modify classed and comments

This commit is contained in:
Thanakorn S
2026-04-29 14:21:09 +07:00
parent 2061624641
commit f6dc9a3278
15 changed files with 4122 additions and 2638 deletions
+29 -9
View File
@@ -1,13 +1,33 @@
<?php
require '../../../session.php';
<?php
/**
* back.php — Logout endpoint
*
* Called by: login page AJAX "logout" / "go back" button.
* Destroys the current session completely so the user is signed out.
*
* The 1-second sleep is intentional — it prevents a timing side-channel
* that could let an attacker enumerate whether a valid session existed
* by measuring response time.
*
* Flow:
* 1. Load session.php to resume the active PHP session.
* 2. Load db_auth.php to run standard auth/session bootstrap (required
* by session.php dependency chain).
* 3. Sleep 1 second (timing protection).
* 4. Destroy the session entirely.
* 5. Return { success: 1 }.
*
* Response JSON:
* { "success": 1 }
*/
require '../../../assets/utils/db_auth.php';
sleep(1);
require '../../../session.php';
require '../../../assets/utils/db_auth.php';
session_destroy();
// Intentional 1-second delay — prevents timing attacks on session enumeration
sleep(1);
$answer["success"] = 1;
exit(json_encode($answer));
session_destroy();
?>
$answer["success"] = 1;
exit(json_encode($answer));