mirror of
https://github.com/jakejarvis/spoons.git
synced 2025-04-26 18:08:27 -04:00
disabling remember password option until I fix massive 3-year-old security hole. oops.... (issue #12)
This commit is contained in:
parent
70be24caf5
commit
d5f12cf9c6
@ -6,19 +6,11 @@ session_start();
|
|||||||
if($_SESSION['logged_in']) {
|
if($_SESSION['logged_in']) {
|
||||||
header("Location:" . $site_url . "/");
|
header("Location:" . $site_url . "/");
|
||||||
die();
|
die();
|
||||||
} else if($_COOKIE['remembered'] == 'TRUE') {
|
|
||||||
$_SESSION['logged_in'] = TRUE;
|
|
||||||
header("Location:" . $site_url . "/");
|
|
||||||
die();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if(isset($_POST['password'])) {
|
if(isset($_POST['password'])) {
|
||||||
if($_POST['password'] == $site_password) {
|
if($_POST['password'] == $site_password) {
|
||||||
$_SESSION['logged_in'] = TRUE;
|
$_SESSION['logged_in'] = TRUE;
|
||||||
if($_POST['remember'] == "remember") {
|
|
||||||
$threeMonths = 60 * 60 * 24 * 90 + time();
|
|
||||||
setcookie('remembered', 'TRUE', $threeMonths);
|
|
||||||
}
|
|
||||||
header("Location:" . $site_url . "/");
|
header("Location:" . $site_url . "/");
|
||||||
die();
|
die();
|
||||||
} else {
|
} else {
|
||||||
@ -218,9 +210,9 @@ if(isset($_POST['password'])) {
|
|||||||
<img src="<?php echo $site_url ?>/assets/img/paulblart.png">
|
<img src="<?php echo $site_url ?>/assets/img/paulblart.png">
|
||||||
|
|
||||||
<input type="password" name="password" class="input-block-level" placeholder="Password">
|
<input type="password" name="password" class="input-block-level" placeholder="Password">
|
||||||
<label class="checkbox">
|
<!--<label class="checkbox">
|
||||||
<input type="checkbox" name="remember" value="remember"> Remember this device
|
<input type="checkbox" name="remember" value="remember"> Remember this device
|
||||||
</label>
|
</label>-->
|
||||||
<button class="btn btn-large btn-success submit" type="submit">Leggo!</button>
|
<button class="btn btn-large btn-success submit" type="submit">Leggo!</button>
|
||||||
</form>
|
</form>
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user