git-svn-id: https://adminer.svn.sourceforge.net/svnroot/adminer/trunk@1248
7c3ca157-0c34-0410-bff1-
cbf682f78f5c
page_footer("auth");
}
-if (!$_SESSION["tokens"][$_GET["server"]]) {
- $_SESSION["tokens"][$_GET["server"]] = rand(1, 1e6); // defense against cross-site request forgery
- if ($_POST["token"]) {
- $_POST["token"] = $_SESSION["tokens"][$_GET["server"]];
- }
-}
-
$username = &$_SESSION["usernames"][$_GET["server"]];
if (!isset($username)) {
$username = $_GET["username"]; // default username can be passed in URL
exit;
}
unset($username);
+
+if (!$_SESSION["tokens"][$_GET["server"]]) {
+ $_SESSION["tokens"][$_GET["server"]] = (isset($_POST["server"]) && $_POST["token"] ? $_POST["token"] : rand(1, 1e6)); // defense against cross-site request forgery
+}