$_SESSION["theme"] = $user_theme;
$_SESSION["ip_address"] = $_SERVER["REMOTE_ADDR"];
+ $_SESSION["pwd_hash"] = $pwd_hash;
initialize_user_prefs($link, $_SESSION["uid"]);
}
}
+ if ($_SESSION["uid"]) {
+
+ $result = db_query($link,
+ "SELECT pwd_hash FROM ttrss_users WHERE id = '".$_SESSION["uid"]."'");
+
+ $pwd_hash = db_fetch_result($result, 0, "pwd_hash");
+
+ if ($pwd_hash != $_SESSION["pwd_hash"]) {
+ return false;
+ }
+ }
+
/* if ($_SESSION["cookie_lifetime"] && $_SESSION["uid"]) {
//print_r($_SESSION);