From 467a55acd9651c8a9ce7367b7c7f0ee9d653b108 Mon Sep 17 00:00:00 2001
From: Jacek Kowalski <Jacek@jacekk.info>
Date: Wed, 07 Aug 2019 15:12:39 +0000
Subject: [PATCH] Add logoutLocal() method that only clears local session and does not logout from the CAS server.

---
 uphpCAS.php |   27 +++++++++++++++++++++------
 1 files changed, 21 insertions(+), 6 deletions(-)

diff --git a/uphpCAS.php b/uphpCAS.php
index 955d204..98a3134 100644
--- a/uphpCAS.php
+++ b/uphpCAS.php
@@ -56,7 +56,16 @@
 		if($port != 0) {
 			$url .= ':'.$port;
 		}
+		
 		$url .= $_SERVER['REQUEST_URI'];
+		
+		if(isset($_GET['ticket'])) {
+			$pos = max(
+				strrpos($url, '?ticket='),
+				strrpos($url, '&ticket=')
+			);
+			$url = substr($url, 0, $pos);
+		}
 		
 		return $url;
 	}
@@ -113,10 +122,14 @@
 			.($returnUrl ? '?service='.urlencode($returnUrl) : '');
 	}
 	
+	public function logoutLocal() {
+		@session_start();
+		unset($_SESSION[$this->sessionName]);
+	}
+	
 	public function logout($returnUrl = NULL) {
-		session_start();
+		$this->logoutLocal();
 		if($this->isAuthenticated()) {
-			unset($_SESSION[$this->sessionName]);
 			header('Location: '.$this->logoutUrl($returnUrl));
 			die();
 		} elseif($returnUrl) {
@@ -130,7 +143,7 @@
 	}
 	
 	public function authenticate() {
-		session_start();
+		@session_start();
 		if($this->isAuthenticated()) {
 			return $_SESSION[$this->sessionName];
 		} elseif(isset($_REQUEST['ticket'])) {
@@ -219,13 +232,15 @@
 				}
 			}
 		} catch(Exception $e) {
-			throw new JasigException('Authentication error: CAS server'
-					.' response invalid - parse error', 0, $e);
-		} finally {
 			libxml_clear_errors();
 			libxml_disable_entity_loader($xmlEntityLoader);
 			libxml_use_internal_errors($xmlInternalErrors);
+			throw new JasigException('Authentication error: CAS server'
+					.' response invalid - parse error', 0, $e);
 		}
+		libxml_clear_errors();
+		libxml_disable_entity_loader($xmlEntityLoader);
+		libxml_use_internal_errors($xmlInternalErrors);
 		
 		$failure = $xml->getElementsByTagName('authenticationFailure');
 		$success = $xml->getElementsByTagName('authenticationSuccess');

--
Gitblit v1.9.1