Start every session through session.php; idle timeout, app access and auth status codes
This commit is contained in:
@@ -34,7 +34,8 @@ if (!empty($_SESSION['login_user_id'])) {
|
||||
// Intentional 1-second delay — prevents timing attacks on session enumeration
|
||||
sleep(1);
|
||||
|
||||
session_destroy();
|
||||
// Clears the session data, deletes the session file and expires the cookie.
|
||||
session_end_completely();
|
||||
|
||||
$answer["success"] = 1;
|
||||
exit(json_encode($answer));
|
||||
Reference in New Issue
Block a user