070
2071 </li>
2072
2073 <li class="md-nav__item">
2074 <a href="#virtual-sessions" class="md-nav__link">
2075 Virtual Sessions
2076 </a>
2077
2078 </li>
2079
2080 <li class="md-nav__item">
2081 <a href="#security-token-constants" class="md-nav__link">
2082 Security Token Constants
2083 </a>
2084
2085 </li>
2086
2087 <li class="md-nav__item">
2088 <a href="#passwordutil-and-double-bcrypt-hashes" class="md-nav__link">
2089 PasswordUtil and Double BCrypt Hashes
2090 </a>
2091
2092 </li>
2093
2094 </ul>
2095 </nav>
2096
2097 </li>
2098
2099 </ul>
2100
2101 </nav>
2102 </div>
2103 </div>
2104 </div>
2105
2106
2107 <div class="md-content" data-md-component="content">
2108 <article class="md-content__inner md-typeset">
2109
2110
2111 <a href="https://github.com/WoltLab/docs.woltlab.com/edit/5.4/docs/migration/wsc53/session.md" title="Edit this page" class="md-content__button md-icon">
2112 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20.71 7.04c.39-.39.39-1.04 0-1.41l-2.34-2.34c-.37-.39-1.02-.39-1.41 0l-1.84 1.83 3.75 3.75M3 17.25V21h3.75L17.81 9.93l-3.75-3.75L3 17.25z"/></svg>
2113 </a>
2114
2115
2116 <h1 id="migrating-from-wsc-53-session-handling-and-authentication">Migrating from WSC 5.3 - Session Handling and Authentication<a class="headerlink" href="#migrating-from-wsc-53-session-handling-and-authentication" title="Permanent link">#</a></h1>
2117 <p>WoltLab Suite 5.4 includes a completely refactored session handling.
2118 As long as you only interact with sessions via <code>WCF::getSession()</code>, especially when you perform read-only accesses, you should not notice any breaking changes.</p>
2119 <p>You might appreciate some of the new session methods if you process security sensitive data.</p>
2120 <h2 id="summary-and-concepts">Summary and Concepts<a class="headerlink" href="#summary-and-concepts" title="Permanent link">#</a></h2>
2121 <p>Most of the changes revolve around the removal of the legacy persistent login functionality and the assumption that every user has a single session only.
2122 Both aspects are related to each other.</p>
2123 <h3 id="legacy-persistent-login">Legacy Persistent Login<a class="headerlink" href="#legacy-persistent-login" title="Permanent link">#</a></h3>
2124 <p>The legacy persistent login was rather an automated login.
2125 Upon bootstrapping a session, it was checked whether the user had a cookie pair storing the user’s <code>userID</code> and (a single BCrypt hash of) the user’s password.
2126 If such a cookie pair exists and the BCrypt hash within the cookie matches the user’s password hash when hashed again, the session would immediately <code>changeUser()</code> to the respective user.</p>
2127 <p>This legacy persistent login was completely removed.
2128 Instead, any sessions that belong to an authenticated user will automatically be long-lived.
2129 These long-lived sessions expire no sooner than 14 days after the last activity, ensuring that the user continously stays logged in, provided that they visit the page at least once per fortnight.</p>
2130 <h3 id="multiple-sessions">Multiple Sessions<a class="headerlink" href="#multiple-sessions" title="Permanent link">#</a></h3>
2131 <p>To allow for a proper separation of these long-lived user sessions, WoltLab Suite now allows for multiple sessions per user.
2132 These sessions are completely unrelated to each other.
2133 Specifically, they do not share session variables and they expire independently.</p>
2134 <p>As the existing <code>wcf1_session</code> table is also used for the online lists and location tracking, it will be maintained on a best effort basis.
2135 It no longer stores any private session data.</p>
2136 <p>The actual sessions storing security sensitive information are in an unrelated location.
