Deployed 59ff7f1 to 5.4 with MkDocs 1.1.2 and mike 0.5.5
[GitHub/WoltLab/woltlab.github.io.git] / latest / migration / wsc53 / session / index.html
1
2 <!doctype html>
3 <html lang="en" class="no-js">
4 <head>
5
6 <meta charset="utf-8">
7 <meta name="viewport" content="width=device-width,initial-scale=1">
8
9
10
11
12 <link rel="icon" href="../../../assets/default.favicon.ico">
13 <meta name="generator" content="mkdocs-1.1.2, mkdocs-material-7.1.0">
14
15
16
17 <title>Session Handling and Authentication - WoltLab Suite Documentation</title>
18
19
20
21 <link rel="stylesheet" href="../../../assets/stylesheets/main.33e2939f.min.css">
22
23
24 <link rel="stylesheet" href="../../../assets/stylesheets/palette.ef6f36e2.min.css">
25
26
27
28 <meta name="theme-color" content="#009485">
29
30
31
32
33
34
35
36
37
38 <link rel="stylesheet" href="../../../stylesheets/extra.css">
39
40
41
42
43
44 </head>
45
46
47
48
49
50
51
52 <body dir="ltr" data-md-color-scheme="" data-md-color-primary="teal" data-md-color-accent="">
53
54
55 <script>function __prefix(e){return new URL("../../..",location).pathname+"."+e}function __get(e,t=localStorage){return JSON.parse(t.getItem(__prefix(e)))}</script>
56
57 <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
58 <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
59 <label class="md-overlay" for="__drawer"></label>
60 <div data-md-component="skip">
61
62
63 <a href="#migrating-from-wsc-53-session-handling-and-authentication" class="md-skip">
64 Skip to content
65 </a>
66
67 </div>
68 <div data-md-component="announce">
69
70 <aside class="md-announce">
71 <div class="md-announce__inner md-grid md-typeset">
72
73 <a href="https://www.woltlab.com">Back to <strong>woltlab.com</strong></a>
74
75 </div>
76 </aside>
77
78 </div>
79
80 <header class="md-header" data-md-component="header">
81 <nav class="md-header__inner md-grid" aria-label="Header">
82 <a href="../../.." title="WoltLab Suite Documentation" class="md-header__button md-logo" aria-label="WoltLab Suite Documentation" data-md-component="logo">
83
84 <img src="../../../assets/logo.png" alt="logo">
85
86 </a>
87 <label class="md-header__button md-icon" for="__drawer">
88 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3V6m0 5h18v2H3v-2m0 5h18v2H3v-2z"/></svg>
89 </label>
90 <div class="md-header__title" data-md-component="header-title">
91 <div class="md-header__ellipsis">
92 <div class="md-header__topic">
93 <span class="md-ellipsis">
94 WoltLab Suite Documentation
95 </span>
96 </div>
97 <div class="md-header__topic" data-md-component="header-topic">
98 <span class="md-ellipsis">
99
100 Session Handling and Authentication
101
102 </span>
103 </div>
104 </div>
105 </div>
106
107
108
109 <label class="md-header__button md-icon" for="__search">
110 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5z"/></svg>
111 </label>
112
113 <div class="md-search" data-md-component="search" role="dialog">
114 <label class="md-search__overlay" for="__search"></label>
115 <div class="md-search__inner" role="search">
116 <form class="md-search__form" name="search">
117 <input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" data-md-state="active" required>
118 <label class="md-search__icon md-icon" for="__search">
119 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5z"/></svg>
120 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12z"/></svg>
121 </label>
122 <button type="reset" class="md-search__icon md-icon" aria-label="Clear" tabindex="-1">
123 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12 19 6.41z"/></svg>
124 </button>
125 </form>
126 <div class="md-search__output">
127 <div class="md-search__scrollwrap" data-md-scrollfix>
128 <div class="md-search-result" data-md-component="search-result">
129 <div class="md-search-result__meta">
130 Initializing search
131 </div>
132 <ol class="md-search-result__list"></ol>
133 </div>
134 </div>
135 </div>
136 </div>
137 </div>
138
139
140 <div class="md-header__source">
141
142 <a href="https://github.com/WoltLab/docs.woltlab.com/" title="Go to repository" class="md-source" data-md-component="source">
143 <div class="md-source__icon md-icon">
144
145 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
146 </div>
147 <div class="md-source__repository">
148 GitHub
149 </div>
150 </a>
151 </div>
152
153 </nav>
154 </header>
155
156 <div class="md-container" data-md-component="container">
157
158
159
160
161 <main class="md-main" data-md-component="main">
162 <div class="md-main__inner md-grid">
163
164
165
166 <div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
167 <div class="md-sidebar__scrollwrap">
168 <div class="md-sidebar__inner">
169
170
171
172 <nav class="md-nav md-nav--primary" aria-label="Navigation" data-md-level="0">
173 <label class="md-nav__title" for="__drawer">
174 <a href="../../.." title="WoltLab Suite Documentation" class="md-nav__button md-logo" aria-label="WoltLab Suite Documentation" data-md-component="logo">
175
176 <img src="../../../assets/logo.png" alt="logo">
177
178 </a>
179 WoltLab Suite Documentation
180 </label>
181
182 <div class="md-nav__source">
183
184 <a href="https://github.com/WoltLab/docs.woltlab.com/" title="Go to repository" class="md-source" data-md-component="source">
185 <div class="md-source__icon md-icon">
186
187 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
188 </div>
189 <div class="md-source__repository">
190 GitHub
191 </div>
192 </a>
193 </div>
194
195 <ul class="md-nav__list" data-md-scrollfix>
196
197
198
199
200
201
202
203
204 <li class="md-nav__item">
205 <a href="../../../getting-started/" class="md-nav__link">
206 Getting Started
207 </a>
208 </li>
209
210
211
212
213
214
215
216
217
218
219
220 <li class="md-nav__item md-nav__item--nested">
221
222
223 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2" type="checkbox" id="__nav_2" >
224
225 <label class="md-nav__link" for="__nav_2">
226 PHP API
227 <span class="md-nav__icon md-icon"></span>
228 </label>
229 <nav class="md-nav" aria-label="PHP API" data-md-level="1">
230 <label class="md-nav__title" for="__nav_2">
231 <span class="md-nav__icon md-icon"></span>
232 PHP API
233 </label>
234 <ul class="md-nav__list" data-md-scrollfix>
235
236
237
238
239
240 <li class="md-nav__item">
241 <a href="../../../php/pages/" class="md-nav__link">
242 Pages
243 </a>
244 </li>
245
246
247
248
249
250
251
252 <li class="md-nav__item">
253 <a href="../../../php/database-objects/" class="md-nav__link">
254 Database Objects
255 </a>
256 </li>
257
258
259
260
261
262
263
264 <li class="md-nav__item">
265 <a href="../../../php/database-access/" class="md-nav__link">
266 Database Access
267 </a>
268 </li>
269
270
271
272
273
274
275
276 <li class="md-nav__item">
277 <a href="../../../php/exceptions/" class="md-nav__link">
278 Exceptions
279 </a>
280 </li>
281
282
283
284
285
286
287
288
289 <li class="md-nav__item md-nav__item--nested">
290
291
292 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2_5" type="checkbox" id="__nav_2_5" >
293
