closing security gap [ignore guarding change for now]

This commit is contained in:
Thanakorn S
2026-05-07 10:29:14 +07:00
parent a24930f684
commit a75d37e841
13 changed files with 39 additions and 93 deletions
+7
View File
@@ -77,6 +77,13 @@ if(!empty($_SESSION["login_company_id"])){
}
// Fail closed — reject any request that arrives without an authenticated session
// unless the engine explicitly declared itself a pre-auth route.
if (empty($_SESSION['login_company_id']) && !defined('UNAUTHENTICATED_ROUTE')) {
http_response_code(401);
exit(json_encode(['success' => 0, 'message' => 'Authentication required.']));
}
// set up ANSWER
$answer = array("success"=>0, "message"=>"");