Module.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368
  1. <?php
  2. /**
  3. * @link http://www.yiiframework.com/
  4. * @copyright Copyright (c) 2008 Yii Software LLC
  5. * @license http://www.yiiframework.com/license/
  6. */
  7. namespace yii\debug;
  8. use Yii;
  9. use yii\base\Application;
  10. use yii\base\BootstrapInterface;
  11. use yii\helpers\Json;
  12. use yii\web\Response;
  13. use yii\helpers\Html;
  14. use yii\helpers\Url;
  15. use yii\web\View;
  16. use yii\web\ForbiddenHttpException;
  17. /**
  18. * The Yii Debug Module provides the debug toolbar and debugger
  19. *
  20. * @author Qiang Xue <qiang.xue@gmail.com>
  21. * @since 2.0
  22. */
  23. class Module extends \yii\base\Module implements BootstrapInterface
  24. {
  25. const DEFAULT_IDE_TRACELINE = '<a href="ide://open?url=file://{file}&line={line}">{text}</a>';
  26. /**
  27. * @var array the list of IPs that are allowed to access this module.
  28. * Each array element represents a single IP filter which can be either an IP address
  29. * or an address with wildcard (e.g. 192.168.0.*) to represent a network segment.
  30. * The default value is `['127.0.0.1', '::1']`, which means the module can only be accessed
  31. * by localhost.
  32. */
  33. public $allowedIPs = ['127.0.0.1', '::1'];
  34. /**
  35. * @var array the list of hosts that are allowed to access this module.
  36. * Each array element is a hostname that will be resolved to an IP address that is compared
  37. * with the IP address of the user. A use case is to use a dynamic DNS (DDNS) to allow access.
  38. * The default value is `[]`.
  39. */
  40. public $allowedHosts = [];
  41. /**
  42. * {@inheritdoc}
  43. */
  44. public $controllerNamespace = 'yii\debug\controllers';
  45. /**
  46. * @var LogTarget
  47. */
  48. public $logTarget;
  49. /**
  50. * @var array|Panel[] list of debug panels. The array keys are the panel IDs, and values are the corresponding
  51. * panel class names or configuration arrays. This will be merged with [[corePanels()]].
  52. * You may reconfigure a core panel via this property by using the same panel ID.
  53. * You may also disable a core panel by setting it to be false in this property.
  54. */
  55. public $panels = [];
  56. /**
  57. * @var string the name of the panel that should be visible when opening the debug panel.
  58. * The default value is 'log'.
  59. * @since 2.0.7
  60. */
  61. public $defaultPanel = 'log';
  62. /**
  63. * @var string the directory storing the debugger data files. This can be specified using a path alias.
  64. */
  65. public $dataPath = '@runtime/debug';
  66. /**
  67. * @var int the permission to be set for newly created debugger data files.
  68. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  69. * If not set, the permission will be determined by the current environment.
  70. * @since 2.0.6
  71. */
  72. public $fileMode;
  73. /**
  74. * @var int the permission to be set for newly created directories.
  75. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  76. * Defaults to 0775, meaning the directory is read-writable by owner and group,
  77. * but read-only for other users.
  78. * @since 2.0.6
  79. */
  80. public $dirMode = 0775;
  81. /**
  82. * @var int the maximum number of debug data files to keep. If there are more files generated,
  83. * the oldest ones will be removed.
  84. */
  85. public $historySize = 50;
  86. /**
  87. * @var bool whether to enable message logging for the requests about debug module actions.
  88. * You normally do not want to keep these logs because they may distract you from the logs about your applications.
  89. * You may want to enable the debug logs if you want to investigate how the debug module itself works.
  90. */
  91. public $enableDebugLogs = false;
  92. /**
  93. * @var bool whether to disable IP address restriction warning triggered by checkAccess function
  94. * @since 2.0.14
  95. */
  96. public $disableIpRestrictionWarning = false;
  97. /**
  98. * @var mixed the string with placeholders to be be substituted or an anonymous function that returns the trace line string.