294 <label class="md-nav__link" for="__nav_2_5">
295 API
296 <span class="md-nav__icon md-icon"></span>
297 </label>
298 <nav class="md-nav" aria-label="API" data-md-level="2">
299 <label class="md-nav__title" for="__nav_2_5">
300 <span class="md-nav__icon md-icon"></span>
301 API
302 </label>
303 <ul class="md-nav__list" data-md-scrollfix>
304
305
306
307
308
309
310 <li class="md-nav__item md-nav__item--nested">
311
312
313 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2_5_1" type="checkbox" id="__nav_2_5_1" >
314
315 <label class="md-nav__link" for="__nav_2_5_1">
316 Caches
317 <span class="md-nav__icon md-icon"></span>
318 </label>
319 <nav class="md-nav" aria-label="Caches" data-md-level="3">
320 <label class="md-nav__title" for="__nav_2_5_1">
321 <span class="md-nav__icon md-icon"></span>
322 Caches
323 </label>
324 <ul class="md-nav__list" data-md-scrollfix>
325
326
327
328
329
330 <li class="md-nav__item">
331 <a href="../../../php/api/caches/" class="md-nav__link">
332 Overview
333 </a>
334 </li>
335
336
337
338
339
340
341
342 <li class="md-nav__item">
343 <a href="../../../php/api/caches_persistent-caches/" class="md-nav__link">
344 Persistent Caches
345 </a>
346 </li>
347
348
349
350
351
352
353
354 <li class="md-nav__item">
355 <a href="../../../php/api/caches_runtime-caches/" class="md-nav__link">
356 Runtime Caches
357 </a>
358 </li>
359
360
361
362 </ul>
363 </nav>
364 </li>
365
366
367
368
369
370
371
372 <li class="md-nav__item">
373 <a href="../../../php/api/comments/" class="md-nav__link">
374 Comments
375 </a>
376 </li>
377
378
379
380
381
382
383
384 <li class="md-nav__item">
385 <a href="../../../php/api/cronjobs/" class="md-nav__link">
386 Cronjobs
387 </a>
388 </li>
389
390
391
392
393
394
395
396 <li class="md-nav__item">
397 <a href="../../../php/api/events/" class="md-nav__link">
398 Events
399 </a>
400 </li>
401
402
403
404
405
406
407
408
409 <li class="md-nav__item md-nav__item--nested">
410
411
412 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_2_5_5" type="checkbox" id="__nav_2_5_5" >
413
414 <label class="md-nav__link" for="__nav_2_5_5">
415 Form Builder
416 <span class="md-nav__icon md-icon"></span>
417 </label>
418 <nav class="md-nav" aria-label="Form Builder" data-md-level="3">
419 <label class="md-nav__title" for="__nav_2_5_5">
420 <span class="md-nav__icon md-icon"></span>
421 Form Builder
422 </label>
423 <ul class="md-nav__list" data-md-scrollfix>
424
425
426
427
428
429 <li class="md-nav__item">
430 <a href="../../../php/api/form_builder/overview/" class="md-nav__link">
431 Overview
432 </a>
433 </li>
434
435
436
437
438
439
440
441 <li class="md-nav__item">
442 <a href="../../../php/api/form_builder/structure/" class="md-nav__link">
443 Structure
444 </a>
445 </li>
446
447
448
449
450
451
452
453 <li class="md-nav__item">
454 <a href="../../../php/api/form_builder/form_fields/" class="md-nav__link">
455 Fields
456 </a>
457 </li>
458
459
460
461
462
463
464
465 <li class="md-nav__item">
466 <a href="../../../php/api/form_builder/validation_data/" class="md-nav__link">
467 Validation and Data
468 </a>
469 </li>
470
471
472
473
474
475
476
477 <li class="md-nav__item">
478 <a href="../../../php/api/form_builder/dependencies/" class="md-nav__link">
479 Dependencies
480 </a>
481 </li>
482
483
484
485 </ul>
486 </nav>
487 </li>
488
489
490
491
492
493
494
495 <li class="md-nav__item">
496 <a href="../../../php/api/package_installation_plugins/" class="md-nav__link">
497 Package Installation Plugins
498 </a>
499 </li>
500
501
502
503
504
505
506
507 <li class="md-nav__item">
508 <a href="../../../php/api/user_activity_points/" class="md-nav__link">
509 User Activity Points
510 </a>
511 </li>
512
513
514
515
516
517
518
519 <li class="md-nav__item">
520 <a href="../../../php/api/user_notifications/" class="md-nav__link">
521 User Notifications
522 </a>
523 </li>
524
525
526
527
528
529
530
531 <li class="md-nav__item">
532 <a href="../../../php/api/sitemaps/" class="md-nav__link">
533 Sitemaps
534 </a>
535 </li>
536
537
538
539 </ul>
540 </nav>
541 </li>
542
543
544
545
546
547
548
549 <li class="md-nav__item">
550 <a href="../../../php/code-style/" class="md-nav__link">
551 Code Style
552 </a>
553 </li>
554
555
556
557
558
559
560
561 <li class="md-nav__item">
562 <a href="../../../php/apps/" class="md-nav__link">
563 Apps
564 </a>
565 </li>
566
567
568
569
570
571
572
573 <li class="md-nav__item">
574 <a href="../../../php/gdpr/" class="md-nav__link">
575 GDPR
576 </a>
577 </li>
578
579
580
581 </ul>
582 </nav>
583 </li>
584
585
586
587
588
589
590
591
592
593
594
595 <li class="md-nav__item md-nav__item--nested">
596
597
598 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_3" type="checkbox" id="__nav_3" >
599
600 <label class="md-nav__link" for="__nav_3">
601 Languages, Templates & CSS
602 <span class="md-nav__icon md-icon"></span>
603 </label>
604 <nav class="md-nav" aria-label="Languages, Templates & CSS" data-md-level="1">
605 <label class="md-nav__title" for="__nav_3">
606 <span class="md-nav__icon md-icon"></span>
607 Languages, Templates & CSS
608 </label>
609 <ul class="md-nav__list" data-md-scrollfix>
610
611
612
613
614
615 <li class="md-nav__item">
616 <a href="../../../view/languages/" class="md-nav__link">
617 Languages
618 </a>
619 </li>
620
621
622
623
624
625
626
627 <li class="md-nav__item">
628 <a href="../../../view/templates/" class="md-nav__link">
629 Templates
630 </a>
631 </li>
632
633
634
635
636
637
638
639 <li class="md-nav__item">
640 <a href="../../../view/template-plugins/" class="md-nav__link">
641 Template Plugins
642 </a>
643 </li>
644
645
646
647
648
649
650
651 <li class="md-nav__item">
652 <a href="../../../view/css/" class="md-nav__link">
653 CSS
654 </a>
655 </li>
656
657
658
659 </ul>
660 </nav>
661 </li>
662
663
664
665
666
667
668
669
670
671
672
673 <li class="md-nav__item md-nav__item--nested">
674
675
676 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_4" type="checkbox" id="__nav_4" >
677
678 <label class="md-nav__link" for="__nav_4">
679 TypeScript and JavaScript API
680 <span class="md-nav__icon md-icon"></span>
681 </label>
682 <nav class="md-nav" aria-label="TypeScript and JavaScript API" data-md-level="1">
683 <label class="md-nav__title" for="__nav_4">
684 <span class="md-nav__icon md-icon"></span>
685 TypeScript and JavaScript API
686 </label>
687 <ul class="md-nav__list" data-md-scrollfix>
688
689
690
691
692
693 <li class="md-nav__item">
694 <a href="../../../javascript/general-usage/" class="md-nav__link">
695 General Usage
696 </a>
697 </li>
698
699
700
701
702
703
704
705 <li class="md-nav__item">
706 <a href="../../../javascript/typescript/" class="md-nav__link">
707 TypeScript
708 </a>
709 </li>
710
711
712
713
714
715
716
717
718 <li class="md-nav__item md-nav__item--nested">
719
720
721 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_4_3" type="checkbox" id="__nav_4_3" >
722
723 <label class="md-nav__link" for="__nav_4_3">
724 New API
725 <span class="md-nav__icon md-icon"></span>
