Version 4.6.0
This commit is contained in:
1 parent
f79dcf067a
commit
517a5e1f70
2036 files changed
+110041
-26162
No files matched your search
@@ -70,6 +70,9 @@ abstract class _Session
|
||||
{
|
||||
/* Create class */
|
||||
static::$instance = new $classname;
|
||||
|
||||
/* Remove PHPs own cache headers */
|
||||
session_cache_limiter('');
|
||||
|
||||
/* Name the session */
|
||||
$name = session_name( ( \IPS\COOKIE_PREFIX !== NULL ) ? \IPS\COOKIE_PREFIX . 'IPSSession' . $location : 'IPSSession' . $location );
|
||||
@@ -204,6 +207,14 @@ abstract class _Session
|
||||
$this->member->save();
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Ensure any loggedIn cookies are removed */
|
||||
if( isset( \IPS\Request::i()->cookie['loggedIn'] ) )
|
||||
{
|
||||
\IPS\Request::i()->setCookie( 'loggedIn', NULL );
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -223,7 +234,15 @@ abstract class _Session
|
||||
*/
|
||||
public function csrfCheck()
|
||||
{
|
||||
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, (string) \IPS\Request::i()->csrfKey ) )
|
||||
$token = (string) \IPS\Request::i()->csrfKey;
|
||||
|
||||
/* Guests may provide the csrf token via a header */
|
||||
if ( !\IPS\Member::loggedIn()->member_id && isset( $_SERVER['HTTP_X_CSRF_TOKEN'] ) )
|
||||
{
|
||||
$token = $_SERVER['HTTP_X_CSRF_TOKEN'];
|
||||
}
|
||||
|
||||
if ( !\IPS\Login::compareHashes( (string) $this->csrfKey, $token ) )
|
||||
{
|
||||
\IPS\Output::i()->error( 'generic_error', '2S119/1', 403, 'admin_csrf_error' );
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user