From 57dab27169b6a657b6df8bdef5609d7e31679ecd Mon Sep 17 00:00:00 2001 From: Marcus Hill Date: Sat, 17 Jun 2023 15:09:01 +0100 Subject: [PATCH] Login page enhancements - Default to secure cookies (in case var is not defined in config.php) - Enable content security policy - Return HTTP 401 response code for invalid username/password combinations --- js/login_prevent_resubmit.js | 3 +++ login.php | 17 ++++++++--------- 2 files changed, 11 insertions(+), 9 deletions(-) create mode 100644 js/login_prevent_resubmit.js diff --git a/js/login_prevent_resubmit.js b/js/login_prevent_resubmit.js new file mode 100644 index 00000000..de13d0e9 --- /dev/null +++ b/js/login_prevent_resubmit.js @@ -0,0 +1,3 @@ +if (window.history.replaceState) { + window.history.replaceState(null,null,window.location.href); +} diff --git a/login.php b/login.php index 148a2dfe..b9281d86 100644 --- a/login.php +++ b/login.php @@ -1,6 +1,7 @@ + + - + - +