726 </label>
727 <nav class="md-nav" aria-label="New API" data-md-level="2">
728 <label class="md-nav__title" for="__nav_4_3">
729 <span class="md-nav__icon md-icon"></span>
730 New API
731 </label>
732 <ul class="md-nav__list" data-md-scrollfix>
733
734
735
736
737
738 <li class="md-nav__item">
739 <a href="../../../javascript/new-api_writing-a-module/" class="md-nav__link">
740 Writing a module
741 </a>
742 </li>
743
744
745
746
747
748
749
750 <li class="md-nav__item">
751 <a href="../../../javascript/new-api_data-structures/" class="md-nav__link">
752 Data Structures
753 </a>
754 </li>
755
756
757
758
759
760
761
762 <li class="md-nav__item">
763 <a href="../../../javascript/new-api_core/" class="md-nav__link">
764 Core Functions
765 </a>
766 </li>
767
768
769
770
771
772
773
774 <li class="md-nav__item">
775 <a href="../../../javascript/new-api_dom/" class="md-nav__link">
776 DOM
777 </a>
778 </li>
779
780
781
782
783
784
785
786 <li class="md-nav__item">
787 <a href="../../../javascript/new-api_events/" class="md-nav__link">
788 Event Handling
789 </a>
790 </li>
791
792
793
794
795
796
797
798 <li class="md-nav__item">
799 <a href="../../../javascript/new-api_ajax/" class="md-nav__link">
800 Ajax
801 </a>
802 </li>
803
804
805
806
807
808
809
810 <li class="md-nav__item">
811 <a href="../../../javascript/new-api_dialogs/" class="md-nav__link">
812 Dialogs
813 </a>
814 </li>
815
816
817
818
819
820
821
822 <li class="md-nav__item">
823 <a href="../../../javascript/new-api_browser/" class="md-nav__link">
824 Browser and Screen Sizes
825 </a>
826 </li>
827
828
829
830
831
832
833
834 <li class="md-nav__item">
835 <a href="../../../javascript/new-api_ui/" class="md-nav__link">
836 User Interface
837 </a>
838 </li>
839
840
841
842 </ul>
843 </nav>
844 </li>
845
846
847
848
849
850
851
852 <li class="md-nav__item">
853 <a href="../../../javascript/legacy-api/" class="md-nav__link">
854 Legacy API
855 </a>
856 </li>
857
858
859
860
861
862
863
864 <li class="md-nav__item">
865 <a href="../../../javascript/helper-functions/" class="md-nav__link">
866 Helper Functions
867 </a>
868 </li>
869
870
871
872
873
874
875
876 <li class="md-nav__item">
877 <a href="../../../javascript/code-snippets/" class="md-nav__link">
878 Code Snippets
879 </a>
880 </li>
881
882
883
884 </ul>
885 </nav>
886 </li>
887
888
889
890
891
892
893
894
895
896
897
898 <li class="md-nav__item md-nav__item--nested">
899
900
901 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_5" type="checkbox" id="__nav_5" >
902
903 <label class="md-nav__link" for="__nav_5">
904 Package Components
905 <span class="md-nav__icon md-icon"></span>
906 </label>
907 <nav class="md-nav" aria-label="Package Components" data-md-level="1">
908 <label class="md-nav__title" for="__nav_5">
909 <span class="md-nav__icon md-icon"></span>
910 Package Components
911 </label>
912 <ul class="md-nav__list" data-md-scrollfix>
913
914
915
916
917
918 <li class="md-nav__item">
919 <a href="../../../package/package-xml/" class="md-nav__link">
920 package.xml
921 </a>
922 </li>
923
924
925
926
927
928
929
930
931 <li class="md-nav__item md-nav__item--nested">
932
933
934 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_5_2" type="checkbox" id="__nav_5_2" >
935
936 <label class="md-nav__link" for="__nav_5_2">
937 PIPs
938 <span class="md-nav__icon md-icon"></span>
939 </label>
940 <nav class="md-nav" aria-label="PIPs" data-md-level="2">
941 <label class="md-nav__title" for="__nav_5_2">
942 <span class="md-nav__icon md-icon"></span>
943 PIPs
944 </label>
945 <ul class="md-nav__list" data-md-scrollfix>
946
947
948
949
950
951 <li class="md-nav__item">
952 <a href="../../../package/pip/" class="md-nav__link">
953 Overview
954 </a>
955 </li>
956
957
958
959
960
961
962
963 <li class="md-nav__item">
964 <a href="../../../package/pip/acl-option/" class="md-nav__link">
965 aclOption
966 </a>
967 </li>
968
969
970
971
972
973
974
975 <li class="md-nav__item">
976 <a href="../../../package/pip/acp-menu/" class="md-nav__link">
977 acpMenu
978 </a>
979 </li>
980
981
982
983
984
985
986
987 <li class="md-nav__item">
988 <a href="../../../package/pip/acp-search-provider/" class="md-nav__link">
989 acpSearchProvider
990 </a>
991 </li>
992
993
994
995
996
997
998
999 <li class="md-nav__item">
1000 <a href="../../../package/pip/acp-template/" class="md-nav__link">
1001 acpTemplate
1002 </a>
1003 </li>
1004
1005
1006
1007
1008
1009
1010
1011 <li class="md-nav__item">
1012 <a href="../../../package/pip/bbcode/" class="md-nav__link">
1013 bbcode
1014 </a>
1015 </li>
1016
1017
1018
1019
1020
1021
1022
1023 <li class="md-nav__item">
1024 <a href="../../../package/pip/box/" class="md-nav__link">
1025 box
1026 </a>
1027 </li>
1028
1029
1030
1031
1032
1033
1034
1035 <li class="md-nav__item">
1036 <a href="../../../package/pip/clipboard-action/" class="md-nav__link">
1037 clipboardAction
1038 </a>
1039 </li>
1040
1041
1042
1043
1044
1045
1046
1047 <li class="md-nav__item">
1048 <a href="../../../package/pip/core-object/" class="md-nav__link">
1049 coreObject
1050 </a>
1051 </li>
1052
1053
1054
1055
1056
1057
1058
1059 <li class="md-nav__item">
1060 <a href="../../../package/pip/cronjob/" class="md-nav__link">
1061 cronjob
1062 </a>
1063 </li>
1064
1065
1066
1067
1068
1069
1070
1071 <li class="md-nav__item">
1072 <a href="../../../package/pip/database/" class="md-nav__link">
1073 database
1074 </a>
1075 </li>
1076
1077
1078
1079
1080
1081
1082
1083 <li class="md-nav__item">
1084 <a href="../../../package/pip/event-listener/" class="md-nav__link">
1085 eventListener
1086 </a>
1087 </li>
1088
1089
1090
1091
1092
1093
1094
1095 <li class="md-nav__item">
1096 <a href="../../../package/pip/file/" class="md-nav__link">
1097 file
1098 </a>
1099 </li>
1100
1101
1102
1103
1104
1105
1106
1107 <li class="md-nav__item">
1108 <a href="../../../package/pip/language/" class="md-nav__link">
1109 language
1110 </a>
1111 </li>
1112
1113
1114
1115
1116
1117
1118
1119 <li class="md-nav__item">
1120 <a href="../../../package/pip/media-provider/" class="md-nav__link">
1121 mediaProvider
1122 </a>
1123 </li>
1124
1125
1126
1127
1128
1129
1130
1131 <li class="md-nav__item">
1132 <a href="../../../package/pip/menu/" class="md-nav__link">
1133 menu
1134 </a>
1135 </li>
1136
1137
1138
1139
1140
1141
1142
1143 <li class="md-nav__item">
1144 <a href="../../../package/pip/menu-item/" class="md-nav__link">
1145 menuItem
1146 </a>
1147 </li>
1148
1149
1150
1151
1152
1153
1154
1155 <li class="md-nav__item">
1156 <a href="../../../package/pip/object-type/" class="md-nav__link">
1157 objectType
1158 </a>
1159 </li>
1160
1161
1162
1163
1164
1165
1166
1167 <li class="md-nav__item">
1168 <a href="../../../package/pip/object-type-definition/" class="md-nav__link">
1169 objectTypeDefinition
1170 </a>
1171 </li>
1172
1173
1174
1175
1176
1177
1178
1179 <li class="md-nav__item">
1180 <a href="../../../package/pip/option/" class="md-nav__link">
1181 option
1182 </a>
1183 </li>
1184
1185
1186
1187
1188
1189
1190
1191 <li class="md-nav__item">