  99. * The placeholders are {file}, {line} and {text} and the string should be as follows:
  100. *
  101. * `File: {file} - Line: {line} - Text: {text}`
  102. *
  103. * The signature of the anonymous function should be as follows:
  104. *
  105. * ```php
  106. * function($trace, $panel) {
  107. * // compute line string
  108. * return $line;
  109. * }
  110. * ```
  111. * @since 2.0.7
  112. */
  113. public $traceLine = self::DEFAULT_IDE_TRACELINE;
  114. /**
  115. * @var string Yii logo URL
  116. */
  117. private static $_yiiLogo = '';
  118. /**
  119. * Returns the logo URL to be used in `<img src="`
  120. *
  121. * @return string the logo URL
  122. */
  123. public static function getYiiLogo()
  124. {
  125. return self::$_yiiLogo;
  126. }
  127. /**
  128. * Sets the logo URL to be used in `<img src="`
  129. *
  130. * @param string $logo the logo URL
  131. */
  132. public static function setYiiLogo($logo)
  133. {
  134. self::$_yiiLogo = $logo;
  135. }
  136. /**
  137. * {@inheritdoc}
  138. */
  139. public function init()
  140. {
  141. parent::init();
  142. $this->dataPath = Yii::getAlias($this->dataPath);
  143. if (Yii::$app instanceof \yii\web\Application) {
  144. $this->initPanels();
  145. }
  146. }
  147. /**
  148. * Initializes panels.
  149. */
  150. protected function initPanels()
  151. {
  152. // merge custom panels and core panels so that they are ordered mainly by custom panels
  153. if (empty($this->panels)) {
  154. $this->panels = $this->corePanels();
  155. } else {
  156. $corePanels = $this->corePanels();
  157. foreach ($corePanels as $id => $config) {
  158. if (isset($this->panels[$id])) {
  159. unset($corePanels[$id]);
  160. }
  161. }
  162. $this->panels = array_filter(array_merge($corePanels, $this->panels));
  163. }
  164. foreach ($this->panels as $id => $config) {
  165. if (is_string($config)) {
  166. $config = ['class' => $config];
  167. }
  168. $config['module'] = $this;
  169. $config['id'] = $id;
  170. $this->panels[$id] = Yii::createObject($config);
  171. if ($this->panels[$id] instanceof Panel && !$this->panels[$id]->isEnabled()) {
  172. unset($this->panels[$id]);
  173. }
  174. }
  175. }
  176. /**
  177. * {@inheritdoc}
  178. */
  179. public function bootstrap($app)
  180. {
  181. $this->logTarget = $app->getLog()->targets['debug'] = new LogTarget($this);
  182. // delay attaching event handler to the view component after it is fully configured
  183. $app->on(Application::EVENT_BEFORE_REQUEST, function () use ($app) {
  184. $app->getView()->on(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  185. $app->getResponse()->on(Response::EVENT_AFTER_PREPARE, [$this, 'setDebugHeaders']);
  186. });
  187. $app->getUrlManager()->addRules([
  188. [
  189. 'class' => 'yii\web\UrlRule',
  190. 'route' => $this->id,
  191. 'pattern' => $this->id,
  192. 'suffix' => false
  193. ],
  194. [
  195. 'class' => 'yii\web\UrlRule',
  196. 'route' => $this->id . '/<controller>/<action>',
  197. 'pattern' => $this->id . '/<controller:[\w\-]+>/<action:[\w\-]+>',
  198. 'suffix' => false
  199. ]
  200. ], false);
  201. }
  202. /**
  203. * {@inheritdoc}
  204. */
  205. public function beforeAction($action)
  206. {
  207. if (!$this->enableDebugLogs) {
  208. foreach ($this->get('log')->targets as $target) {
  209. $target->enabled = false;
  210. }
  211. }
  212. if (!parent::beforeAction($action)) {
  213. return false;
  214. }
  215. // do not display debug toolbar when in debug view mode
  216. Yii::$app->getView()->off(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  217. Yii::$app->getResponse()->off(Response::EVENT_AFTER_PREPARE, [$this, 'setDebugHeaders']);
  218. if ($this->checkAccess()) {
  219. $this->resetGlobalSettings();
  220. return true;
  221. }
  222. if ($action->id === 'toolbar') {
  223. // Accessing toolbar remotely is normal. Do not throw exception.
  224. return false;
  225. }
  226. throw new ForbiddenHttpException('You are not allowed to access this page.');
  227. }
  228. /**
  229. * Setting headers to transfer debug data in AJAX requests
  230. * without interfering with the request itself.
