Skip to content

Commit 8477015

Browse files
author
Kristan Kenney
committed
Do not log current session when deleting log for impersonated user
1 parent 0419871 commit 8477015

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

web/delete/log/auth/index.php

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,11 @@
2828
$v_user_agent = escapeshellarg($user_agent);
2929

3030
$v_session_id = escapeshellarg($_SESSION['token']);
31-
exec(HESTIA_CMD."v-log-user-login ".$v_username." ".$v_ip." success ".$v_session_id." ".$v_user_agent, $output, $return_var);
31+
32+
// Add current user session back to log unless impersonating another user
33+
if (!isset($_SESSION['look'])) {
34+
exec(HESTIA_CMD."v-log-user-login ".$v_username." ".$v_ip." success ".$v_session_id." ".$v_user_agent, $output, $return_var);
35+
}
3236

3337
// Flush session messages
3438
unset($_SESSION['error_msg']);

0 commit comments

Comments
 (0)