1192 <a href="../../../package/pip/page/" class="md-nav__link">
1193 page
1194 </a>
1195 </li>
1196
1197
1198
1199
1200
1201
1202
1203 <li class="md-nav__item">
1204 <a href="../../../package/pip/pip/" class="md-nav__link">
1205 pip
1206 </a>
1207 </li>
1208
1209
1210
1211
1212
1213
1214
1215 <li class="md-nav__item">
1216 <a href="../../../package/pip/script/" class="md-nav__link">
1217 script
1218 </a>
1219 </li>
1220
1221
1222
1223
1224
1225
1226
1227 <li class="md-nav__item">
1228 <a href="../../../package/pip/smiley/" class="md-nav__link">
1229 smiley
1230 </a>
1231 </li>
1232
1233
1234
1235
1236
1237
1238
1239 <li class="md-nav__item">
1240 <a href="../../../package/pip/sql/" class="md-nav__link">
1241 sql
1242 </a>
1243 </li>
1244
1245
1246
1247
1248
1249
1250
1251 <li class="md-nav__item">
1252 <a href="../../../package/pip/style/" class="md-nav__link">
1253 style
1254 </a>
1255 </li>
1256
1257
1258
1259
1260
1261
1262
1263 <li class="md-nav__item">
1264 <a href="../../../package/pip/template/" class="md-nav__link">
1265 template
1266 </a>
1267 </li>
1268
1269
1270
1271
1272
1273
1274
1275 <li class="md-nav__item">
1276 <a href="../../../package/pip/template-listener/" class="md-nav__link">
1277 templateListener
1278 </a>
1279 </li>
1280
1281
1282
1283
1284
1285
1286
1287 <li class="md-nav__item">
1288 <a href="../../../package/pip/user-group-option/" class="md-nav__link">
1289 userGroupOption
1290 </a>
1291 </li>
1292
1293
1294
1295
1296
1297
1298
1299 <li class="md-nav__item">
1300 <a href="../../../package/pip/user-menu/" class="md-nav__link">
1301 userMenu
1302 </a>
1303 </li>
1304
1305
1306
1307
1308
1309
1310
1311 <li class="md-nav__item">
1312 <a href="../../../package/pip/user-notification-event/" class="md-nav__link">
1313 userNotificationEvent
1314 </a>
1315 </li>
1316
1317
1318
1319
1320
1321
1322
1323 <li class="md-nav__item">
1324 <a href="../../../package/pip/user-option/" class="md-nav__link">
1325 userOption
1326 </a>
1327 </li>
1328
1329
1330
1331
1332
1333
1334
1335 <li class="md-nav__item">
1336 <a href="../../../package/pip/user-profile-menu/" class="md-nav__link">
1337 userProfileMenu
1338 </a>
1339 </li>
1340
1341
1342
1343 </ul>
1344 </nav>
1345 </li>
1346
1347
1348
1349
1350
1351
1352
1353 <li class="md-nav__item">
1354 <a href="../../../package/database-php-api/" class="md-nav__link">
1355 Database PHP API
1356 </a>
1357 </li>
1358
1359
1360
1361 </ul>
1362 </nav>
1363 </li>
1364
1365
1366
1367
1368
1369
1370
1371
1372
1373
1374
1375
1376
1377 <li class="md-nav__item md-nav__item--active md-nav__item--nested">
1378
1379
1380 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6" type="checkbox" id="__nav_6" checked>
1381
1382 <label class="md-nav__link" for="__nav_6">
1383 Migration
1384 <span class="md-nav__icon md-icon"></span>
1385 </label>
1386 <nav class="md-nav" aria-label="Migration" data-md-level="1">
1387 <label class="md-nav__title" for="__nav_6">
1388 <span class="md-nav__icon md-icon"></span>
1389 Migration
1390 </label>
1391 <ul class="md-nav__list" data-md-scrollfix>
1392
1393
1394
1395
1396
1397
1398
1399
1400 <li class="md-nav__item md-nav__item--active md-nav__item--nested">
1401
1402
1403 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_1" type="checkbox" id="__nav_6_1" checked>
1404
1405 <label class="md-nav__link" for="__nav_6_1">
1406 Migrating from WSC 5.3
1407 <span class="md-nav__icon md-icon"></span>
1408 </label>
1409 <nav class="md-nav" aria-label="Migrating from WSC 5.3" data-md-level="2">
1410 <label class="md-nav__title" for="__nav_6_1">
1411 <span class="md-nav__icon md-icon"></span>
1412 Migrating from WSC 5.3
1413 </label>
1414 <ul class="md-nav__list" data-md-scrollfix>
1415
1416
1417
1418
1419
1420 <li class="md-nav__item">
1421 <a href="../php/" class="md-nav__link">
1422 PHP API
1423 </a>
1424 </li>
1425
1426
1427
1428
1429
1430
1431
1432
1433
1434 <li class="md-nav__item md-nav__item--active">
1435
1436 <input class="md-nav__toggle md-toggle" data-md-toggle="toc" type="checkbox" id="__toc">
1437
1438
1439
1440
1441 <label class="md-nav__link md-nav__link--active" for="__toc">
1442 Session Handling and Authentication
1443 <span class="md-nav__icon md-icon"></span>
1444 </label>
1445
1446 <a href="./" class="md-nav__link md-nav__link--active">
1447 Session Handling and Authentication
1448 </a>
1449
1450
1451 <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
1452
1453
1454
1455
1456
1457 <label class="md-nav__title" for="__toc">
1458 <span class="md-nav__icon md-icon"></span>
1459 Table of contents
1460 </label>
1461 <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
1462
1463 <li class="md-nav__item">
1464 <a href="#summary-and-concepts" class="md-nav__link">
1465 Summary and Concepts
1466 </a>
1467
1468 <nav class="md-nav" aria-label="Summary and Concepts">
1469 <ul class="md-nav__list">
1470
1471 <li class="md-nav__item">
1472 <a href="#legacy-persistent-login" class="md-nav__link">
1473 Legacy Persistent Login
1474 </a>
1475
1476 </li>
1477
1478 <li class="md-nav__item">
1479 <a href="#multiple-sessions" class="md-nav__link">
1480 Multiple Sessions
1481 </a>
1482
1483 </li>
1484
1485 <li class="md-nav__item">
1486 <a href="#merged-acp-and-frontend-sessions" class="md-nav__link">
1487 Merged ACP and Frontend Sessions
1488 </a>
1489
1490 </li>
1491
1492 <li class="md-nav__item">
1493 <a href="#improved-authentication-and-reauthentication" class="md-nav__link">
1494 Improved Authentication and Reauthentication
1495 </a>
1496
1497 </li>
1498
1499 </ul>
1500 </nav>
1501
1502 </li>
1503
1504 <li class="md-nav__item">
1505 <a href="#additions-and-changes" class="md-nav__link">
1506 Additions and Changes
1507 </a>
1508
1509 <nav class="md-nav" aria-label="Additions and Changes">
1510 <ul class="md-nav__list">
1511
1512 <li class="md-nav__item">
1513 <a href="#password-hashing" class="md-nav__link">
1514 Password Hashing
1515 </a>
1516
1517 </li>
1518
1519 <li class="md-nav__item">
1520 <a href="#session-storage" class="md-nav__link">
1521 Session Storage
1522 </a>
1523
1524 </li>
1525
1526 <li class="md-nav__item">
1527 <a href="#reauthentication" class="md-nav__link">
1528 Reauthentication
1529 </a>
1530
1531 </li>
1532
1533 <li class="md-nav__item">
1534 <a href="#multi-factor-authentication" class="md-nav__link">
1535 Multi-factor Authentication
1536 </a>
1537
1538 <nav class="md-nav" aria-label="Multi-factor Authentication">
1539 <ul class="md-nav__list">
1540
1541 <li class="md-nav__item">
1542 <a href="#adding-multi-factor-methods" class="md-nav__link">
1543 Adding Multi-factor Methods
1544 </a>
1545
1546 </li>
1547
1548 </ul>
1549 </nav>
1550
1551 </li>
1552
1553 </ul>
1554 </nav>
1555
1556 </li>
1557
1558 <li class="md-nav__item">
1559 <a href="#deprecations-and-removals" class="md-nav__link">
1560 Deprecations and Removals
1561 </a>
1562
1563 <nav class="md-nav" aria-label="Deprecations and Removals">
1564 <ul class="md-nav__list">
1565
1566 <li class="md-nav__item">
1567 <a href="#sessionhandler" class="md-nav__link">
