From b82b04b121c7a55a91d654d0daf369d40a1e16d0 Mon Sep 17 00:00:00 2001 From: Josh Sherman Date: Sat, 12 Sep 2015 11:47:08 -0400 Subject: [PATCH] Disabled token logic Causing a bunch of shit in scenarios where you want to unauth / reauth a user as the cookie isn't immediately available. Should resolve all of the "You are not properly authenticated" errors we see. --- classes/Security.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/classes/Security.php b/classes/Security.php index 85bd07a..84c83bc 100644 --- a/classes/Security.php +++ b/classes/Security.php @@ -255,12 +255,14 @@ class Security if (self::checkSession() == true && isset($_SESSION['__pickles']['security']['user_id'])) { // Checks the session against the cookie + /* if (isset($_SESSION['__pickles']['security']['token'], $_COOKIE['pickles_security_token']) && $_SESSION['__pickles']['security']['token'] != $_COOKIE['pickles_security_token']) { Security::logout(); } - elseif (isset($_SESSION['__pickles']['security']['level']) && $_SESSION['__pickles']['security']['level'] != null) + else*/ + if (isset($_SESSION['__pickles']['security']['level']) && $_SESSION['__pickles']['security']['level'] != null) { return $_SESSION['__pickles']['security']['level']; }