summaryrefslogtreecommitdiff
path: root/login.php
diff options
context:
space:
mode:
Diffstat (limited to 'login.php')
-rw-r--r--login.php3
1 files changed, 3 insertions, 0 deletions
diff --git a/login.php b/login.php
index 76f7a7f..37bed4b 100644
--- a/login.php
+++ b/login.php
@@ -28,6 +28,7 @@
$_SESSION["owner"] = $username;
$_SESSION["pass_hash"] = sha1($user->pass);
+ $_SESSION["csrf_token"] = bin2hex(random_bytes(16));
header("Location: index.php");
exit;
@@ -35,6 +36,8 @@
} else {
$login_notice = "Incorrect username or password";
}
+ } else {
+ logout_user();
}
?>
<!DOCTYPE html>