Module.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368
  1. <?php
  2. /**
  3. * @link http://www.yiiframework.com/
  4. * @copyright Copyright (c) 2008 Yii Software LLC
  5. * @license http://www.yiiframework.com/license/
  6. */
  7. namespace yii\debug;
  8. use Yii;
  9. use yii\base\Application;
  10. use yii\base\BootstrapInterface;
  11. use yii\helpers\Json;
  12. use yii\web\Response;
  13. use yii\helpers\Html;
  14. use yii\helpers\Url;
  15. use yii\web\View;
  16. use yii\web\ForbiddenHttpException;
  17. /**
  18. * The Yii Debug Module provides the debug toolbar and debugger
  19. *
  20. * @author Qiang Xue <qiang.xue@gmail.com>
  21. * @since 2.0
  22. */
  23. class Module extends \yii\base\Module implements BootstrapInterface
  24. {
  25. const DEFAULT_IDE_TRACELINE = '<a href="ide://open?url=file://{file}&line={line}">{text}</a>';
  26. /**
  27. * @var array the list of IPs that are allowed to access this module.
  28. * Each array element represents a single IP filter which can be either an IP address
  29. * or an address with wildcard (e.g. 192.168.0.*) to represent a network segment.
  30. * The default value is `['127.0.0.1', '::1']`, which means the module can only be accessed
  31. * by localhost.
  32. */
  33. public $allowedIPs = ['127.0.0.1', '::1'];
  34. /**
  35. * @var array the list of hosts that are allowed to access this module.
  36. * Each array element is a hostname that will be resolved to an IP address that is compared
  37. * with the IP address of the user. A use case is to use a dynamic DNS (DDNS) to allow access.
  38. * The default value is `[]`.
  39. */
  40. public $allowedHosts = [];
  41. /**
  42. * {@inheritdoc}
  43. */
  44. public $controllerNamespace = 'yii\debug\controllers';
  45. /**
  46. * @var LogTarget
  47. */
  48. public $logTarget;
  49. /**
  50. * @var array|Panel[] list of debug panels. The array keys are the panel IDs, and values are the corresponding
  51. * panel class names or configuration arrays. This will be merged with [[corePanels()]].
  52. * You may reconfigure a core panel via this property by using the same panel ID.
  53. * You may also disable a core panel by setting it to be false in this property.
  54. */
  55. public $panels = [];
  56. /**
  57. * @var string the name of the panel that should be visible when opening the debug panel.
  58. * The default value is 'log'.
  59. * @since 2.0.7
  60. */
  61. public $defaultPanel = 'log';
  62. /**
  63. * @var string the directory storing the debugger data files. This can be specified using a path alias.
  64. */
  65. public $dataPath = '@runtime/debug';
  66. /**
  67. * @var int the permission to be set for newly created debugger data files.
  68. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  69. * If not set, the permission will be determined by the current environment.
  70. * @since 2.0.6
  71. */
  72. public $fileMode;
  73. /**
  74. * @var int the permission to be set for newly created directories.
  75. * This value will be used by PHP [[chmod()]] function. No umask will be applied.
  76. * Defaults to 0775, meaning the directory is read-writable by owner and group,
  77. * but read-only for other users.
  78. * @since 2.0.6
  79. */
  80. public $dirMode = 0775;
  81. /**
  82. * @var int the maximum number of debug data files to keep. If there are more files generated,
  83. * the oldest ones will be removed.
  84. */
  85. public $historySize = 50;
  86. /**
  87. * @var bool whether to enable message logging for the requests about debug module actions.
  88. * You normally do not want to keep these logs because they may distract you from the logs about your applications.
  89. * You may want to enable the debug logs if you want to investigate how the debug module itself works.
  90. */
  91. public $enableDebugLogs = false;
  92. /**
  93. * @var bool whether to disable IP address restriction warning triggered by checkAccess function
  94. * @since 2.0.14
  95. */
  96. public $disableIpRestrictionWarning = false;
  97. /**
  98. * @var mixed the string with placeholders to be be substituted or an anonymous function that returns the trace line string.
