X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=include%2Fsecurity.php;h=9f160e7884cbada1f9691d362eb936604ba491f9;hb=68e0324c1b50b18f78a754553d487cc20b8de6b1;hp=cb4587fbdaf4e904def5679c4ff589eda714fe83;hpb=a0e18a0ff8fbefaf5cb66a4d5c91fac1d45d5931;p=friendica.git diff --git a/include/security.php b/include/security.php index cb4587fbda..9f160e7884 100644 --- a/include/security.php +++ b/include/security.php @@ -46,7 +46,7 @@ function authenticate_success($user_record, $login_initial = false, $interactive $master_record = $r[0]; } - $r = q("SELECT `uid`,`username`,`nickname` FROM `user` WHERE `password` = '%s' AND `email` = '%s'", + $r = q("SELECT `uid`,`username`,`nickname` FROM `user` WHERE `password` = '%s' AND `email` = '%s' AND `account_removed` = 0 ", dbesc($master_record['password']), dbesc($master_record['email']) ); @@ -56,8 +56,8 @@ function authenticate_success($user_record, $login_initial = false, $interactive $a->identities = array(); $r = q("select `user`.`uid`, `user`.`username`, `user`.`nickname` - from manage left join user on manage.mid = user.uid - where `manage`.`uid` = %d", + from manage left join user on manage.mid = user.uid where `user`.`account_removed` = 0 + and `manage`.`uid` = %d", intval($master_record['uid']) ); if($r && count($r))