Add session regeneration after token refresh to enhance security

This commit is contained in:
“VeLiTi”
2026-02-05 16:38:19 +01:00
parent d7b9b91bb6
commit 4564a4a04b

View File

@@ -63,6 +63,8 @@ if (!isset($_SESSION['authorization']['userkey']) ||
if (isset($responses['userkey']) && isset($responses['token_valid'])) {
// Update session with complete response (same as login.php)
$_SESSION['authorization'] = $responses;
session_regenerate_id(true); // Resets the session ID and timer to avoid user needs to relogin
} else {
// Token refresh failed - redirect to login
session_destroy();