  99. * The placeholders are {file}, {line} and {text} and the string should be as follows:
  100. *
  101. * `File: {file} - Line: {line} - Text: {text}`
  102. *
  103. * The signature of the anonymous function should be as follows:
  104. *
  105. * ```php
  106. * function($trace, $panel) {
  107. * // compute line string
  108. * return $line;
  109. * }
  110. * ```
  111. * @since 2.0.7
  112. */
  113. public $traceLine = self::DEFAULT_IDE_TRACELINE;
  114. /**
  115. * @var string Yii logo URL
  116. */
  117. private static $_yiiLogo = 'data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADwAAAA8CAMAAAANIilAAAAC7lBMVEUAAACl034Cb7HlcjGRyT/H34fyy5PxqlSfzjwQeb5PmtX71HAMdrWOxkDzmU3qcDSPx0HzhUGNxT+/2lX2olDmUy/Q1l+TyD7rgjq21k3ZRzDQ4GGFw0Ghzz6MwOkKdrTA2lTzzMVjo9mhzkCIxUPk1MLynU7qWS33vmbP1rm011Fwqsj123/r44tUltTyq1aCxEOo0EL1tFuCw0Npp9v7xGVHkM8Ddrza0pvC3FboczHmXSvE21h+wkRkpNHvjkS92FPW3avpeDT2t1zX5GefzUD6wGQReLtMltPN417oczPZ0L+62FF+tuJgqtXZUzNzrN3s4Y7n65y72FLwmk7xjESr0kYof8MQe8DY5Gc6jMnN32DoaDLbTiLulUo1hsni45vuwnIigMXC21dqq8vKzaaBt+XU4mUMd7wDdr7xlUrU4a7A2VTD0LbVx5vvpFP/0m9godp/tuTD0LVyrsfZVDUuhMjkPChsrMt3suK92VDd52oEc7un0EKjzj7D21e01EuSyD2fzDvH3Fqu0kcDdL641k+x00rmXy0EdLiayzzynU2XyTzxmUur0ETshD7lZDDvkUbtiUDrgTvqfjrkWS292FPujEKAuObQ4GH3vWH1slr0r1j0pVLulEiPxj7oeDRnptn4zWrM31/1t13A2lb1rFb1qVS72FKHw0CLxD/qdTfnazL4wGPJ3VzwpFLpcjKFveljo9dfn9ZbntUYfcEIdr35w2XyoFH0ok/pfDZ9tONUmNRPltJIj89Ais388IL85Hn82nL80W33uV72tFy611DxlUnujkSCwkGlz0DqeTnocDJ3r99yrN1Xm9RFjc42hsorgsYhgMQPer/81XD5yGbT4mTriD/lbS3laCvjTiluqN5NktAxhMf853v84He/2VTgVCnmVSg8h8sHcrf6633+3nb8zGr2xmR/wEGcyzt3r+T/6n7tm01tqNnfSCnfPyO4zLmFwkDVRDGOweLP1aX55nrZTTOaxdjuY9uiAAAAfHRSTlMABv7+9hAJ/vMyGP2CbV5DOA+NbyYeG/DV0sC/ubaonYN5blZRQT41MSUk/v797+zj49PR0MXEw8PDu6imppqYlpOGhYN+bldWVFJROjAM+fPy8fDw8O7t6+vp5+Lh4N7e3Nvb2NPQ0MW8urm2rqiimJKFg3t5amZTT0k1ewExHwAABPVJREFUSMed1Xc81HEYB/DvhaOUEe29995777333ntv2sopUTQ4F104hRBSl8ohldCwOqfuuEiKaPdfz/P7/u6Syuu+ff727vM8z+8bhDHNB3TrXI38V6p1fvSosLBwgICd1qx/5cqVT8jrl9c1Wlm2qmFdgbWq5X316lXKq5dxu+ouyNWePevo6JjVd6il9T/soUPe3t48tyI0LeqWlpbk5oJ1dXVVKpNCH/e1/NO2rXXy5CEI5Y+6EZomn0tLSlS50OuaFZQUGuojl7vXtii/VQMnp5MQPW/+C6tUXDFnfeTubm4utVv+fud3EPTIUdfXYZVKpQULxTp75sz5h4PK7C4wO8zFCT1XbkxHG/cdZuaLqXV5Afb0xYW2etxsPxfg73htbEUPBhgXDgoKCg30kbu58Pai8/SW+o3t7e0TExPBYzuObkyXFk7SAnYFnBQYyPeePn3R2fnEiZsWPO5y6pQ9JpHXgPlHWlcLxWiTAh/LqX3wAOlNiYTXRzGn8F9I5LUx/052aLWOWVnwgQMfu7u7UQu9t26FhISYcpObHMdwHstxcR2uAc1ZSlgYsJsL7kutRCKT+XeyxWMfxHAeykE7OQGm6ecIOInaF3grmPkEWn8vL3FXIfxEnWMY8FTD5GYjeNwK3pbSCDEsTC30ysCK79/3HQY/MTggICABOZRTbYYHo9WuSiMjvhi/EWf90frGe3q2JmR8Ts65cwEJCVAOGgc3a6bD1vOVRj5wLVwY7U2dvR/vGRy1BB7TsgMH/HKAQzfVZlZEF0sjwHgtLC7GbySjvWCjojYS0vjIEcpBH8WTmwmIPmON4GEChksXF8MnotYX7NuMDGkb0vbaEeQ50E11A1R67SOnUzsjlsjgzvHx8cFRQKUFvQmpd/kaaD+sPoiYrqyfvDY39QPYOMTU1F8shn09g98WSOPi4szbEBuPy8BRY7V9l3L/34VDy2AvsdgXLfTGmZun9yY1PTw8Ll+DwenWI0j52A6awWGJzNQLj0VtenpsbHshWZXpQasTYO6ZJuTPCC3WQjFeix5LKpWap8dqNJohZHgmaA5DtQ35e6wtNnXS4wwojn2jUSimkH2ZtBpxnYp+67ce1pX7xBkF1KrV+S3IHIrxYuNJxbEd2SM4qoDDim/5+THrSD09bmzIn5eRPTiMNmYqLM2PDUMblNabzaE5PwbSZowHPdi0tsTQmKxor1EXFcXEDKnJf6q9xOBMCPvyVQG6aDGZhw80x8ZwK1h5ISzsRwe1Wt2B1MPHPZgYnqa3b1+4gOUKhUl/sP0Z7ITJycmowz5q3oxrfMBvvYBh6O7ZKcnvqY7dZuPXR8hQvOXSJdQc/7hhTB8TBjs6Ivz6pezsbKobmggYbJWOT1ADT8HFGxKW9LwTjRp4CujbTHj007t37kRHhGP5h5Tk5K0MduLce0/vvoyOjoiIuH4ddMoeBrzz2WvUMDrMDvpDFQa89Pkr4KCBo+7OYEdFpqLGcqqbMuDVaZGpqc/1OjycYerKohtpkZFl9ECG4qoihxvA9aN3ZDlXL5GDXR7Vr56BZtlYcAOwnQMdHXRPlmdd2U5kh5gffRHL0GSUXR5gKBeJ0tIiZ1UmLKlqlydygHD1s8EyYYe8PBFMjulVhbClEdy6kohLVTaJGEYW4eBr6MhsY1fi0ggoe7a3a7d84O6J5L8iNOiX3U+uoa/p8UPtoQAAAABJRU5ErkJggg==';
  118. /**
  119. * Returns the logo URL to be used in `<img src="`
  120. *
  121. * @return string the logo URL
  122. */
  123. public static function getYiiLogo()
  124. {
  125. return self::$_yiiLogo;
  126. }
  127. /**
  128. * Sets the logo URL to be used in `<img src="`
  129. *
  130. * @param string $logo the logo URL
  131. */
  132. public static function setYiiLogo($logo)
  133. {
  134. self::$_yiiLogo = $logo;
  135. }
  136. /**
  137. * {@inheritdoc}
  138. */
  139. public function init()
  140. {
  141. parent::init();
  142. $this->dataPath = Yii::getAlias($this->dataPath);
  143. if (Yii::$app instanceof \yii\web\Application) {
  144. $this->initPanels();
  145. }
  146. }
  147. /**
  148. * Initializes panels.
