mirror of
				https://git.code.sf.net/p/seeddms/code
				synced 2025-10-31 13:18:06 +00:00 
			
		
		
		
	allways use http only cookie, pass referuri to controller
This commit is contained in:
		
							parent
							
								
									22fa26bdb7
								
							
						
					
					
						commit
						b1560bb87b
					
				|  | @ -36,6 +36,7 @@ class SeedDMS_Controller_Login extends SeedDMS_Controller_Common { | |||
| 		$settings = $this->params['settings']; | ||||
| 		$session = $this->params['session']; | ||||
| 		$sesstheme = $this->params['sesstheme']; | ||||
| 		$referuri = $this->params['referuri']; | ||||
| 		$lang = $this->params['lang']; | ||||
| 		$login = $this->params['login']; | ||||
| 		$pwd = $this->params['pwd']; | ||||
|  | @ -199,8 +200,8 @@ class SeedDMS_Controller_Login extends SeedDMS_Controller_Common { | |||
| 			$dms_session = $_COOKIE["mydms_session"]; | ||||
| 			if(!$resArr = $session->load($dms_session)) { | ||||
| 				/* Turn off http only cookies if jumploader is enabled */ | ||||
| 				setcookie("mydms_session", $dms_session, time()-3600, $settings->_httpRoot, null, null, !$settings->_enableLargeFileUpload); //delete cookie
 | ||||
| 				header("Location: " . $settings->_httpRoot . "out/out.Login.php?referuri=".$refer); | ||||
| 				setcookie("mydms_session", $dms_session, time()-3600, $settings->_httpRoot, null, false, true); //delete cookie
 | ||||
| 				header("Location: " . $settings->_httpRoot . "out/out.Login.php?referuri=".$referuri); | ||||
| 				exit; | ||||
| 			} else { | ||||
| 				$session->updateAccess($dms_session); | ||||
|  | @ -218,7 +219,7 @@ class SeedDMS_Controller_Login extends SeedDMS_Controller_Common { | |||
| 				$lifetime = time() + intval($settings->_cookieLifetime); | ||||
| 			else | ||||
| 				$lifetime = 0; | ||||
| 			setcookie("mydms_session", $id, $lifetime, $settings->_httpRoot, null, null, !$settings->_enableLargeFileUpload); | ||||
| 			setcookie("mydms_session", $id, $lifetime, $settings->_httpRoot, null, false, true); | ||||
| 		} | ||||
| 
 | ||||
| 		if($this->callHook('postLogin', $user)) { | ||||
|  |  | |||
		Loading…
	
		Reference in New Issue
	
	Block a user
	 Uwe Steinmann
						Uwe Steinmann