From b085cb44c18e8e2d51ab313cb58ebd8df29224f2 Mon Sep 17 00:00:00 2001 From: jakubvrana Date: Wed, 11 Jul 2007 08:03:08 +0000 Subject: [PATCH] Generate token before session close git-svn-id: https://adminer.svn.sourceforge.net/svnroot/adminer/trunk@114 7c3ca157-0c34-0410-bff1-cbf682f78f5c --- auth.inc.php | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/auth.inc.php b/auth.inc.php index 69fe4f75..41e9ab83 100644 --- a/auth.inc.php +++ b/auth.inc.php @@ -30,6 +30,9 @@ if (isset($_POST["server"])) { } if (!isset($_SESSION["usernames"][$_GET["server"]]) || !$mysql->connect($_GET["server"], $_SESSION["usernames"][$_GET["server"]], $_SESSION["passwords"][$_GET["server"]])) { + if ($_POST["token"]) { + $_POST["token"] = token(); + } page_header(lang('Login')); if (isset($_SESSION["usernames"][$_GET["server"]])) { echo "

" . lang('Invalid credentials.') . "

\n"; @@ -56,8 +59,6 @@ if (!isset($_SESSION["usernames"][$_GET["server"]]) || !$mysql->connect($_GET["s } } } - } elseif ($key == "token") { - echo ''; } elseif (!in_array($key, $ignore)) { echo ''; }