  231. *
  232. * @param \yii\base\Event $event
  233. * @since 2.0.7
  234. */
  235. public function setDebugHeaders($event)
  236. {
  237. if (!$this->checkAccess()) {
  238. return;
  239. }
  240. $url = Url::toRoute(['/' . $this->id . '/default/view',
  241. 'tag' => $this->logTarget->tag,
  242. ]);
  243. $event->sender->getHeaders()
  244. ->set('X-Debug-Tag', $this->logTarget->tag)
  245. ->set('X-Debug-Duration', number_format((microtime(true) - YII_BEGIN_TIME) * 1000 + 1))
  246. ->set('X-Debug-Link', $url);
  247. }
  248. /**
  249. * Resets potentially incompatible global settings done in app config.
  250. */
  251. protected function resetGlobalSettings()
  252. {
  253. Yii::$app->assetManager->bundles = [];
  254. }
  255. /**
  256. * Gets toolbar HTML
  257. * @since 2.0.7
  258. */
  259. public function getToolbarHtml()
  260. {
  261. $url = Url::toRoute(['/' . $this->id . '/default/toolbar',
  262. 'tag' => $this->logTarget->tag,
  263. ]);
  264. return '<div id="yii-debug-toolbar" data-url="' . Html::encode($url) . '" style="display:none" class="yii-debug-toolbar-bottom"></div>';
  265. }
  266. /**
  267. * Renders mini-toolbar at the end of page body.
  268. *
  269. * @param \yii\base\Event $event
  270. */
  271. public function renderToolbar($event)
  272. {
  273. if (!$this->checkAccess() || Yii::$app->getRequest()->getIsAjax()) {
  274. return;
  275. }
  276. /* @var $view View */
  277. $view = $event->sender;
  278. echo $view->renderDynamic('return Yii::$app->getModule("' . $this->id . '")->getToolbarHtml();');
  279. // echo is used in order to support cases where asset manager is not available
  280. echo '<style>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.css') . '</style>';
  281. echo '<script>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.js') . '</script>';
  282. }
  283. /**
  284. * Checks if current user is allowed to access the module
  285. * @return bool if access is granted
  286. */
  287. protected function checkAccess()
  288. {
  289. $ip = Yii::$app->getRequest()->getUserIP();
  290. foreach ($this->allowedIPs as $filter) {
  291. if ($filter === '*' || $filter === $ip || (($pos = strpos($filter, '*')) !== false && !strncmp($ip, $filter, $pos))) {
  292. return true;
  293. }
  294. }
  295. foreach ($this->allowedHosts as $hostname) {
  296. $filter = gethostbyname($hostname);
  297. if ($filter === $ip) {
  298. return true;
  299. }
  300. }
  301. if (!$this->disableIpRestrictionWarning) {
  302. Yii::warning('Access to debugger is denied due to IP address restriction. The requesting IP address is ' . $ip, __METHOD__);
  303. }
  304. return false;
  305. }
  306. /**
  307. * @return array default set of panels
  308. */
  309. protected function corePanels()
  310. {
  311. return [
  312. 'config' => ['class' => 'yii\debug\panels\ConfigPanel'],
  313. 'request' => ['class' => 'yii\debug\panels\RequestPanel'],
  314. 'log' => ['class' => 'yii\debug\panels\LogPanel'],
  315. 'profiling' => ['class' => 'yii\debug\panels\ProfilingPanel'],
  316. 'db' => ['class' => 'yii\debug\panels\DbPanel'],
  317. 'event' => ['class' => 'yii\debug\panels\EventPanel'],
  318. 'assets' => ['class' => 'yii\debug\panels\AssetPanel'],
  319. 'mail' => ['class' => 'yii\debug\panels\MailPanel'],
  320. 'timeline' => ['class' => 'yii\debug\panels\TimelinePanel'],
  321. 'user' => ['class' => 'yii\debug\panels\UserPanel'],
  322. 'router' => ['class' => 'yii\debug\panels\RouterPanel'],
  323. ];
  324. }
  325. /**
  326. * {@inheritdoc}
  327. * @since 2.0.7
  328. */
  329. protected function defaultVersion()
  330. {
  331. $packageInfo = Json::decode(file_get_contents(dirname(__DIR__) . DIRECTORY_SEPARATOR . 'composer.json'));
  332. $extensionName = $packageInfo['name'];
  333. if (isset(Yii::$app->extensions[$extensionName])) {
  334. return Yii::$app->extensions[$extensionName]['version'];
  335. }
  336. return parent::defaultVersion();
  337. }
  338. }