login: block concurrent login, single-factor auth for staff/viewer
This commit is contained in:
@@ -108,6 +108,17 @@
|
||||
action: 'read',
|
||||
onSuccess: function(res) {
|
||||
|
||||
if (res.skip_otp) {
|
||||
// Staff/viewer — no OTP required, confirm session directly
|
||||
return ajax_request({
|
||||
url: "<?php echo $server_url?>login/api/engine/login_confirm.php",
|
||||
data: { json: JSON.stringify({ otp: '', action: 'read' }) },
|
||||
onSuccess: function() {
|
||||
window.location.href = "<?php echo $server_url?>index.php";
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
window.location.href = "<?php echo $server_url?>index.php";
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user