Start every session through session.php; idle timeout, app access and auth status codes
This commit is contained in:
@@ -19,6 +19,18 @@ if(empty($_SESSION["login_company_id"])){
|
||||
}
|
||||
|
||||
require 'preset.php';
|
||||
require_once __DIR__ . '/assets/utils/app_access.php';
|
||||
|
||||
// Accounting pages require accounting app access; the menus below only hide the
|
||||
// links, this stops a WMS-only user who opens the URL directly.
|
||||
$_page_app = app_access_app_for($_SERVER['SCRIPT_NAME'] ?? '');
|
||||
if ($_page_app !== null && !app_access_allows($_SESSION['login_app_access'] ?? 'wms', $_page_app)) {
|
||||
while (ob_get_level() > 0) {
|
||||
ob_end_clean();
|
||||
}
|
||||
header('Location: '.$server_url.'dashboard/index.php');
|
||||
exit;
|
||||
}
|
||||
|
||||
// ── User display data from session ────────────────────────────────────────────
|
||||
$topbar_name = htmlspecialchars(trim(($_SESSION['login_name'] ?? '') . ' ' . ($_SESSION['login_surname'] ?? '')), ENT_QUOTES, 'UTF-8');
|
||||
@@ -367,6 +379,7 @@ function log_out() {
|
||||
checkRequired: 0,
|
||||
action: 'read',
|
||||
onSuccess: function(res) {
|
||||
try { sessionStorage.clear(); } catch (e) {}
|
||||
window.location.href = server_url + 'index.php';
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user