]> andersk Git - sql-web.git/blobdiff - index.php
Fix CSRF vulnerabilities
[sql-web.git] / index.php
index 7cceea03cfd527c5a17489ad1d76cb07f2175a0e..386d5f7a304c24285fdf52af752f68af03cc887a 100755 (executable)
--- a/index.php
+++ b/index.php
@@ -9,7 +9,10 @@
 require_once('mitsql.cfg.php');
 require_once('mitsql.lib.php');
 
+if (substr(URI, -strlen('do/index')) != 'do/index') redirect('main/do/index');
 isLoggedIn() && redirect('main');
+//!DEVEL && $_SERVER['SERVER_NAME'] != 'sql.mit.edu' && redirect2('http://sql.mit.edu/');
+
 //$LoginSSL->canSignup() && redirect('signup');
 //redirect('login');
 
This page took 0.024621 seconds and 4 git commands to generate.