Don't log the user out after changing account info
Also include * username validation -- no spaces or weird chars * no longer base64 encoded sha1-hex hash for CSRF token * refresh login page every two hours to keep session active
Showing
- include/class.csrf.php 2 additions, 7 deletionsinclude/class.csrf.php
- include/class.staff.php 4 additions, 3 deletionsinclude/class.staff.php
- include/class.usersession.php 1 addition, 1 deletioninclude/class.usersession.php
- include/class.validator.php 11 additions, 2 deletionsinclude/class.validator.php
- include/staff/login.header.php 1 addition, 0 deletionsinclude/staff/login.header.php
- include/staff/login.tpl.php 1 addition, 1 deletioninclude/staff/login.tpl.php
- scp/staff.inc.php 1 addition, 1 deletionscp/staff.inc.php
Loading
Please register or sign in to comment