Removed HTTP_REFERER check from index.php

Signed-off-by: Janos SUTO <sj@acts.hu>
This commit is contained in:
Janos SUTO 2019-02-23 21:48:06 +01:00
parent 8ecaa4443b
commit 421f0c538c

View File

@ -74,10 +74,6 @@ else if($session->get("four_eyes") == 1 && $request->get['route'] != 'login/logo
}
else if(Registry::get('username')) {
// Check the Referer header which must be present after we are authenticated
if(!isset($_SERVER['HTTP_REFERER'])) die("missing HTTP_REFERER");
if(strpos($_SERVER['HTTP_REFERER'], SITE_URL) === false) die("invalid HTTP_REFERER");
if(isset($request->get['route'])){
$action = new Router($request->get['route']);
}