|
From: Paul S. O. <ps...@us...> - 2002-02-15 23:34:35
|
Update of /cvsroot/phpbb/phpBB2
In directory usw-pr-cvs1:/tmp/cvs-serv7208
Modified Files:
login.php
Log Message:
Minor updates, may fix bug #517876
Index: login.php
===================================================================
RCS file: /cvsroot/phpbb/phpBB2/login.php,v
retrieving revision 1.41
retrieving revision 1.42
diff -C2 -r1.41 -r1.42
*** login.php 5 Feb 2002 01:45:23 -0000 1.41
--- login.php 15 Feb 2002 23:34:32 -0000 1.42
***************
*** 55,71 ****
$sql = "SELECT user_id, username, user_password, user_active, user_level
! FROM ".USERS_TABLE."
WHERE username = '" . str_replace("\'", "''", $username) . "'";
! $result = $db->sql_query($sql);
! if(!$result)
{
message_die(GENERAL_ERROR, "Error in obtaining userdata : login", "", __LINE__, __FILE__, $sql);
}
! $rowresult = $db->sql_fetchrow($result);
!
! if( count($rowresult) )
{
! if( $rowresult['user_level'] != ADMIN && $board_config['board_disable'] )
{
header($header_location . append_sid("index.$phpEx", true));
--- 55,68 ----
$sql = "SELECT user_id, username, user_password, user_active, user_level
! FROM " . USERS_TABLE . "
WHERE username = '" . str_replace("\'", "''", $username) . "'";
! if ( !($result = $db->sql_query($sql)) )
{
message_die(GENERAL_ERROR, "Error in obtaining userdata : login", "", __LINE__, __FILE__, $sql);
}
! if( $row = $db->sql_fetchrow($result) )
{
! if( $row['user_level'] != ADMIN && $board_config['board_disable'] )
{
header($header_location . append_sid("index.$phpEx", true));
***************
*** 73,81 ****
else
{
! if( md5($password) == $rowresult['user_password'] && $rowresult['user_active'] )
{
$autologin = ( isset($HTTP_POST_VARS['autologin']) ) ? TRUE : 0;
! $session_id = session_begin($rowresult['user_id'], $user_ip, PAGE_INDEX, FALSE, $autologin);
if( $session_id )
--- 70,78 ----
else
{
! if( md5($password) == $row['user_password'] && $row['user_active'] )
{
$autologin = ( isset($HTTP_POST_VARS['autologin']) ) ? TRUE : 0;
! $session_id = session_begin($row['user_id'], $user_ip, PAGE_INDEX, FALSE, $autologin);
if( $session_id )
|