2137 They must only be accessed via the PHP API exposed by the <code>SessionHandler</code>.</p>
2138 <h3 id="merged-acp-and-frontend-sessions">Merged ACP and Frontend Sessions<a class="headerlink" href="#merged-acp-and-frontend-sessions" title="Permanent link">#</a></h3>
2139 <p>WoltLab Suite 5.4 shares a single session across both the frontend, as well as the ACP.
2140 When a user logs in to the frontend, they will also be logged into the ACP and vice versa.</p>
2141 <p>Actual access to the ACP is controlled via the new <a href="#reauthentication">reauthentication mechanism</a>.</p>
2142 <p>The session variable store is scoped:
2143 Session variables set within the frontend are not available within the ACP and vice versa.</p>
2144 <h3 id="improved-authentication-and-reauthentication">Improved Authentication and Reauthentication<a class="headerlink" href="#improved-authentication-and-reauthentication" title="Permanent link">#</a></h3>
2145 <p>WoltLab Suite 5.4 ships with multi-factor authentication support and a generic re-authentication implementation that can be used to verify the account owner’s presence.</p>
2146 <h2 id="additions-and-changes">Additions and Changes<a class="headerlink" href="#additions-and-changes" title="Permanent link">#</a></h2>
2147 <h3 id="password-hashing">Password Hashing<a class="headerlink" href="#password-hashing" title="Permanent link">#</a></h3>
2148 <p>WoltLab Suite 5.4 includes a new object-oriented password hashing framework that is modeled after PHP’s <code>password_*</code> API.
2149 Check <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/authentication/password/PasswordAlgorithmManager.class.php"><code>PasswordAlgorithmManager</code></a> and <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/authentication/password/IPasswordAlgorithm.class.php"><code>IPasswordAlgorithm</code></a> for details.</p>
2150 <p>The new default password hash is a standard BCrypt hash.
2151 All newly generated hashes in <code>wcf1_user.password</code> will now include a type prefix, instead of just passwords imported from other systems.</p>
2152 <h3 id="session-storage">Session Storage<a class="headerlink" href="#session-storage" title="Permanent link">#</a></h3>
2153 <p>The <code>wcf1_session</code> table will no longer be used for session storage.
2154 Instead, it is maintained for compatibility with existing online lists.</p>
2155 <p>The actual session storage is considered an implementation detail and you <em>must not</em> directly interact with the session tables.
2156 Future versions might support alternative session backends, such as Redis.</p>
2157 <div class="admonition warning">
2158 <p class="admonition-title">Do not interact directly with the session database tables but only via the <code>SessionHandler</code> class!</p>
2159 </div>
2160 <h3 id="reauthentication">Reauthentication<a class="headerlink" href="#reauthentication" title="Permanent link">#</a></h3>
2161 <p>For security sensitive processing, you might want to ensure that the account owner is actually present instead of a third party accessing a session that was accidentally left logged in.</p>
2162 <p>WoltLab Suite 5.4 ships with a generic reauthentication framework.
2163 To request reauthentication within your controller you need to:</p>
2164 <ol>
2165 <li>Use the <code>wcf\system\user\authentication\TReauthenticationCheck</code> trait.</li>
2166 <li>Call:
2167 <div class="highlight"><pre><span></span><code><span class="nv">$this</span><span class="o">-&gt;</span><span class="na">requestReauthentication</span><span class="p">(</span><span class="nx">LinkHandler</span><span class="o">::</span><span class="na">getInstance</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">getControllerLink</span><span class="p">(</span><span class="k">static</span><span class="o">::</span><span class="na">class</span><span class="p">,</span> <span class="p">[</span>
2168 <span class="cm">/* additional parameters */</span>
2169 <span class="p">]));</span>
2170 </code></pre></div></li>
2171 </ol>
2172 <p><code>requestReauthentication()</code> will check if the user has recently authenticated themselves.
