| 12345678910111213141516 |
- <?php
- declare(strict_types=1);
- require_once __DIR__ . "/../includes/auth.php";
- manageStartSession();
- // POST only with a valid CSRF token, so a third-party page cannot log the
- // admin out (and the session cannot be cycled by a stray GET).
- if (($_SERVER["REQUEST_METHOD"] ?? "") === "POST" && manageCsrfIsValid((string) ($_POST["csrf_token"] ?? ""))) {
- manageLogout();
- }
- header("Location: login.php");
- exit;
|