You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

Module.php 17KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258
  1. <?php
  2. /**
  3. * @link http://www.yiiframework.com/
  4. * @copyright Copyright (c) 2008 Yii Software LLC
  5. * @license http://www.yiiframework.com/license/
  6. */
  7. namespace yii\debug;
  8. use Yii;
  9. use yii\base\Application;
  10. use yii\base\BootstrapInterface;
  11. use yii\helpers\Html;
  12. use yii\helpers\Url;
  13. use yii\web\View;
  14. use yii\web\ForbiddenHttpException;
  15. /**
  16. * The Yii Debug Module provides the debug toolbar and debugger
  17. *
  18. * @author Qiang Xue <qiang.xue@gmail.com>
  19. * @since 2.0
  20. */
  21. class Module extends \yii\base\Module implements BootstrapInterface
  22. {
  23. /**
  24. * @var array the list of IPs that are allowed to access this module.
  25. * Each array element represents a single IP filter which can be either an IP address
  26. * or an address with wildcard (e.g. 192.168.0.*) to represent a network segment.
  27. * The default value is `['127.0.0.1', '::1']`, which means the module can only be accessed
  28. * by localhost.
  29. */
  30. public $allowedIPs = ['127.0.0.1', '::1'];
  31. /**
  32. * @var array the list of hosts that are allowed to access this module.
  33. * Each array element is a hostname that will be resolved to an IP address that is compared
  34. * with the IP address of the user. A use case is to use a dynamic DNS (DDNS) to allow access.
  35. * The default value is `[]`.
  36. */
  37. public $allowedHosts = [];
  38. /**
  39. * @inheritdoc
  40. */
  41. public $controllerNamespace = 'yii\debug\controllers';
  42. /**
  43. * @var LogTarget
  44. */
  45. public $logTarget;
  46. /**
  47. * @var array|Panel[] list of debug panels. The array keys are the panel IDs, and values are the corresponding
  48. * panel class names or configuration arrays. This will be merged with [[corePanels()]].
  49. * You may reconfigure a core panel via this property by using the same panel ID.
  50. * You may also disable a core panel by setting it to be false in this property.
  51. */
  52. public $panels = [];
  53. /**
  54. * @var string the directory storing the debugger data files. This can be specified using a path alias.
  55. */
  56. public $dataPath = '@runtime/debug';
  57. /**
  58. * @var integer the permission to be set for newly created debugger data files.
  59. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  60. * If not set, the permission will be determined by the current environment.
  61. * @since 2.0.6
  62. */
  63. public $fileMode;
  64. /**
  65. * @var integer the permission to be set for newly created directories.
  66. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  67. * Defaults to 0775, meaning the directory is read-writable by owner and group,
  68. * but read-only for other users.
  69. * @since 2.0.6
  70. */
  71. public $dirMode = 0775;
  72. /**
  73. * @var integer the maximum number of debug data files to keep. If there are more files generated,
  74. * the oldest ones will be removed.
  75. */
  76. public $historySize = 50;
  77. /**
  78. * @var boolean whether to enable message logging for the requests about debug module actions.
  79. * You normally do not want to keep these logs because they may distract you from the logs about your applications.
  80. * You may want to enable the debug logs if you want to investigate how the debug module itself works.
  81. */
  82. public $enableDebugLogs = false;
  83. /**
  84. * Returns Yii logo ready to use in `<img src="`
  85. *
  86. * @return string base64 representation of the image
  87. */
  88. public static function getYiiLogo()
  89. {
  90. return '';
  91. }
  92. /**
  93. * @inheritdoc
  94. */
  95. public function init()
  96. {
  97. parent::init();
  98. $this->dataPath = Yii::getAlias($this->dataPath);
  99. $this->initPanels();
  100. }
  101. /**
  102. * Initializes panels.