2173 If they did, the request proceeds as usual.
2174 Otherwise, they will be asked to reauthenticate themselves.
2175 After the successful authentication, they will be redirected to the URL that was passed as the first parameter (the current controller within the example).</p>
2176 <p>Details can be found in <a href="https://github.com/WoltLab/WCF/pull/3775">WoltLab/WCF#3775</a>.</p>
2177 <h3 id="multi-factor-authentication">Multi-factor Authentication<a class="headerlink" href="#multi-factor-authentication" title="Permanent link">#</a></h3>
2178 <p>To implement multi-factor authentication securely, WoltLab Suite 5.4 implements the concept of a “pending user change”.
2179 The user will not be logged in (i.e. <code>WCF::getUser()-&gt;userID</code> returns <code>null</code>) until they authenticate themselves with their second factor.</p>
2180 <p>Requesting multi-factor authentication is done on an opt-in basis for compatibility reasons.
2181 If you perform authentication yourself and do not trust the authentication source to perform multi-factor authentication itself, you will need to adjust your logic to request multi-factor authentication from WoltLab Suite:</p>
2182 <p>Previously:</p>
2183 <div class="highlight"><pre><span></span><code><span class="nx">WCF</span><span class="o">::</span><span class="na">getSession</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">changeUser</span><span class="p">(</span><span class="nv">$targetUser</span><span class="p">);</span>
2184 </code></pre></div>
2185 <p>Now:</p>
2186 <div class="highlight"><pre><span></span><code><span class="nv">$isPending</span> <span class="o">=</span> <span class="nx">WCF</span><span class="o">::</span><span class="na">getSession</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">changeUserAfterMultifactorAuthentication</span><span class="p">(</span><span class="nv">$targetUser</span><span class="p">);</span>
2187 <span class="k">if</span> <span class="p">(</span><span class="nv">$isPending</span><span class="p">)</span> <span class="p">{</span>
2188 <span class="c1">// Redirect to the authentication form. The user will not be logged in.</span>
2189 <span class="c1">// Note: Do not use `getControllerLink` to support both the frontend as well as the ACP.</span>
2190 <span class="nx">HeaderUtil</span><span class="o">::</span><span class="na">redirect</span><span class="p">(</span><span class="nx">LinkHandler</span><span class="o">::</span><span class="na">getInstance</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">getLink</span><span class="p">(</span><span class="s1">&#39;MultifactorAuthentication&#39;</span><span class="p">,</span> <span class="p">[</span>
2191 <span class="s1">&#39;url&#39;</span> <span class="o">=&gt;</span> <span class="cm">/* Return To */</span><span class="p">,</span>
2192 <span class="p">]));</span>
2193 <span class="k">exit</span><span class="p">;</span>
2194 <span class="p">}</span>
2195 <span class="c1">// Proceed as usual. The user will be logged in.</span>
2196 </code></pre></div>
2197 <h4 id="adding-multi-factor-methods">Adding Multi-factor Methods<a class="headerlink" href="#adding-multi-factor-methods" title="Permanent link">#</a></h4>
2198 <p>Adding your own multi-factor method requires the implementation of a single object type:</p>
2199 <div class="highlight"><pre><span></span><code><span class="nt">&lt;type&gt;</span>
2200 <span class="nt">&lt;name&gt;</span>com.example.multifactor.foobar<span class="nt">&lt;/name&gt;</span>
2201 <span class="nt">&lt;definitionname&gt;</span>com.woltlab.wcf.multifactor<span class="nt">&lt;/definitionname&gt;</span>
2202 <span class="nt">&lt;icon&gt;</span><span class="c">&lt;!-- Font Awesome 4 Icon Name goes here. --&gt;</span><span class="nt">&lt;/icon&gt;</span>
2203 <span class="nt">&lt;priority&gt;</span><span class="c">&lt;!-- Determines the sort order, higher priority will be preferred for authentication. --&gt;</span><span class="nt">&lt;/priority&gt;</span>
2204 <span class="nt">&lt;classname&gt;</span>wcf\system\user\multifactor\FoobarMultifactorMethod<span class="nt">&lt;/classname&gt;</span>
2205 <span class="nt">&lt;/type&gt;</span>
2206 </code></pre></div>
2207 <p>The given classname must implement the <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/multifactor/IMultifactorMethod.class.php"><code>IMultifactorMethod</code></a> interface.</p>
2208 <p>As a self-contained example, you can find the initial implementation of the email multi-factor method in <a href="https://github.com/WoltLab/WCF/pull/3729">WoltLab/WCF#3729</a>.
