From 63418879ff9b96bbe68413085a47b5e2606ed23c Mon Sep 17 00:00:00 2001 From: Alexander Ebert Date: Tue, 29 Sep 2026 20:51:10 +0200 Subject: [PATCH 01/19] Stop writing guest sessions for first-visit tracking and trigger pending background queue checks in-request --- com.woltlab.wcf/templates/footer.tpl | 7 +++++ .../templates/permissionDenied.tpl | 29 +++++++++---------- .../lib/action/AJAXProxyAction.class.php | 5 +++- .../install/files/lib/system/WCF.class.php | 11 +++++++ .../system/session/SessionHandler.class.php | 10 +++---- .../files/lib/util/HeaderUtil.class.php | 6 ---- 6 files changed, 40 insertions(+), 28 deletions(-) diff --git a/com.woltlab.wcf/templates/footer.tpl b/com.woltlab.wcf/templates/footer.tpl index b82160dd9d6..499d7b0fa5c 100644 --- a/com.woltlab.wcf/templates/footer.tpl +++ b/com.woltlab.wcf/templates/footer.tpl @@ -70,6 +70,13 @@ {event name='footer'} +{* Evaluated at the end of the page, because content and boxes may request a check after the head was rendered. *} +{if $__wcf->getBackgroundQueueHandler()->hasPendingCheck()} + +{/if} +
{event name='pageFooterStickyNotice'} diff --git a/com.woltlab.wcf/templates/permissionDenied.tpl b/com.woltlab.wcf/templates/permissionDenied.tpl index 2cba203f7e1..f9e48170353 100644 --- a/com.woltlab.wcf/templates/permissionDenied.tpl +++ b/com.woltlab.wcf/templates/permissionDenied.tpl @@ -1,20 +1,19 @@ {capture assign='pageTitle'}{lang}wcf.page.error.permissionDenied.title{/lang}{/capture} {capture assign='contentTitle'}{lang}wcf.page.error.permissionDenied.title{/lang}{/capture} -{if !$isFirstVisit} - {capture assign='contentHeaderNavigation'} - - {/capture} - - -{/if} +{capture assign='contentHeaderNavigation'} + +{/capture} + + {include file='header' __disableAds=true} diff --git a/wcfsetup/install/files/lib/action/AJAXProxyAction.class.php b/wcfsetup/install/files/lib/action/AJAXProxyAction.class.php index e6b9677e2cc..cdcdca34751 100644 --- a/wcfsetup/install/files/lib/action/AJAXProxyAction.class.php +++ b/wcfsetup/install/files/lib/action/AJAXProxyAction.class.php @@ -108,7 +108,10 @@ protected function sendResponse() if ( !RequestHandler::getInstance()->isACPRequest() - && (bool)WCF::getSession()->getVar('forceBackgroundQueuePerform') + && ( + BackgroundQueueHandler::getInstance()->hasPendingCheck() + || (bool)WCF::getSession()->getVar('forceBackgroundQueuePerform') + ) ) { @\header( \sprintf( diff --git a/wcfsetup/install/files/lib/system/WCF.class.php b/wcfsetup/install/files/lib/system/WCF.class.php index d29a6710deb..8012037757b 100644 --- a/wcfsetup/install/files/lib/system/WCF.class.php +++ b/wcfsetup/install/files/lib/system/WCF.class.php @@ -12,6 +12,7 @@ use wcf\data\user\User; use wcf\system\application\ApplicationHandler; use wcf\system\application\IApplication; +use wcf\system\background\BackgroundQueueHandler; use wcf\system\benchmark\Benchmark; use wcf\system\box\BoxHandler; use wcf\system\cache\builder\PackageUpdateCacheBuilder; @@ -1088,6 +1089,16 @@ public function getBoxHandler(): BoxHandler return BoxHandler::getInstance(); } + /** + * Returns the background queue handler. + * + * @since 6.3 + */ + public function getBackgroundQueueHandler(): BackgroundQueueHandler + { + return BackgroundQueueHandler::getInstance(); + } + /** * Returns number of available updates. */ diff --git a/wcfsetup/install/files/lib/system/session/SessionHandler.class.php b/wcfsetup/install/files/lib/system/session/SessionHandler.class.php index 0ac288a471c..719df554dd5 100644 --- a/wcfsetup/install/files/lib/system/session/SessionHandler.class.php +++ b/wcfsetup/install/files/lib/system/session/SessionHandler.class.php @@ -372,12 +372,6 @@ public function initSession(): void // assign language $languageID = $this->getVar('languageID') ?: $this->user->languageID; $this->languageID = $languageID ?: 0; - - // https://github.com/WoltLab/WCF/issues/2568 - if ($this->getVar('__wcfIsFirstVisit') === true) { - $this->firstVisit = true; - $this->unregister('__wcfIsFirstVisit'); - } } /** @@ -507,6 +501,10 @@ public function unregister(string $key): void { $scope = $this->isACP ? 'acp' : 'frontend'; + if (!\array_key_exists($key, $this->variables[$scope] ?? [])) { + return; + } + unset($this->variables[$scope][$key]); $this->variablesChanged = true; } diff --git a/wcfsetup/install/files/lib/util/HeaderUtil.class.php b/wcfsetup/install/files/lib/util/HeaderUtil.class.php index 075572dabc3..54757a3e933 100644 --- a/wcfsetup/install/files/lib/util/HeaderUtil.class.php +++ b/wcfsetup/install/files/lib/util/HeaderUtil.class.php @@ -9,7 +9,6 @@ use wcf\system\event\EventHandler; use wcf\system\request\RequestHandler; use wcf\system\request\RouteHandler; -use wcf\system\session\SessionHandler; use wcf\system\WCF; /** @@ -228,11 +227,6 @@ public static function parseOutputStream(StreamInterface $input): StreamInterfac */ public static function redirect(string $location, bool $sendStatusCode = false, bool $temporaryRedirect = true): void { - // https://github.com/WoltLab/WCF/issues/2568 - if (SessionHandler::getInstance()->isFirstVisit()) { - SessionHandler::getInstance()->register('__wcfIsFirstVisit', true); - } - if ($sendStatusCode) { if ($temporaryRedirect) { @\header('HTTP/1.1 307 Temporary Redirect'); From f59dba55ba10292ab7fb89f7b48ffe9fac1456e3 Mon Sep 17 00:00:00 2001 From: Alexander Ebert Date: Tue, 29 Sep 2026 21:12:37 +0200 Subject: [PATCH 02/19] Add opt-in on-demand guest sessions option and sessionless signed captcha question tokens --- com.woltlab.wcf/option.xml | 5 + phpstan-ambient.neon | 1 + .../update_com.woltlab.wcf_6.3_step1.php | 14 +++ .../captcha/CaptchaQuestionHandler.class.php | 107 +++++++++++++++++- .../cronjob/DailyCleanUpCronjob.class.php | 2 + .../system/session/SessionHandler.class.php | 17 +++ .../files/lib/util/HeaderUtil.class.php | 8 ++ wcfsetup/install/files/options.inc.php | 1 + wcfsetup/install/lang/de.xml | 2 + wcfsetup/install/lang/en.xml | 2 + wcfsetup/setup/db/install_com.woltlab.wcf.php | 13 +++ 11 files changed, 166 insertions(+), 6 deletions(-) diff --git a/com.woltlab.wcf/option.xml b/com.woltlab.wcf/option.xml index 015fb45b044..c17dc84e241 100644 --- a/com.woltlab.wcf/option.xml +++ b/com.woltlab.wcf/option.xml @@ -285,6 +285,11 @@ boolean 0 +