1568 SessionHandler
1569 </a>
1570
1571 </li>
1572
1573 <li class="md-nav__item">
1574 <a href="#acp-sessions" class="md-nav__link">
1575 ACP Sessions
1576 </a>
1577
1578 </li>
1579
1580 <li class="md-nav__item">
1581 <a href="#cookies" class="md-nav__link">
1582 Cookies
1583 </a>
1584
1585 </li>
1586
1587 <li class="md-nav__item">
1588 <a href="#virtual-sessions" class="md-nav__link">
1589 Virtual Sessions
1590 </a>
1591
1592 </li>
1593
1594 <li class="md-nav__item">
1595 <a href="#security-token-constants" class="md-nav__link">
1596 Security Token Constants
1597 </a>
1598
1599 </li>
1600
1601 <li class="md-nav__item">
1602 <a href="#passwordutil-and-double-bcrypt-hashes" class="md-nav__link">
1603 PasswordUtil and Double BCrypt Hashes
1604 </a>
1605
1606 </li>
1607
1608 </ul>
1609 </nav>
1610
1611 </li>
1612
1613 </ul>
1614
1615 </nav>
1616
1617 </li>
1618
1619
1620
1621
1622
1623
1624
1625 <li class="md-nav__item">
1626 <a href="../javascript/" class="md-nav__link">
1627 TypeScript and JavaScript
1628 </a>
1629 </li>
1630
1631
1632
1633
1634
1635
1636
1637 <li class="md-nav__item">
1638 <a href="../templates/" class="md-nav__link">
1639 Templates
1640 </a>
1641 </li>
1642
1643
1644
1645
1646
1647
1648
1649 <li class="md-nav__item">
1650 <a href="../libraries/" class="md-nav__link">
1651 Third Party Libraries
1652 </a>
1653 </li>
1654
1655
1656
1657 </ul>
1658 </nav>
1659 </li>
1660
1661
1662
1663
1664
1665
1666
1667
1668 <li class="md-nav__item md-nav__item--nested">
1669
1670
1671 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_2" type="checkbox" id="__nav_6_2" >
1672
1673 <label class="md-nav__link" for="__nav_6_2">
1674 Migrating from WSC 5.2
1675 <span class="md-nav__icon md-icon"></span>
1676 </label>
1677 <nav class="md-nav" aria-label="Migrating from WSC 5.2" data-md-level="2">
1678 <label class="md-nav__title" for="__nav_6_2">
1679 <span class="md-nav__icon md-icon"></span>
1680 Migrating from WSC 5.2
1681 </label>
1682 <ul class="md-nav__list" data-md-scrollfix>
1683
1684
1685
1686
1687
1688 <li class="md-nav__item">
1689 <a href="../../wsc52/php/" class="md-nav__link">
1690 PHP API
1691 </a>
1692 </li>
1693
1694
1695
1696
1697
1698
1699
1700 <li class="md-nav__item">
1701 <a href="../../wsc52/templates/" class="md-nav__link">
1702 Templates and Languages
1703 </a>
1704 </li>
1705
1706
1707
1708
1709
1710
1711
1712 <li class="md-nav__item">
1713 <a href="../../wsc52/libraries/" class="md-nav__link">
1714 Third Party Libraries
1715 </a>
1716 </li>
1717
1718
1719
1720 </ul>
1721 </nav>
1722 </li>
1723
1724
1725
1726
1727
1728
1729
1730
1731 <li class="md-nav__item md-nav__item--nested">
1732
1733
1734 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_3" type="checkbox" id="__nav_6_3" >
1735
1736 <label class="md-nav__link" for="__nav_6_3">
1737 Migrating from WSC 3.1
1738 <span class="md-nav__icon md-icon"></span>
1739 </label>
1740 <nav class="md-nav" aria-label="Migrating from WSC 3.1" data-md-level="2">
1741 <label class="md-nav__title" for="__nav_6_3">
1742 <span class="md-nav__icon md-icon"></span>
1743 Migrating from WSC 3.1
1744 </label>
1745 <ul class="md-nav__list" data-md-scrollfix>
1746
1747
1748
1749
1750
1751 <li class="md-nav__item">
1752 <a href="../../wsc31/php/" class="md-nav__link">
1753 PHP API
1754 </a>
1755 </li>
1756
1757
1758
1759 </ul>
1760 </nav>
1761 </li>
1762
1763
1764
1765
1766
1767
1768
1769
1770 <li class="md-nav__item md-nav__item--nested">
1771
1772
1773 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_4" type="checkbox" id="__nav_6_4" >
1774
1775 <label class="md-nav__link" for="__nav_6_4">
1776 Migrating from WSC 3.0
1777 <span class="md-nav__icon md-icon"></span>
1778 </label>
1779 <nav class="md-nav" aria-label="Migrating from WSC 3.0" data-md-level="2">
1780 <label class="md-nav__title" for="__nav_6_4">
1781 <span class="md-nav__icon md-icon"></span>
1782 Migrating from WSC 3.0
1783 </label>
1784 <ul class="md-nav__list" data-md-scrollfix>
1785
1786
1787
1788
1789
1790 <li class="md-nav__item">
1791 <a href="../../wsc30/php/" class="md-nav__link">
1792 PHP API
1793 </a>
1794 </li>
1795
1796
1797
1798
1799
1800
1801
1802 <li class="md-nav__item">
1803 <a href="../../wsc30/javascript/" class="md-nav__link">
1804 JavaScript API
1805 </a>
1806 </li>
1807
1808
1809
1810
1811
1812
1813
1814 <li class="md-nav__item">
1815 <a href="../../wsc30/templates/" class="md-nav__link">
1816 Templates
1817 </a>
1818 </li>
1819
1820
1821
1822
1823
1824
1825
1826 <li class="md-nav__item">
1827 <a href="../../wsc30/css/" class="md-nav__link">
1828 CSS
1829 </a>
1830 </li>
1831
1832
1833
1834
1835
1836
1837
1838 <li class="md-nav__item">
1839 <a href="../../wsc30/package/" class="md-nav__link">
1840 Package Components
1841 </a>
1842 </li>
1843
1844
1845
1846 </ul>
1847 </nav>
1848 </li>
1849
1850
1851
1852
1853
1854
1855
1856
1857 <li class="md-nav__item md-nav__item--nested">
1858
1859
1860 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_6_5" type="checkbox" id="__nav_6_5" >
1861
1862 <label class="md-nav__link" for="__nav_6_5">
1863 Migrating from WCF 2.1
1864 <span class="md-nav__icon md-icon"></span>
1865 </label>
1866 <nav class="md-nav" aria-label="Migrating from WCF 2.1" data-md-level="2">
1867 <label class="md-nav__title" for="__nav_6_5">
1868 <span class="md-nav__icon md-icon"></span>
1869 Migrating from WCF 2.1
1870 </label>
1871 <ul class="md-nav__list" data-md-scrollfix>
1872
1873
1874
1875
1876
1877 <li class="md-nav__item">
1878 <a href="../../wcf21/php/" class="md-nav__link">
1879 PHP API
1880 </a>
1881 </li>
1882
1883
1884
1885
1886
1887
1888
1889 <li class="md-nav__item">
1890 <a href="../../wcf21/templates/" class="md-nav__link">
1891 Templates
1892 </a>
1893 </li>
1894
1895
1896
1897
1898
1899
1900
1901 <li class="md-nav__item">
1902 <a href="../../wcf21/css/" class="md-nav__link">
1903 CSS
1904 </a>
1905 </li>
1906
1907
1908
1909
1910
1911
1912
1913 <li class="md-nav__item">
1914 <a href="../../wcf21/package/" class="md-nav__link">
1915 Package Components
1916 </a>
1917 </li>
1918
1919
1920
1921 </ul>
1922 </nav>
1923 </li>
1924
1925
1926
1927 </ul>
1928 </nav>
1929 </li>
1930
1931
1932
1933
1934
1935
1936
1937
1938
1939
1940
1941 <li class="md-nav__item md-nav__item--nested">
1942
1943
1944 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_7" type="checkbox" id="__nav_7" >
1945
1946 <label class="md-nav__link" for="__nav_7">
1947 Tutorials
1948 <span class="md-nav__icon md-icon"></span>
1949 </label>
1950 <nav class="md-nav" aria-label="Tutorials" data-md-level="1">
1951 <label class="md-nav__title" for="__nav_7">
1952 <span class="md-nav__icon md-icon"></span>
1953 Tutorials
1954 </label>
1955 <ul class="md-nav__list" data-md-scrollfix>
1956
1957
1958
1959
1960
1961
1962 <li class="md-nav__item md-nav__item--nested">
1963
1964
1965 <input class="md-nav__toggle md-toggle" data-md-toggle="__nav_7_1" type="checkbox" id="__nav_7_1" >
1966
1967 <label class="md-nav__link" for="__nav_7_1">
1968 Tutorial Series
