Fix login redirect and hide PHP errors on pages
This commit is contained in:
@@ -27,6 +27,11 @@ class db_statement extends PDOStatement {
|
|||||||
$this->pdo = $pdo;
|
$this->pdo = $pdo;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// PDOStatement::execute() is declared ?array $params = null : bool. This
|
||||||
|
// override deliberately accepts a looser signature so callers may pass
|
||||||
|
// positional arguments (see func_get_args() below), so the tightened return
|
||||||
|
// type is opted out of rather than the call sites being changed.
|
||||||
|
#[\ReturnTypeWillChange]
|
||||||
public function execute($args = null) {
|
public function execute($args = null) {
|
||||||
// Perform logging here. PDO object is accessible
|
// Perform logging here. PDO object is accessible
|
||||||
// from $this->pdo.
|
// from $this->pdo.
|
||||||
|
|||||||
@@ -1,4 +1,23 @@
|
|||||||
<?php
|
<?php
|
||||||
|
// Output buffering must be active before the first byte of HTML below, so that
|
||||||
|
// header() calls made later in the page still work — notably the
|
||||||
|
// not-logged-in redirect in include_topbar.php, which runs *after* this file
|
||||||
|
// has already emitted <!DOCTYPE html>. Without a buffer that redirect depends
|
||||||
|
// entirely on php.ini's output_buffering: it is on for the dev stack but off
|
||||||
|
// in production, where every protected page answered 200 with a half-rendered
|
||||||
|
// body instead of sending the browser to the login form. session.php starts a
|
||||||
|
// buffer for the same reason.
|
||||||
|
if (ob_get_level() === 0) {
|
||||||
|
ob_start();
|
||||||
|
}
|
||||||
|
|
||||||
|
// Never render PHP notices/warnings into the page: they leak absolute server
|
||||||
|
// paths to anonymous visitors and corrupt the markup. Errors still reach the
|
||||||
|
// server log. This mirrors the policy db_auth.php already applies to the JSON
|
||||||
|
// API routes, and keeps the app safe even where php.ini has display_errors on.
|
||||||
|
ini_set('display_errors', '0');
|
||||||
|
ini_set('log_errors', '1');
|
||||||
|
|
||||||
// Security headers — emitted before any HTML output.
|
// Security headers — emitted before any HTML output.
|
||||||
header('X-Content-Type-Options: nosniff');
|
header('X-Content-Type-Options: nosniff');
|
||||||
header('X-Frame-Options: SAMEORIGIN');
|
header('X-Frame-Options: SAMEORIGIN');
|
||||||
|
|||||||
@@ -8,6 +8,11 @@ require_once __DIR__ . '/assets/utils/classes/UsageGuard.php';
|
|||||||
// login_company_id is only written by login_confirm.php after OTP is verified —
|
// login_company_id is only written by login_confirm.php after OTP is verified —
|
||||||
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
// using it (not "otp") ensures half-logged-in sessions are also redirected.
|
||||||
if(empty($_SESSION["login_company_id"])){
|
if(empty($_SESSION["login_company_id"])){
|
||||||
|
// Discard the markup include_header.php has already buffered so the browser
|
||||||
|
// receives a clean redirect rather than a partially rendered page body.
|
||||||
|
while (ob_get_level() > 0) {
|
||||||
|
ob_end_clean();
|
||||||
|
}
|
||||||
header('Location: '.$server_url.'login/index.php');
|
header('Location: '.$server_url.'login/index.php');
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user