web app security fix

This commit is contained in:
Thanakorn S
2026-05-11 13:49:44 +07:00
parent d989e59edc
commit 7a87909392
7 changed files with 107 additions and 21 deletions
+5 -2
View File
@@ -1,8 +1,11 @@
<?php
// logout once session expire
if(!isset($_SESSION["otp"])){
// Redirect to login if the user has not completed full authentication.
// login_company_id is only written by login_confirm.php after OTP is verified —
// using it (not "otp") ensures half-logged-in sessions are also redirected.
if(empty($_SESSION["login_company_id"])){
header('Location: '.$server_url.'login/index.php');
exit;
}
require 'preset.php';