add api validation

This commit is contained in:
zhaoxuan 2017-11-15 10:48:29 +08:00
parent 8b2c07861d
commit 224025650a

View File

@ -60,8 +60,11 @@ if (!empty($fn)) {
}
// Check if user is logged
if ((isset($_SESSION['login'])&&$_SESSION['login']===true)&&
(isset($_SESSION['identifier'])&&$_SESSION['identifier']===Settings::get()['identifier'])) {
$status = (isset($_SESSION['login'])&&$_SESSION['login']===true)&&
(isset($_SESSION['identifier'])&&$_SESSION['identifier']===Settings::get()['identifier']);
// Use identifier to access api
if ($status || ($_POST['identifier']===Settings::get()['identifier'])) {
/**
* Admin Access