Merge pull request #11796 from hregis/develop_menu
FIX possibility to bypass captcha if it has been validated otherwise
This commit is contained in:
commit
89160c4594
@ -493,7 +493,7 @@ if (! defined('NOLOGIN'))
|
||||
}
|
||||
|
||||
// Verification security graphic code
|
||||
if (GETPOST("username", "alpha", 2) && ! empty($conf->global->MAIN_SECURITY_ENABLECAPTCHA))
|
||||
if (GETPOST("username", "alpha", 2) && ! empty($conf->global->MAIN_SECURITY_ENABLECAPTCHA) && ! isset($_SESSION['dol_bypass_antispam']))
|
||||
{
|
||||
$sessionkey = 'dol_antispam_value';
|
||||
$ok=(array_key_exists($sessionkey, $_SESSION) === true && (strtolower($_SESSION[$sessionkey]) == strtolower($_POST['code'])));
|
||||
|
||||
Loading…
Reference in New Issue
Block a user