]> git.wh0rd.org - tt-rss.git/blobdiff - include/sessions.php
remove session REMOTE_ADDR checks
[tt-rss.git] / include / sessions.php
index f625cd16f59415f7c672662dffba84bc2afae88b..5584c25bdbff3fd3ea446069c2a1e60d30f9bad9 100644 (file)
@@ -13,7 +13,6 @@
        $session_name = (!defined('TTRSS_SESSION_NAME')) ? "ttrss_sid" : TTRSS_SESSION_NAME;
 
        if (is_server_https()) {
-               $session_name .= "_ssl";
                ini_set("session.cookie_secure", true);
        }
 
 
                if ($_SESSION["uid"]) {
 
-                       if (!defined('_SKIP_SESSION_ADDRESS_CHECKS') || !_SKIP_SESSION_ADDRESS_CHECKS) {
-                               if ($_SESSION["ip_address"] != $_SERVER["REMOTE_ADDR"]) {
-                                       $_SESSION["login_error_msg"] = __("Session failed to validate.");
-                                       return false;
-                               }
-                       }
-
                        if ($_SESSION["user_agent"] != sha1($_SERVER['HTTP_USER_AGENT'])) {
-                               $_SESSION["login_error_msg"] = __("Session failed to validate.");
+                               $_SESSION["login_error_msg"] = __("Session failed to validate (UA changed).");
                                return false;
                        }