Commit Graph
1 Commits
Author SHA1 Message Date
Divarion_D 2c7ea749e7 refactor(admin): delete functions.php, consolidate the admin bootstrap
Views/admin/functions.php duplicated, almost line for line, the body of
AdminScopeBootstrap::bootFunctions() (the front-controller admin boot), and
was also include'd by the JSON DataTables endpoint — where its cookies /
redirects / setup-COUNT query are inappropriate and the relative include was
fragile (only resolved via the FC's @chdir).

- AdminScopeBootstrap: expose the boot body through a public
  hydrateAdminContext() entry point; guard the setcookie()/header() calls with
  headers_sent() so the view scripts can call it after output has begun;
  validate the session via the shared predicate.
- SessionManager::adminSessionValid() is now the single definition of the admin
  session-integrity check (user/is_admin + login-IP + verify hash), split into
  adminIdentityValid()/adminIpAllowed() and covered by SessionManagerTest.
- The six $noBootstrapPages view scripts (login, logout, setup, database,
  player, post) call AdminScopeBootstrap::hydrateAdminContext() in place of
  include "functions.php", re-importing the view-facing globals in their own
  scope (the load-bearing part of the old include).
- Admin TableController: the api_key / api_user_id / session branches share a
  hydrateApiUser() helper; the session branch validates via adminSessionValid()
  and returns JSON on failure (no cookies / redirect / setup query). index()'s
  global is widened so Authorization::check sees $rUserInfo/$rSettings.

793 unit tests pass; make gates and the CRAP gate stay green.
2026-09-18 11:32:15 +03:00