]> andersk Git - sql-web.git/blobdiff - global.act.php
Fix CSRF vulnerabilities
[sql-web.git] / global.act.php
index 1a9b64d6731d16c3454280a00d0fed254341f553..ee34748a31ab6385433813a80b9ed737c6935eb8 100644 (file)
@@ -1,4 +1,7 @@
 <?php
+/*
+       (c) 2005 Joe Presbrey
+*/
 
 require_once('mitsql.cfg.php');
 require_once('mitsql.lib.php');
@@ -35,22 +38,26 @@ if (isOnline()) {
 
                /*$LoginSSL = sess('LoginSSL');
                if (!is_a($LoginSSL, 'Login')) { $LoginSSL = new Login($SSLUsername); }*/
-               $LoginSSL = new Login($SSLUsername);
+               $LoginSSL = new Login(getUsernameID($SSLUsername));
                $LoginSSL->update($SSLCred['Name'],$SSLCred['Email']);
 
                if (!isLoggedIn() && !$LoginSSL->exists()) {
                        if (!empty($SSLName))
                                addUser($SSLCred);
-                       $LoginSSL->refresh();
+                       $LoginSSL = new Login(getUsernameID($SSLUsername));
                }
        } else {
                unset($_SESSION['LoginSSL']);
        }
 
+       /*
        if (isPost() || isset($i_refresh)) {
-               checkQuotas($UserId);
-               isset($i_refresh) && redirect('main');
+               if (!empty($UserId)) {
+                       checkQuotas($UserId);
+               }
+               isset($i_refresh) && redirect('main?r');
        }
+       */
 
 } // isOnline()
 
This page took 0.072324 seconds and 4 git commands to generate.