I've been tasked to fix the "Session based back button" in one of our company's ancient PHP based internal systems.
The main idea was to log the user's navigation through the system, and allow them to navigate back whenever they want to any of the previously visited sites (with a few exceptions) without using the browser's built in back button. The system is built to require both POST and GET requests upon navigating (searching up a name with filtering for example) and resubmit it upon clicking the site's back button. I do not have permission to modify this part sadly, so "fixing" the browser button is not an option for me.
The trackable sites have a "Header" php included into it, which has the following function:
<?php
if(isset($_GET["backButton"]))
{
$curpage = $_SERVER["SCRIPT_FILENAME"];
$backId = (count($_SESSION["visitedPages"])-1);
if(isset($_GET["backId"])) { $backId = $_GET["backId"]; }
if($curpage == $_SESSION["visitedPages"][$backId]["file"])
{
$vGet = unserialize($_SESSION["visitedPages"][$backId]["GET"]);
$vPost = unserialize($_SESSION["visitedPages"][$backId]["POST"]);
if(count($vGet) > 0) { $_GET = $vGet; }
if(count($vPost) > 0) { $_POST = $vPost; }
$backURL = explode("/var/www/", $curpage)[1];
$bdeli = (strpos($backURL, ".php?") !== false) ? "&" : "?";
$usedIndexes = array();
foreach($_GET as $index => $val)
{
if(!in_array($index, $usedIndexes)) {
$backURL .= $bdeli . $index . ((strlen($val) > 0) ? "=" .$val : "");
$bdeli = "&";
array_push($usedIndexes, $index);
}
}
echo '<script>
window.history.pushState("backButton", "backButton", "'.$backURL.'");
</script>';
unset($_SESSION["visitedPages"][$backId+1]);
$_SESSION["visitedPages"] = array_values($_SESSION["visitedPages"]);
} else
{
for($i = (count($_SESSION["visitedPages"])-1); $i > 0; $i--)
{
$backURL = explode("/var/www/", $$_SESSION["visitedPages"][$i]["file"])[1];
if($curpage == $_SESSION["visitedPages"][$i]["file"]) { echo '<script>window.location.href = "'.$backURL.'?backButton&backId='.$i.'";</script>'; die(); break; }
}
}
}
...
if(!isset($_SESSION["visitedPages"])) { $_SESSION["visitedPages"] = array(); }
if(!isset($_GET["newsession"]) && !isset($_GET["ajax"]) && !isset($_GET["ip"]) && !isset($_GET["backButton"]))
{
$lastPage = $_SESSION["visitedPages"][(count($_SESSION["visitedPages"])-1)];
if($lastPage["file"] != $_SERVER["SCRIPT_FILENAME"]) { $_SESSION["visitedPages"][count($_SESSION["visitedPages"])] = array("file" => $_SERVER["SCRIPT_FILENAME"], "GET" => serialize($_GET), "POST" => serialize($_POST)); }
}
It would do it's job, if the users would only open one instance of the system in one session, but obviously in 2021 that's not the case, so the users usually work with 5-10 tabs open simultaneously, which defeats the indexing system in this form.
My question is, that how can I restrict or "sandbox" the open tabs, so they aren't touching the others' history? Example: Tab1: Site1 -> Site2 -> Site4 ... SiteN Tab2: Site4 -> Site1 -> Site3 ... SiteN
If user presses the back button on Tab1 but worked in Tab2, the page is gonna look up the session indexes, and redirect user to Site2...