diff --git a/Rocksolid_Light/common/changepw.php b/Rocksolid_Light/common/changepw.php index cfc157b..6f056ba 100644 --- a/Rocksolid_Light/common/changepw.php +++ b/Rocksolid_Light/common/changepw.php @@ -3,6 +3,16 @@ include "config.inc.php"; include "head.inc"; +$keyfile = $spooldir.'/keys.dat'; +$keys = unserialize(file_get_contents($keyfile)); + +if((password_verify($keys[0],$_POST['key'])) || (password_verify($keys[1],$_POST['key']))) { + $auth_ok = true; +} else { + $auth_ok = false; + unset($_POST['command']); +} + if(!isset($_POST['command']) || $_POST['command'] !== 'Change') { echo ''; @@ -25,6 +35,7 @@ if(!isset($_POST['command']) || $_POST['command'] !== 'Change') { echo ''; echo ''; echo ''; + echo ''; echo ''; echo ''; echo '
 
';