]> git.wh0rd.org - tt-rss.git/blobdiff - include/sessions.php
remove session REMOTE_ADDR checks
[tt-rss.git] / include / sessions.php
index c80c21de3a24cc6314f4fe8164c0313363f29cfb..5584c25bdbff3fd3ea446069c2a1e60d30f9bad9 100644 (file)
@@ -13,7 +13,6 @@
        $session_name = (!defined('TTRSS_SESSION_NAME')) ? "ttrss_sid" : TTRSS_SESSION_NAME;
 
        if (is_server_https()) {
-               $session_name .= "_ssl";
                ini_set("session.cookie_secure", true);
        }
 
         $pdo = Db::pdo();
 
                if ($_SESSION["uid"]) {
+
+                       if ($_SESSION["user_agent"] != sha1($_SERVER['HTTP_USER_AGENT'])) {
+                               $_SESSION["login_error_msg"] = __("Session failed to validate (UA changed).");
+                               return false;
+                       }
+
                        $sth = $pdo->prepare("SELECT pwd_hash FROM ttrss_users WHERE id = ?");
                        $sth->execute([$_SESSION['uid']]);