2209 Please check <a href="https://github.com/WoltLab/WCF/commits/master/wcfsetup/install/files/lib/system/user/multifactor/EmailMultifactorMethod.class.php">the version history</a> of the PHP class to make sure you do not miss important changes that were added later.</p>
2210 <div class="admonition warning">
2211 <p class="admonition-title">Multi-factor authentication is security sensitive. Make sure to carefully read the remarks in <code>IMultifactorMethod</code> for possible issues. Also make sure to carefully test your implementation against all sorts of incorrect input and consider attack vectors such as race conditions. It is strongly recommended to generously check the current state by leveraging assertions and exceptions.</p>
2212 </div>
2213 <h2 id="deprecations-and-removals">Deprecations and Removals<a class="headerlink" href="#deprecations-and-removals" title="Permanent link">#</a></h2>
2214 <h3 id="sessionhandler">SessionHandler<a class="headerlink" href="#sessionhandler" title="Permanent link">#</a></h3>
2215 <p>Most of the changes with regard to the new session handling happened in <code>SessionHandler</code>.
2216 Most notably, <code>SessionHandler</code> now is marked <code>final</code> to ensure proper encapsulation of data.</p>
2217 <p>A number of methods in <code>SessionHandler</code> are now deprecated and result in a noop.
2218 This change mostly affects methods that have been used to bootstrap the session, such as <code>setHasValidCookie()</code>.</p>
2219 <p>Additionally, accessing the following keys on the session is deprecated.
2220 They directly map to an existing method in another class and any uses can easily be updated:
2221 - <code>ipAddress</code>
2222 - <code>userAgent</code>
2223 - <code>requestURI</code>
2224 - <code>requestMethod</code>
2225 - <code>lastActivityTime</code></p>
2226 <p>Refer to <a href="https://github.com/WoltLab/WCF/blob/439de4963c947c3569a0c584f795245f693155b0/wcfsetup/install/files/lib/system/session/SessionHandler.class.php#L168-L178">the implementation</a> for details.</p>
2227 <h3 id="acp-sessions">ACP Sessions<a class="headerlink" href="#acp-sessions" title="Permanent link">#</a></h3>
2228 <p>The database tables related to ACP sessions have been removed.
2229 The PHP classes have been preserved due to being used within the class hierarchy of the legacy sessions.</p>
2230 <h3 id="cookies">Cookies<a class="headerlink" href="#cookies" title="Permanent link">#</a></h3>
2231 <p>The <code>_userID</code>, <code>_password</code>, <code>_cookieHash</code> and <code>_cookieHash_acp</code> cookies will no longer be created nor consumed.</p>
2232 <h3 id="virtual-sessions">Virtual Sessions<a class="headerlink" href="#virtual-sessions" title="Permanent link">#</a></h3>
2233 <p>The virtual session logic existed to support multiple devices per single session in <code>wcf1_session</code>.
2234 Virtual sessions are no longer required with the refactored session handling.</p>
2235 <p>Anything related to virtual sessions has been completely removed as they are considered an implementation detail.
2236 This removal includes PHP classes and database tables.</p>
2237 <h3 id="security-token-constants">Security Token Constants<a class="headerlink" href="#security-token-constants" title="Permanent link">#</a></h3>
2238 <p>The security token constants are deprecated.
