From 44c169073ef5a59aa62c188922c49c6502e819ba Mon Sep 17 00:00:00 2001 From: Jonathan Rosenbaum Date: Wed, 6 Sep 2017 05:52:17 +0000 Subject: [PATCH] Turns security back on in the members directory This is so non-logged in people can't alter the database. Mark Leigh pointed this out to me when sending me the code, and said "Can't remember why it ended up like this, the auth code is there but commented out." --- members/add.php | 4 ++-- members/getinfo.php | 4 ++-- members/signinsubmit.php | 4 ++-- members/signinsubmitretro.php | 4 ++-- members/submit.php | 4 ++-- 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/members/add.php b/members/add.php index a02f6fb..081e38a 100755 --- a/members/add.php +++ b/members/add.php @@ -15,8 +15,8 @@ global $cfg_membershipID; if(!$sec->isLoggedIn()) { - //header ("location: ../login.php"); - //exit(); + header ("location: ../login.php"); + exit(); } ?> diff --git a/members/getinfo.php b/members/getinfo.php index ca6c00f..3924ff1 100755 --- a/members/getinfo.php +++ b/members/getinfo.php @@ -15,8 +15,8 @@ global $cfg_membershipID; if(!$sec->isLoggedIn()) { -// header ("location: ../login.php"); -// exit(); + header ("location: ../login.php"); + exit(); } ?> diff --git a/members/signinsubmit.php b/members/signinsubmit.php index 72b3b56..e3f2d98 100755 --- a/members/signinsubmit.php +++ b/members/signinsubmit.php @@ -15,8 +15,8 @@ global $cfg_membershipID; if(!$sec->isLoggedIn()) { -// header ("location: ../login.php"); -// exit(); + header ("location: ../login.php"); + exit(); } diff --git a/members/signinsubmitretro.php b/members/signinsubmitretro.php index c7b5067..88a2a06 100755 --- a/members/signinsubmitretro.php +++ b/members/signinsubmitretro.php @@ -24,8 +24,8 @@ global $cfg_membershipID; if(!$sec->isLoggedIn()) { -// header ("location: ../login.php"); -// exit(); + header ("location: ../login.php"); + exit(); } diff --git a/members/submit.php b/members/submit.php index 5d67196..60a08d7 100755 --- a/members/submit.php +++ b/members/submit.php @@ -15,8 +15,8 @@ global $cfg_membershipID; if(!$sec->isLoggedIn()) { -// header ("location: ../login.php"); -// exit(); + header ("location: ../login.php"); + exit(); } ?>