  149. */
  150. protected function initPanels()
  151. {
  152. // merge custom panels and core panels so that they are ordered mainly by custom panels
  153. if (empty($this->panels)) {
  154. $this->panels = $this->corePanels();
  155. } else {
  156. $corePanels = $this->corePanels();
  157. foreach ($corePanels as $id => $config) {
  158. if (isset($this->panels[$id])) {
  159. unset($corePanels[$id]);
  160. }
  161. }
  162. $this->panels = array_filter(array_merge($corePanels, $this->panels));
  163. }
  164. foreach ($this->panels as $id => $config) {
  165. if (is_string($config)) {
  166. $config = ['class' => $config];
  167. }
  168. $config['module'] = $this;
  169. $config['id'] = $id;
  170. $this->panels[$id] = Yii::createObject($config);
  171. if ($this->panels[$id] instanceof Panel && !$this->panels[$id]->isEnabled()) {
  172. unset($this->panels[$id]);
  173. }
  174. }
  175. }
  176. /**
  177. * {@inheritdoc}
  178. */
  179. public function bootstrap($app)
  180. {
  181. $this->logTarget = $app->getLog()->targets['debug'] = new LogTarget($this);
  182. // delay attaching event handler to the view component after it is fully configured
  183. $app->on(Application::EVENT_BEFORE_REQUEST, function () use ($app) {
  184. $app->getView()->on(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  185. $app->getResponse()->on(Response::EVENT_AFTER_PREPARE, [$this, 'setDebugHeaders']);
  186. });
  187. $app->getUrlManager()->addRules([
  188. [
  189. 'class' => 'yii\web\UrlRule',
  190. 'route' => $this->id,
  191. 'pattern' => $this->id,
  192. 'suffix' => false
  193. ],
  194. [
  195. 'class' => 'yii\web\UrlRule',
  196. 'route' => $this->id . '/<controller>/<action>',
  197. 'pattern' => $this->id . '/<controller:[\w\-]+>/<action:[\w\-]+>',
  198. 'suffix' => false
  199. ]
  200. ], false);
  201. }
  202. /**
  203. * {@inheritdoc}
  204. */
  205. public function beforeAction($action)
  206. {
  207. if (!$this->enableDebugLogs) {
  208. foreach ($this->get('log')->targets as $target) {
  209. $target->enabled = false;
  210. }
  211. }
  212. if (!parent::beforeAction($action)) {
  213. return false;
  214. }
  215. // do not display debug toolbar when in debug view mode
  216. Yii::$app->getView()->off(View::EVENT_END_BODY, [$this, 'renderToolbar']);
  217. Yii::$app->getResponse()->off(Response::EVENT_AFTER_PREPARE, [$this, 'setDebugHeaders']);
  218. if ($this->checkAccess()) {
  219. $this->resetGlobalSettings();
  220. return true;
  221. }
  222. if ($action->id === 'toolbar') {
  223. // Accessing toolbar remotely is normal. Do not throw exception.
  224. return false;
  225. }
  226. throw new ForbiddenHttpException('You are not allowed to access this page.');
  227. }
  228. /**
  229. * Setting headers to transfer debug data in AJAX requests
  230. * without interfering with the request itself.
  231. *
  232. * @param \yii\base\Event $event
  233. * @since 2.0.7
  234. */
  235. public function setDebugHeaders($event)
  236. {
  237. if (!$this->checkAccess()) {
  238. return;
  239. }
  240. $url = Url::toRoute(['/' . $this->id . '/default/view',
  241. 'tag' => $this->logTarget->tag,
  242. ]);
  243. $event->sender->getHeaders()
  244. ->set('X-Debug-Tag', $this->logTarget->tag)
  245. ->set('X-Debug-Duration', number_format((microtime(true) - YII_BEGIN_TIME) * 1000 + 1))
  246. ->set('X-Debug-Link', $url);
  247. }
  248. /**
  249. * Resets potentially incompatible global settings done in app config.
