web app security fix
This commit is contained in:
@@ -1,8 +1,11 @@
|
||||
<?php
|
||||
|
||||
// logout once session expire
|
||||
if(!isset($_SESSION["otp"])){
|
||||
// Redirect to login if the user has not completed full authentication.
|
||||
// login_company_id is only written by login_confirm.php after OTP is verified —
|
||||
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
||||
if(empty($_SESSION["login_company_id"])){
|
||||
header('Location: '.$server_url.'login/index.php');
|
||||
exit;
|
||||
}
|
||||
|
||||
require 'preset.php';
|
||||
|
||||
Reference in New Issue
Block a user