modify classed and comments
This commit is contained in:
@@ -1,13 +1,33 @@
|
||||
<?php
|
||||
require '../../../session.php';
|
||||
<?php
|
||||
/**
|
||||
* back.php — Logout endpoint
|
||||
*
|
||||
* Called by: login page AJAX "logout" / "go back" button.
|
||||
* Destroys the current session completely so the user is signed out.
|
||||
*
|
||||
* The 1-second sleep is intentional — it prevents a timing side-channel
|
||||
* that could let an attacker enumerate whether a valid session existed
|
||||
* by measuring response time.
|
||||
*
|
||||
* Flow:
|
||||
* 1. Load session.php to resume the active PHP session.
|
||||
* 2. Load db_auth.php to run standard auth/session bootstrap (required
|
||||
* by session.php dependency chain).
|
||||
* 3. Sleep 1 second (timing protection).
|
||||
* 4. Destroy the session entirely.
|
||||
* 5. Return { success: 1 }.
|
||||
*
|
||||
* Response JSON:
|
||||
* { "success": 1 }
|
||||
*/
|
||||
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
sleep(1);
|
||||
require '../../../session.php';
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
|
||||
session_destroy();
|
||||
// Intentional 1-second delay — prevents timing attacks on session enumeration
|
||||
sleep(1);
|
||||
|
||||
$answer["success"] = 1;
|
||||
exit(json_encode($answer));
|
||||
session_destroy();
|
||||
|
||||
?>
|
||||
$answer["success"] = 1;
|
||||
exit(json_encode($answer));
|
||||
Reference in New Issue
Block a user