1969 <span class="md-nav__icon md-icon"></span>
1970 </label>
1971 <nav class="md-nav" aria-label="Tutorial Series" data-md-level="2">
1972 <label class="md-nav__title" for="__nav_7_1">
1973 <span class="md-nav__icon md-icon"></span>
1974 Tutorial Series
1975 </label>
1976 <ul class="md-nav__list" data-md-scrollfix>
1977
1978
1979
1980
1981
1982 <li class="md-nav__item">
1983 <a href="../../../tutorial/series/overview/" class="md-nav__link">
1984 Overview
1985 </a>
1986 </li>
1987
1988
1989
1990
1991
1992
1993
1994 <li class="md-nav__item">
1995 <a href="../../../tutorial/series/part_1/" class="md-nav__link">
1996 Part 1
1997 </a>
1998 </li>
1999
2000
2001
2002
2003
2004
2005
2006 <li class="md-nav__item">
2007 <a href="../../../tutorial/series/part_2/" class="md-nav__link">
2008 Part 2
2009 </a>
2010 </li>
2011
2012
2013
2014
2015
2016
2017
2018 <li class="md-nav__item">
2019 <a href="../../../tutorial/series/part_3/" class="md-nav__link">
2020 Part 3
2021 </a>
2022 </li>
2023
2024
2025
2026 </ul>
2027 </nav>
2028 </li>
2029
2030
2031
2032 </ul>
2033 </nav>
2034 </li>
2035
2036
2037
2038 </ul>
2039 </nav>
2040 </div>
2041 </div>
2042 </div>
2043
2044
2045
2046 <div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
2047 <div class="md-sidebar__scrollwrap">
2048 <div class="md-sidebar__inner">
2049
2050 <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
2051
2052
2053
2054
2055
2056 <label class="md-nav__title" for="__toc">
2057 <span class="md-nav__icon md-icon"></span>
2058 Table of contents
2059 </label>
2060 <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
2061
2062 <li class="md-nav__item">
2063 <a href="#summary-and-concepts" class="md-nav__link">
2064 Summary and Concepts
2065 </a>
2066
2067 <nav class="md-nav" aria-label="Summary and Concepts">
2068 <ul class="md-nav__list">
2069
2070 <li class="md-nav__item">
2071 <a href="#legacy-persistent-login" class="md-nav__link">
2072 Legacy Persistent Login
2073 </a>
2074
2075 </li>
2076
2077 <li class="md-nav__item">
2078 <a href="#multiple-sessions" class="md-nav__link">
2079 Multiple Sessions
2080 </a>
2081
2082 </li>
2083
2084 <li class="md-nav__item">
2085 <a href="#merged-acp-and-frontend-sessions" class="md-nav__link">
2086 Merged ACP and Frontend Sessions
2087 </a>
2088
2089 </li>
2090
2091 <li class="md-nav__item">
2092 <a href="#improved-authentication-and-reauthentication" class="md-nav__link">
2093 Improved Authentication and Reauthentication
2094 </a>
2095
2096 </li>
2097
2098 </ul>
2099 </nav>
2100
2101 </li>
2102
2103 <li class="md-nav__item">
2104 <a href="#additions-and-changes" class="md-nav__link">
2105 Additions and Changes
2106 </a>
2107
2108 <nav class="md-nav" aria-label="Additions and Changes">
2109 <ul class="md-nav__list">
2110
2111 <li class="md-nav__item">
2112 <a href="#password-hashing" class="md-nav__link">
2113 Password Hashing
2114 </a>
2115
2116 </li>
2117
2118 <li class="md-nav__item">
2119 <a href="#session-storage" class="md-nav__link">
2120 Session Storage
2121 </a>
2122
2123 </li>
2124
2125 <li class="md-nav__item">
2126 <a href="#reauthentication" class="md-nav__link">
2127 Reauthentication
2128 </a>
2129
2130 </li>
2131
2132 <li class="md-nav__item">
2133 <a href="#multi-factor-authentication" class="md-nav__link">
2134 Multi-factor Authentication
2135 </a>
2136
2137 <nav class="md-nav" aria-label="Multi-factor Authentication">
2138 <ul class="md-nav__list">
2139
2140 <li class="md-nav__item">
2141 <a href="#adding-multi-factor-methods" class="md-nav__link">
2142 Adding Multi-factor Methods
2143 </a>
2144
2145 </li>
2146
2147 </ul>
2148 </nav>
2149
2150 </li>
2151
2152 </ul>
2153 </nav>
2154
2155 </li>
2156
2157 <li class="md-nav__item">
2158 <a href="#deprecations-and-removals" class="md-nav__link">
2159 Deprecations and Removals
2160 </a>
2161
2162 <nav class="md-nav" aria-label="Deprecations and Removals">
2163 <ul class="md-nav__list">
2164
2165 <li class="md-nav__item">
2166 <a href="#sessionhandler" class="md-nav__link">
2167 SessionHandler
2168 </a>
2169
2170 </li>
2171
2172 <li class="md-nav__item">
2173 <a href="#acp-sessions" class="md-nav__link">
2174 ACP Sessions
2175 </a>
2176
2177 </li>
2178
2179 <li class="md-nav__item">
2180 <a href="#cookies" class="md-nav__link">
2181 Cookies
2182 </a>
2183
2184 </li>
2185
2186 <li class="md-nav__item">
2187 <a href="#virtual-sessions" class="md-nav__link">
2188 Virtual Sessions
2189 </a>
2190
2191 </li>
2192
2193 <li class="md-nav__item">
2194 <a href="#security-token-constants" class="md-nav__link">
2195 Security Token Constants
2196 </a>
2197
2198 </li>
2199
2200 <li class="md-nav__item">
2201 <a href="#passwordutil-and-double-bcrypt-hashes" class="md-nav__link">
2202 PasswordUtil and Double BCrypt Hashes
2203 </a>
2204
2205 </li>
2206
2207 </ul>
2208 </nav>
2209
2210 </li>
2211
2212 </ul>
2213
2214 </nav>
2215 </div>
2216 </div>
2217 </div>
2218
2219
2220 <div class="md-content" data-md-component="content">
2221 <article class="md-content__inner md-typeset">
2222
2223
2224 <a href="https://github.com/WoltLab/docs.woltlab.com/edit/5.4/docs/migration/wsc53/session.md" title="Edit this page" class="md-content__button md-icon">
2225 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20.71 7.04c.39-.39.39-1.04 0-1.41l-2.34-2.34c-.37-.39-1.02-.39-1.41 0l-1.84 1.83 3.75 3.75M3 17.25V21h3.75L17.81 9.93l-3.75-3.75L3 17.25z"/></svg>
2226 </a>
2227
2228
2229 <h1 id="migrating-from-wsc-53-session-handling-and-authentication">Migrating from WSC 5.3 - Session Handling and Authentication<a class="headerlink" href="#migrating-from-wsc-53-session-handling-and-authentication" title="Permanent link">#</a></h1>
2230 <p>WoltLab Suite 5.4 includes a completely refactored session handling.
2231 As long as you only interact with sessions via <code>WCF::getSession()</code>, especially when you perform read-only accesses, you should not notice any breaking changes.</p>
2232 <p>You might appreciate some of the new session methods if you process security sensitive data.</p>
2233 <h2 id="summary-and-concepts">Summary and Concepts<a class="headerlink" href="#summary-and-concepts" title="Permanent link">#</a></h2>
2234 <p>Most of the changes revolve around the removal of the legacy persistent login functionality and the assumption that every user has a single session only.
2235 Both aspects are related to each other.</p>
2236 <h3 id="legacy-persistent-login">Legacy Persistent Login<a class="headerlink" href="#legacy-persistent-login" title="Permanent link">#</a></h3>
2237 <p>The legacy persistent login was rather an automated login.
2238 Upon bootstrapping a session, it was checked whether the user had a cookie pair storing the user’s <code>userID</code> and (a single BCrypt hash of) the user’s password.
2239 If such a cookie pair exists and the BCrypt hash within the cookie matches the user’s password hash when hashed again, the session would immediately <code>changeUser()</code> to the respective user.</p>
2240 <p>This legacy persistent login was completely removed.
