closing security gap [ignore guarding change for now]
This commit is contained in:
@@ -77,6 +77,13 @@ if(!empty($_SESSION["login_company_id"])){
|
||||
|
||||
}
|
||||
|
||||
// Fail closed — reject any request that arrives without an authenticated session
|
||||
// unless the engine explicitly declared itself a pre-auth route.
|
||||
if (empty($_SESSION['login_company_id']) && !defined('UNAUTHENTICATED_ROUTE')) {
|
||||
http_response_code(401);
|
||||
exit(json_encode(['success' => 0, 'message' => 'Authentication required.']));
|
||||
}
|
||||
|
||||
// set up ANSWER
|
||||
$answer = array("success"=>0, "message"=>"");
|
||||
|
||||
|
||||
Reference in New Issue
Block a user