login/ block concurrent login, allow single factor authen for staff and viewer
This commit is contained in:
@@ -25,6 +25,12 @@ require_once '../../../session.php';
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require_once '../../../assets/utils/db_auth.php';
|
||||
|
||||
// Clear session token so the account is free to log in elsewhere immediately
|
||||
if (!empty($_SESSION['login_user_id'])) {
|
||||
$pdo1->prepare("UPDATE user SET session_token = NULL, session_token_at = NULL WHERE user_id = :uid")
|
||||
->execute([':uid' => (int)$_SESSION['login_user_id']]);
|
||||
}
|
||||
|
||||
// Intentional 1-second delay — prevents timing attacks on session enumeration
|
||||
sleep(1);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user