2239 Instead, the methods of <code>SessionHandler</code> should be used (e.g. <code>-&gt;getSecurityToken()</code>).
2240 Within templates, you should migrate to the <code>{csrfToken}</code> tag in place of <code>{@SECURITY_TOKEN_INPUT_TAG}</code>.
2241 The <code>{csrfToken}</code> tag is a drop-in replacement and was backported to WoltLab Suite 5.2+, allowing you to maintain compatibility across a broad range of versions.</p>
2242 <h3 id="passwordutil-and-double-bcrypt-hashes">PasswordUtil and Double BCrypt Hashes<a class="headerlink" href="#passwordutil-and-double-bcrypt-hashes" title="Permanent link">#</a></h3>
2243 <p>Most of the methods in PasswordUtil are deprecated in favor of the new password hashing framework.</p>
2244
2245
2246
2247
2248 <hr>
2249 <div class="md-source-date">
2250 <small>
2251
2252 Last update: 2021-02-11
2253
2254 </small>
2255 </div>
2256
2257
2258
2259
2260
2261
2262
2263
2264 </article>
2265 </div>
2266 </div>
2267 </main>
2268
2269
2270 <footer class="md-footer">
2271
2272 <nav class="md-footer__inner md-grid" aria-label="Footer">
2273
2274 <a href="../php/" class="md-footer__link md-footer__link--prev" rel="prev">
2275 <div class="md-footer__button md-icon">
2276 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12z"/></svg>
2277 </div>
2278 <div class="md-footer__title">
2279 <div class="md-ellipsis">
2280 <span class="md-footer__direction">
2281 Previous
2282 </span>
2283 PHP API
2284 </div>
2285 </div>
2286 </a>
2287
2288
2289 <a href="../javascript/" class="md-footer__link md-footer__link--next" rel="next">
2290 <div class="md-footer__title">
2291 <div class="md-ellipsis">
2292 <span class="md-footer__direction">
2293 Next
2294 </span>
2295 JavaScript
2296 </div>
2297 </div>
2298 <div class="md-footer__button md-icon">
2299 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M4 11v2h12l-5.5 5.5 1.42 1.42L19.84 12l-7.92-7.92L10.5 5.5 16 11H4z"/></svg>
2300 </div>
2301 </a>
2302
2303 </nav>
2304
2305 <div class="md-footer-meta md-typeset">
2306 <div class="md-footer-meta__inner md-grid">
2307 <div class="md-footer-copyright">
2308
2309 <div class="md-footer-copyright__highlight">
2310 Copyright © 2020 WoltLab GmbH
2311 </div>
2312
2313 Made with
2314 <a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
2315 Material for MkDocs
2316 </a>
2317
2318 </div>
2319 <div class="md-footer-copyright">
2320 <a href="https://www.woltlab.com/legal-notice/">Legal Notice</a>
2321 <a href="https://www.woltlab.com/privacy-policy/">Privacy Policy</a>
2322 </div>
2323 </div>
2324 </div>
2325 </footer>
2326
2327 </div>
2328 <div class="md-dialog" data-md-component="dialog">
2329 <div class="md-dialog__inner md-typeset"></div>
2330 </div>
2331 <script id="__config" type="application/json">{"base": "../../..", "features": [], "translations": {"clipboard.copy": "Copy to clipboard", "clipboard.copied": "Copied to clipboard", "search.config.lang": "en", "search.config.pipeline": "trimmer, stopWordFilter", "search.config.separator": "[\\s\\-]+", "search.placeholder": "Search", "search.result.placeholder": "Type to start searching", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.term.missing": "Missing"}, "search": "../../../assets/javascripts/workers/search.fb4a9340.min.js", "version": {"provider": "mike"}}</script>
2332
2333
2334 <script src="../../../assets/javascripts/bundle.5cf3e710.min.js"></script>
2335
2336
2337 </body>
2338 </html>