From 7765eeea347dcc2ba68d15489cb608cafbfa52ee Mon Sep 17 00:00:00 2001 From: Mcat12 Date: Fri, 6 Jan 2017 10:53:01 -0500 Subject: [PATCH] Only show token when authorized --- scripts/pi-hole/php/header.php | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/scripts/pi-hole/php/header.php b/scripts/pi-hole/php/header.php index f5b79528..029b08ab 100644 --- a/scripts/pi-hole/php/header.php +++ b/scripts/pi-hole/php/header.php @@ -83,15 +83,16 @@ $memory_usage = -1; } + if($auth) { + // For session timer + $maxlifetime = ini_get("session.gc_maxlifetime"); - // For session timer - $maxlifetime = ini_get("session.gc_maxlifetime"); - - // Generate CSRF token - if(empty($_SESSION['token'])) { - $_SESSION['token'] = base64_encode(openssl_random_pseudo_bytes(32)); + // Generate CSRF token + if(empty($_SESSION['token'])) { + $_SESSION['token'] = base64_encode(openssl_random_pseudo_bytes(32)); + } + $token = $_SESSION['token']; } - $token = $_SESSION['token']; if(isset($setupVars['WEBUIBOXEDLAYOUT'])) { @@ -171,7 +172,7 @@ - +
@@ -215,7 +216,9 @@ +
Session is valid for 0){echo $maxlifetime;}else{echo "0";} ?>
+