mirror of
https://git.code.sf.net/p/seeddms/code
synced 2025-05-11 20:21:16 +00:00
- no need to sanitize the session cookie, it is properly quoted when used
in the select statement
This commit is contained in:
parent
303e9ed124
commit
f2e279f4c5
|
@ -26,7 +26,7 @@ require_once("inc.ClassEmail.php");
|
|||
require_once("inc.ClassSession.php");
|
||||
|
||||
/* Load session */
|
||||
$dms_session = sanitizeString($_COOKIE["mydms_session"]);
|
||||
$dms_session = $_COOKIE["mydms_session"];
|
||||
$session = new LetoDMS_Session($db);
|
||||
if(!$resArr = $session->load($dms_session)) {
|
||||
setcookie("mydms_session", $dms_session, time()-3600, $settings->_httpRoot); //delete cookie
|
||||
|
|
Loading…
Reference in New Issue
Block a user