  250. */
  251. protected function resetGlobalSettings()
  252. {
  253. Yii::$app->assetManager->bundles = [];
  254. }
  255. /**
  256. * Gets toolbar HTML
  257. * @since 2.0.7
  258. */
  259. public function getToolbarHtml()
  260. {
  261. $url = Url::toRoute(['/' . $this->id . '/default/toolbar',
  262. 'tag' => $this->logTarget->tag,
  263. ]);
  264. return '<div id="yii-debug-toolbar" data-url="' . Html::encode($url) . '" style="display:none" class="yii-debug-toolbar-bottom"></div>';
  265. }
  266. /**
  267. * Renders mini-toolbar at the end of page body.
  268. *
  269. * @param \yii\base\Event $event
  270. */
  271. public function renderToolbar($event)
  272. {
  273. if (!$this->checkAccess() || Yii::$app->getRequest()->getIsAjax()) {
  274. return;
  275. }
  276. /* @var $view View */
  277. $view = $event->sender;
  278. echo $view->renderDynamic('return Yii::$app->getModule("' . $this->id . '")->getToolbarHtml();');
  279. // echo is used in order to support cases where asset manager is not available
  280. echo '<style>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.css') . '</style>';
  281. echo '<script>' . $view->renderPhpFile(__DIR__ . '/assets/toolbar.js') . '</script>';
  282. }
  283. /**
  284. * Checks if current user is allowed to access the module
  285. * @return bool if access is granted
  286. */
  287. protected function checkAccess()
  288. {
  289. $ip = Yii::$app->getRequest()->getUserIP();
  290. foreach ($this->allowedIPs as $filter) {
  291. if ($filter === '*' || $filter === $ip || (($pos = strpos($filter, '*')) !== false && !strncmp($ip, $filter, $pos))) {
  292. return true;
  293. }
  294. }
  295. foreach ($this->allowedHosts as $hostname) {
  296. $filter = gethostbyname($hostname);
  297. if ($filter === $ip) {
  298. return true;
  299. }
  300. }
  301. if (!$this->disableIpRestrictionWarning) {
  302. Yii::warning('Access to debugger is denied due to IP address restriction. The requesting IP address is ' . $ip, __METHOD__);
  303. }
  304. return false;
  305. }
  306. /**
  307. * @return array default set of panels
  308. */
  309. protected function corePanels()
  310. {
  311. return [
  312. 'config' => ['class' => 'yii\debug\panels\ConfigPanel'],
  313. 'request' => ['class' => 'yii\debug\panels\RequestPanel'],
  314. 'log' => ['class' => 'yii\debug\panels\LogPanel'],
  315. 'profiling' => ['class' => 'yii\debug\panels\ProfilingPanel'],
  316. 'db' => ['class' => 'yii\debug\panels\DbPanel'],
  317. 'event' => ['class' => 'yii\debug\panels\EventPanel'],
  318. 'assets' => ['class' => 'yii\debug\panels\AssetPanel'],
  319. 'mail' => ['class' => 'yii\debug\panels\MailPanel'],
  320. 'timeline' => ['class' => 'yii\debug\panels\TimelinePanel'],
  321. 'user' => ['class' => 'yii\debug\panels\UserPanel'],
  322. 'router' => ['class' => 'yii\debug\panels\RouterPanel'],
  323. ];
  324. }
  325. /**
  326. * {@inheritdoc}
  327. * @since 2.0.7
  328. */
  329. protected function defaultVersion()
  330. {
  331. $packageInfo = Json::decode(file_get_contents(dirname(__DIR__) . DIRECTORY_SEPARATOR . 'composer.json'));
  332. $extensionName = $packageInfo['name'];
  333. if (isset(Yii::$app->extensions[$extensionName])) {
  334. return Yii::$app->extensions[$extensionName]['version'];
  335. }
  336. return parent::defaultVersion();
  337. }
  338. }