瀏覽代碼

修改user的index 请求美欧session的id 禁止访问

lvhao 1 月之前
父節點
當前提交
e5fe648dd1
共有 1 個文件被更改,包括 3 次插入0 次删除
  1. 3 0
      core/CoreApp/controllers/User.php

+ 3 - 0
core/CoreApp/controllers/User.php

@@ -74,6 +74,9 @@ class User extends Start_Controller
 	//首页
 	public function _index()
 	{
+		if(empty($_SESSION['api'])){
+			exit('No direct script access allowed');
+		}
 		$user = $this->user->get_api($_SESSION['api']);
 		$this->data['user'] = $user; //登录的用户信息
 		$power = $this->power->read($user['power']);