maybe thats how to escape the activation of unknown users

This commit is contained in:
Thies Mueller 2021-01-09 23:22:17 +01:00
parent cf3031774e
commit 00096d3791

View File

@ -38,7 +38,10 @@ if(isset($_GET['send']) ) {
$user = $statement->fetch(); $user = $statement->fetch();
if($user === false) { if($user === false) {
$error = '<span class="badge badge-pill badge-warning"><b>no user found</b></span>'; $error = '<span class="badge badge-pill badge-warning"><b>no user found</b></span>';
}
if($user['username'] !== $_POST['username']){
$error = '<span class="badge badge-pill badge-warning"><b>no user found/invalid user</b></span>';
} }
if($user['activated'] == "1"){ if($user['activated'] == "1"){
$error = '<span class="badge badge-pill badge-warning"><b>user already activated!</b></span>'; $error = '<span class="badge badge-pill badge-warning"><b>user already activated!</b></span>';