[Svn] r4504 - trunk/roundcubemail

trac at roundcube.net trac at roundcube.net
Tue Feb 8 09:19:18 CET 2011


Author: thomasb
Date: 2011-02-08 02:19:18 -0600 (Tue, 08 Feb 2011)
New Revision: 4504

Modified:
   trunk/roundcubemail/index.php
Log:
Also check referer on logout action

Modified: trunk/roundcubemail/index.php
===================================================================
--- trunk/roundcubemail/index.php	2011-02-08 08:13:06 UTC (rev 4503)
+++ trunk/roundcubemail/index.php	2011-02-08 08:19:18 UTC (rev 4504)
@@ -133,8 +133,8 @@
   }
 }
 
-// end session
-else if ($RCMAIL->task == 'logout' && isset($_SESSION['user_id'])) {
+// end session (after optional referer check)
+else if ($RCMAIL->task == 'logout' && isset($_SESSION['user_id']) && (!$RCMAIL->config->get('referer_check') || rcube_check_referer())) {
   $userdata = array('user' => $_SESSION['username'], 'host' => $_SESSION['imap_host'], 'lang' => $RCMAIL->user->language);
   $OUTPUT->show_message('loggedout');
   $RCMAIL->logout_actions();

_______________________________________________
http://lists.roundcube.net/mailman/listinfo/svn



More information about the Svn mailing list