logout.php 417 B

12345678910111213141516
  1. <?php
  2. declare(strict_types=1);
  3. require_once __DIR__ . "/../includes/auth.php";
  4. manageStartSession();
  5. // POST only with a valid CSRF token, so a third-party page cannot log the
  6. // admin out (and the session cannot be cycled by a stray GET).
  7. if (($_SERVER["REQUEST_METHOD"] ?? "") === "POST" && manageCsrfIsValid((string) ($_POST["csrf_token"] ?? ""))) {
  8. manageLogout();
  9. }
  10. header("Location: login.php");
  11. exit;