  103. */
  104. protected function initPanels()
  105. {
  106. // merge custom panels and core panels so that they are ordered mainly by custom panels
  107. if (empty($this->panels)) {
  108. $this->panels = $this->corePanels();
  109. } else {
  110. $corePanels = $this->corePanels();
  111. foreach ($corePanels as $id => $config) {
  112. if (isset($this->panels[$id])) {
  113. unset($corePanels[$id]);
  114. }
  115. }
  116. $this->panels = array_filter(array_merge($corePanels, $this->panels));
  117. }
  118. foreach ($this->panels as $id => $config) {
  119. if (is_string($config)) {
  120. $config = ['class' => $config];
  121. }
  122. $config['module'] = $this;
  123. $config['id'] = $id;
  124. $this->panels[$id] = Yii::createObject($config);
  125. }
  126. }
  127. /**
  128. * @inheritdoc
  129. */
  130. public function bootstrap($app)
  131. {
  132. $this->logTarget = Yii::$app->getLog()->targets['debug'] = new LogTarget($this);
  133. // delay attaching event handler to the view component after it is fully configured
  134. $app->on(Application::EVENT_BEFORE_REQUEST, function () use ($app) {
  135. $app->getView()->on(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  136. });
  137. $app->getUrlManager()->addRules([
  138. [
  139. 'class' => 'yii\web\UrlRule',
  140. 'route' => $this->id,
  141. 'pattern' => $this->id,
  142. ],
  143. [
  144. 'class' => 'yii\web\UrlRule',
  145. 'route' => $this->id . '/<controller>/<action>',
  146. 'pattern' => $this->id . '/<controller:[\w\-]+>/<action:[\w\-]+>',
  147. ]
  148. ], false);
  149. }
  150. /**
  151. * @inheritdoc
  152. */
  153. public function beforeAction($action)
  154. {
  155. if (!$this->enableDebugLogs) {
  156. foreach (Yii::$app->getLog()->targets as $target) {
  157. $target->enabled = false;
  158. }
  159. }
  160. if (!parent::beforeAction($action)) {
  161. return false;
  162. }
  163. // do not display debug toolbar when in debug view mode
  164. Yii::$app->getView()->off(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  165. if ($this->checkAccess()) {
  166. $this->resetGlobalSettings();
  167. return true;
  168. } elseif ($action->id === 'toolbar') {
  169. // Accessing toolbar remotely is normal. Do not throw exception.
  170. return false;
  171. } else {
  172. throw new ForbiddenHttpException('You are not allowed to access this page.');
  173. }
  174. }
  175. /**
  176. * Resets potentially incompatible global settings done in app config.
  177. */
  178. protected function resetGlobalSettings()
  179. {
  180. Yii::$app->assetManager->bundles = [];
  181. }
  182. /**
  183. * Renders mini-toolbar at the end of page body.
  184. *
  185. * @param \yii\base\Event $event
  186. */
  187. public function renderToolbar($event)
  188. {
  189. if (!$this->checkAccess() || Yii::$app->getRequest()->getIsAjax()) {
  190. return;
  191. }
  192. $url = Url::toRoute(['/' . $this->id . '/default/toolbar',
  193. 'tag' => $this->logTarget->tag,
  194. ]);
  195. echo '<div id="yii-debug-toolbar" data-url="' . Html::encode($url) . '" style="display:none" class="yii-debug-toolbar-bottom"></div>';
  196. /* @var $view View */
  197. $view = $event->sender;
  198. // echo is used in order to support cases where asset manager is not available
  199. echo '<style>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.css') . '</style>';
  200. echo '<script>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.js') . '</script>';
  201. }
  202. /**
  203. * Checks if current user is allowed to access the module
  204. * @return boolean if access is granted
  205. */
  206. protected function checkAccess()
  207. {
  208. $ip = Yii::$app->getRequest()->getUserIP();
  209. foreach ($this->allowedIPs as $filter) {
  210. if ($filter === '*' || $filter === $ip || (($pos = strpos($filter, '*')) !== false && !strncmp($ip, $filter, $pos))) {
  211. return true;
  212. }
  213. }
  214. foreach ($this->allowedHosts as $hostname) {
  215. $filter = gethostbyname($hostname);
  216. if ($filter === $ip) {
  217. return true;
  218. }
  219. }
  220. Yii::warning('Access to debugger is denied due to IP address restriction. The requesting IP address is ' . $ip, __METHOD__);
  221. return false;
  222. }
  223. /**
  224. * @return array default set of panels
  225. */
  226. protected function corePanels()
  227. {
  228. return [
  229. 'config' => ['class' => 'yii\debug\panels\ConfigPanel'],
  230. 'request' => ['class' => 'yii\debug\panels\RequestPanel'],
  231. 'log' => ['class' => 'yii\debug\panels\LogPanel'],
  232. 'profiling' => ['class' => 'yii\debug\panels\ProfilingPanel'],
  233. 'db' => ['class' => 'yii\debug\panels\DbPanel'],
  234. 'assets' => ['class' => 'yii\debug\panels\AssetPanel'],
  235. 'mail' => ['class' => 'yii\debug\panels\MailPanel'],
  236. ];
  237. }
  238. }