2241 Instead, any sessions that belong to an authenticated user will automatically be long-lived.
2242 These long-lived sessions expire no sooner than 14 days after the last activity, ensuring that the user continously stays logged in, provided that they visit the page at least once per fortnight.</p>
2243 <h3 id="multiple-sessions">Multiple Sessions<a class="headerlink" href="#multiple-sessions" title="Permanent link">#</a></h3>
2244 <p>To allow for a proper separation of these long-lived user sessions, WoltLab Suite now allows for multiple sessions per user.
2245 These sessions are completely unrelated to each other.
2246 Specifically, they do not share session variables and they expire independently.</p>
2247 <p>As the existing <code>wcf1_session</code> table is also used for the online lists and location tracking, it will be maintained on a best effort basis.
2248 It no longer stores any private session data.</p>
2249 <p>The actual sessions storing security sensitive information are in an unrelated location.
2250 They must only be accessed via the PHP API exposed by the <code>SessionHandler</code>.</p>
2251 <h3 id="merged-acp-and-frontend-sessions">Merged ACP and Frontend Sessions<a class="headerlink" href="#merged-acp-and-frontend-sessions" title="Permanent link">#</a></h3>
2252 <p>WoltLab Suite 5.4 shares a single session across both the frontend, as well as the ACP.
2253 When a user logs in to the frontend, they will also be logged into the ACP and vice versa.</p>
2254 <p>Actual access to the ACP is controlled via the new <a href="#reauthentication">reauthentication mechanism</a>.</p>
2255 <p>The session variable store is scoped:
2256 Session variables set within the frontend are not available within the ACP and vice versa.</p>
2257 <h3 id="improved-authentication-and-reauthentication">Improved Authentication and Reauthentication<a class="headerlink" href="#improved-authentication-and-reauthentication" title="Permanent link">#</a></h3>
2258 <p>WoltLab Suite 5.4 ships with multi-factor authentication support and a generic re-authentication implementation that can be used to verify the account owner’s presence.</p>
2259 <h2 id="additions-and-changes">Additions and Changes<a class="headerlink" href="#additions-and-changes" title="Permanent link">#</a></h2>
2260 <h3 id="password-hashing">Password Hashing<a class="headerlink" href="#password-hashing" title="Permanent link">#</a></h3>
2261 <p>WoltLab Suite 5.4 includes a new object-oriented password hashing framework that is modeled after PHP’s <code>password_*</code> API.
2262 Check <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/authentication/password/PasswordAlgorithmManager.class.php"><code>PasswordAlgorithmManager</code></a> and <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/authentication/password/IPasswordAlgorithm.class.php"><code>IPasswordAlgorithm</code></a> for details.</p>
2263 <p>The new default password hash is a standard BCrypt hash.
2264 All newly generated hashes in <code>wcf1_user.password</code> will now include a type prefix, instead of just passwords imported from other systems.</p>
2265 <h3 id="session-storage">Session Storage<a class="headerlink" href="#session-storage" title="Permanent link">#</a></h3>
2266 <p>The <code>wcf1_session</code> table will no longer be used for session storage.
2267 Instead, it is maintained for compatibility with existing online lists.</p>
2268 <p>The actual session storage is considered an implementation detail and you <em>must not</em> directly interact with the session tables.
2269 Future versions might support alternative session backends, such as Redis.</p>
2270 <div class="admonition warning">
2271 <p class="admonition-title">Do not interact directly with the session database tables but only via the <code>SessionHandler</code> class!</p>
2272 </div>
2273 <h3 id="reauthentication">Reauthentication<a class="headerlink" href="#reauthentication" title="Permanent link">#</a></h3>
2274 <p>For security sensitive processing, you might want to ensure that the account owner is actually present instead of a third party accessing a session that was accidentally left logged in.</p>
2275 <p>WoltLab Suite 5.4 ships with a generic reauthentication framework.
2276 To request reauthentication within your controller you need to:</p>
2277 <ol>
2278 <li>Use the <code>wcf\system\user\authentication\TReauthenticationCheck</code> trait.</li>
2279 <li>Call:
2280 <div class="highlight"><pre><span></span><code><span class="nv">$this</span><span class="o">-&gt;</span><span class="na">requestReauthentication</span><span class="p">(</span><span class="nx">LinkHandler</span><span class="o">::</span><span class="na">getInstance</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">getControllerLink</span><span class="p">(</span><span class="k">static</span><span class="o">::</span><span class="na">class</span><span class="p">,</span> <span class="p">[</span>
2281 <span class="cm">/* additional parameters */</span>
2282 <span class="p">]));</span>
2283 </code></pre></div></li>
2284 </ol>
2285 <p><code>requestReauthentication()</code> will check if the user has recently authenticated themselves.
2286 If they did, the request proceeds as usual.
2287 Otherwise, they will be asked to reauthenticate themselves.
2288 After the successful authentication, they will be redirected to the URL that was passed as the first parameter (the current controller within the example).</p>
2289 <p>Details can be found in <a href="https://github.com/WoltLab/WCF/pull/3775">WoltLab/WCF#3775</a>.</p>
2290 <h3 id="multi-factor-authentication">Multi-factor Authentication<a class="headerlink" href="#multi-factor-authentication" title="Permanent link">#</a></h3>
2291 <p>To implement multi-factor authentication securely, WoltLab Suite 5.4 implements the concept of a “pending user change”.
2292 The user will not be logged in (i.e. <code>WCF::getUser()-&gt;userID</code> returns <code>null</code>) until they authenticate themselves with their second factor.</p>
2293 <p>Requesting multi-factor authentication is done on an opt-in basis for compatibility reasons.
2294 If you perform authentication yourself and do not trust the authentication source to perform multi-factor authentication itself, you will need to adjust your logic to request multi-factor authentication from WoltLab Suite:</p>
2295 <p>Previously:</p>
2296 <div class="highlight"><pre><span></span><code><span class="nx">WCF</span><span class="o">::</span><span class="na">getSession</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">changeUser</span><span class="p">(</span><span class="nv">$targetUser</span><span class="p">);</span>
2297 </code></pre></div>
2298 <p>Now:</p>
2299 <div class="highlight"><pre><span></span><code><span class="nv">$isPending</span> <span class="o">=</span> <span class="nx">WCF</span><span class="o">::</span><span class="na">getSession</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">changeUserAfterMultifactorAuthentication</span><span class="p">(</span><span class="nv">$targetUser</span><span class="p">);</span>
2300 <span class="k">if</span> <span class="p">(</span><span class="nv">$isPending</span><span class="p">)</span> <span class="p">{</span>
2301 <span class="c1">// Redirect to the authentication form. The user will not be logged in.</span>
2302 <span class="c1">// Note: Do not use `getControllerLink` to support both the frontend as well as the ACP.</span>
2303 <span class="nx">HeaderUtil</span><span class="o">::</span><span class="na">redirect</span><span class="p">(</span><span class="nx">LinkHandler</span><span class="o">::</span><span class="na">getInstance</span><span class="p">()</span><span class="o">-&gt;</span><span class="na">getLink</span><span class="p">(</span><span class="s1">&#39;MultifactorAuthentication&#39;</span><span class="p">,</span> <span class="p">[</span>
2304 <span class="s1">&#39;url&#39;</span> <span class="o">=&gt;</span> <span class="cm">/* Return To */</span><span class="p">,</span>
2305 <span class="p">]));</span>
2306 <span class="k">exit</span><span class="p">;</span>
2307 <span class="p">}</span>
2308 <span class="c1">// Proceed as usual. The user will be logged in.</span>
2309 </code></pre></div>
2310 <h4 id="adding-multi-factor-methods">Adding Multi-factor Methods<a class="headerlink" href="#adding-multi-factor-methods" title="Permanent link">#</a></h4>
2311 <p>Adding your own multi-factor method requires the implementation of a single object type:</p>
2312 <div class="highlight"><pre><span></span><code><span class="nt">&lt;type&gt;</span>
2313 <span class="nt">&lt;name&gt;</span>com.example.multifactor.foobar<span class="nt">&lt;/name&gt;</span>
2314 <span class="nt">&lt;definitionname&gt;</span>com.woltlab.wcf.multifactor<span class="nt">&lt;/definitionname&gt;</span>
2315 <span class="nt">&lt;icon&gt;</span><span class="c">&lt;!-- Font Awesome 4 Icon Name goes here. --&gt;</span><span class="nt">&lt;/icon&gt;</span>
2316 <span class="nt">&lt;priority&gt;</span><span class="c">&lt;!-- Determines the sort order, higher priority will be preferred for authentication. --&gt;</span><span class="nt">&lt;/priority&gt;</span>
2317 <span class="nt">&lt;classname&gt;</span>wcf\system\user\multifactor\FoobarMultifactorMethod<span class="nt">&lt;/classname&gt;</span>
2318 <span class="nt">&lt;/type&gt;</span>
2319 </code></pre></div>
2320 <p>The given classname must implement the <a href="https://github.com/WoltLab/WCF/blob/master/wcfsetup/install/files/lib/system/user/multifactor/IMultifactorMethod.class.php"><code>IMultifactorMethod</code></a> interface.</p>
2321 <p>As a self-contained example, you can find the initial implementation of the email multi-factor method in <a href="https://github.com/WoltLab/WCF/pull/3729">WoltLab/WCF#3729</a>.
