fix cookies and at same time add better secure for cookies
This commit is contained in:
parent
ad7c192a90
commit
e78b2b28a9
@ -26,7 +26,7 @@ class UserManager
|
|||||||
if ($user = Db::loadOne ('SELECT * FROM users WHERE LOWER(username)=LOWER(?)', array ($username))) {
|
if ($user = Db::loadOne ('SELECT * FROM users WHERE LOWER(username)=LOWER(?)', array ($username))) {
|
||||||
if ($user['password'] == UserManager::getHashPassword($password)) {
|
if ($user['password'] == UserManager::getHashPassword($password)) {
|
||||||
if (isset($rememberMe) && $rememberMe == 'true') {
|
if (isset($rememberMe) && $rememberMe == 'true') {
|
||||||
setcookie ("rememberMe", $this->setEncryptedCookie($user['username']), time () + (30 * 24 * 60 * 60 * 1000), "/");
|
setcookie ("rememberMe", $this->setEncryptedCookie($user['username']), time () + (30 * 24 * 60 * 60 * 1000), "/", $_SERVER['HTTP_HOST'], 1);
|
||||||
}
|
}
|
||||||
$_SESSION['user']['id'] = $user['user_id'];
|
$_SESSION['user']['id'] = $user['user_id'];
|
||||||
$page = "./index.php";
|
$page = "./index.php";
|
||||||
@ -62,7 +62,7 @@ class UserManager
|
|||||||
}
|
}
|
||||||
|
|
||||||
public function logout () {
|
public function logout () {
|
||||||
setcookie ("rememberMe","", time() - (30 * 24 * 60 * 60 * 1000), "/");
|
setcookie ("rememberMe","", time() - (30 * 24 * 60 * 60 * 1000), "/", $_SERVER['HTTP_HOST'], 1);
|
||||||
unset($_SESSION['user']);
|
unset($_SESSION['user']);
|
||||||
session_destroy();
|
session_destroy();
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user