#59 We check for an active user on login

merge-requests/2/head
Mike Koch 10 years ago
parent 270a796090
commit 6c126ec78e

@ -197,10 +197,21 @@ function do_login()
unset($_SESSION['pass']);
/* Login successful, clean brute force attempts */
hesk_cleanBfAttempts();
/* Regenerate session ID (security) */
/* Make sure our user is active */
if (!$_SESSION['active']) {
hesk_session_stop();
$_SESSION['a_iserror'] = array('active');
hesk_process_messages($hesklang['inactive_user'], 'NOREDIRECT');
print_login();
exit();
}
/* Regenerate session ID (security) */
hesk_session_regenerate_id();
/* Remember username? */

Loading…
Cancel
Save