2322 Please check <a href="https://github.com/WoltLab/WCF/commits/master/wcfsetup/install/files/lib/system/user/multifactor/EmailMultifactorMethod.class.php">the version history</a> of the PHP class to make sure you do not miss important changes that were added later.</p>
2323 <div class="admonition warning">
2324 <p class="admonition-title">Multi-factor authentication is security sensitive. Make sure to carefully read the remarks in <code>IMultifactorMethod</code> for possible issues. Also make sure to carefully test your implementation against all sorts of incorrect input and consider attack vectors such as race conditions. It is strongly recommended to generously check the current state by leveraging assertions and exceptions.</p>
2325 </div>
2326 <h2 id="deprecations-and-removals">Deprecations and Removals<a class="headerlink" href="#deprecations-and-removals" title="Permanent link">#</a></h2>
2327 <h3 id="sessionhandler">SessionHandler<a class="headerlink" href="#sessionhandler" title="Permanent link">#</a></h3>
2328 <p>Most of the changes with regard to the new session handling happened in <code>SessionHandler</code>.
2329 Most notably, <code>SessionHandler</code> now is marked <code>final</code> to ensure proper encapsulation of data.</p>
2330 <p>A number of methods in <code>SessionHandler</code> are now deprecated and result in a noop.
2331 This change mostly affects methods that have been used to bootstrap the session, such as <code>setHasValidCookie()</code>.</p>
2332 <p>Additionally, accessing the following keys on the session is deprecated.
2333 They directly map to an existing method in another class and any uses can easily be updated:
2334 - <code>ipAddress</code>
2335 - <code>userAgent</code>
2336 - <code>requestURI</code>
2337 - <code>requestMethod</code>
2338 - <code>lastActivityTime</code></p>
2339 <p>Refer to <a href="https://github.com/WoltLab/WCF/blob/439de4963c947c3569a0c584f795245f693155b0/wcfsetup/install/files/lib/system/session/SessionHandler.class.php#L168-L178">the implementation</a> for details.</p>
2340 <h3 id="acp-sessions">ACP Sessions<a class="headerlink" href="#acp-sessions" title="Permanent link">#</a></h3>
2341 <p>The database tables related to ACP sessions have been removed.
2342 The PHP classes have been preserved due to being used within the class hierarchy of the legacy sessions.</p>
2343 <h3 id="cookies">Cookies<a class="headerlink" href="#cookies" title="Permanent link">#</a></h3>
2344 <p>The <code>_userID</code>, <code>_password</code>, <code>_cookieHash</code> and <code>_cookieHash_acp</code> cookies will no longer be created nor consumed.</p>
2345 <h3 id="virtual-sessions">Virtual Sessions<a class="headerlink" href="#virtual-sessions" title="Permanent link">#</a></h3>
2346 <p>The virtual session logic existed to support multiple devices per single session in <code>wcf1_session</code>.
2347 Virtual sessions are no longer required with the refactored session handling.</p>
2348 <p>Anything related to virtual sessions has been completely removed as they are considered an implementation detail.
2349 This removal includes PHP classes and database tables.</p>
2350 <h3 id="security-token-constants">Security Token Constants<a class="headerlink" href="#security-token-constants" title="Permanent link">#</a></h3>
2351 <p>The security token constants are deprecated.
2352 Instead, the methods of <code>SessionHandler</code> should be used (e.g. <code>-&gt;getSecurityToken()</code>).
2353 Within templates, you should migrate to the <code>{csrfToken}</code> tag in place of <code>{@SECURITY_TOKEN_INPUT_TAG}</code>.
2354 The <code>{csrfToken}</code> tag is a drop-in replacement and was backported to WoltLab Suite 5.2+, allowing you to maintain compatibility across a broad range of versions.</p>
2355 <h3 id="passwordutil-and-double-bcrypt-hashes">PasswordUtil and Double BCrypt Hashes<a class="headerlink" href="#passwordutil-and-double-bcrypt-hashes" title="Permanent link">#</a></h3>
2356 <p>Most of the methods in PasswordUtil are deprecated in favor of the new password hashing framework.</p>
2357
2358
2359
2360
2361 <hr>
2362 <div class="md-source-date">
2363 <small>
2364
2365 Last update: 2021-02-11
2366
2367 </small>
2368 </div>
2369
2370
2371
2372
2373
2374
2375
2376
2377 </article>
2378 </div>
2379 </div>
2380
2381 </main>
2382
2383
2384 <footer class="md-footer">
2385
2386 <nav class="md-footer__inner md-grid" aria-label="Footer">
2387
2388 <a href="../php/" class="md-footer__link md-footer__link--prev" rel="prev">
2389 <div class="md-footer__button md-icon">
2390 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12z"/></svg>
2391 </div>
2392 <div class="md-footer__title">
2393 <div class="md-ellipsis">
2394 <span class="md-footer__direction">
2395 Previous
2396 </span>
2397 PHP API
2398 </div>
2399 </div>
2400 </a>
2401
2402
2403 <a href="../javascript/" class="md-footer__link md-footer__link--next" rel="next">
2404 <div class="md-footer__title">
2405 <div class="md-ellipsis">
2406 <span class="md-footer__direction">
2407 Next
2408 </span>
2409 TypeScript and JavaScript
2410 </div>
2411 </div>
2412 <div class="md-footer__button md-icon">
2413 <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M4 11v2h12l-5.5 5.5 1.42 1.42L19.84 12l-7.92-7.92L10.5 5.5 16 11H4z"/></svg>
2414 </div>
2415 </a>
2416
2417 </nav>
2418
2419 <div class="md-footer-meta md-typeset">
2420 <div class="md-footer-meta__inner md-grid">
2421 <div class="md-footer-copyright">
2422
2423 <div class="md-footer-copyright__highlight">
2424 Copyright © 2020 WoltLab GmbH
2425 </div>
2426
2427 Made with
2428 <a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
2429 Material for MkDocs
2430 </a>
2431
2432 </div>
2433 <div class="md-footer-copyright">
2434 <a href="https://www.woltlab.com/legal-notice/">Legal Notice</a>
2435 <a href="https://www.woltlab.com/privacy-policy/">Privacy Policy</a>
2436 </div>
2437 </div>
2438 </div>
2439 </footer>
2440
2441 </div>
2442 <div class="md-dialog" data-md-component="dialog">
2443 <div class="md-dialog__inner md-typeset"></div>
2444 </div>
2445 <script id="__config" type="application/json">{"base": "../../..", "features": [], "translations": {"clipboard.copy": "Copy to clipboard", "clipboard.copied": "Copied to clipboard", "search.config.lang": "en", "search.config.pipeline": "trimmer, stopWordFilter", "search.config.separator": "[\\s\\-]+", "search.placeholder": "Search", "search.result.placeholder": "Type to start searching", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.term.missing": "Missing"}, "search": "../../../assets/javascripts/workers/search.fe42c31b.min.js", "version": {"provider": "mike"}}</script>
2446
2447
2448 <script src="../../../assets/javascripts/bundle.d892486b.min.js"></script>
2449
2450
2451 </body>
2452 </html>