diff --git a/main/admin/user_list.php b/main/admin/user_list.php index 79befbc174..fc4992d747 100755 --- a/main/admin/user_list.php +++ b/main/admin/user_list.php @@ -209,7 +209,7 @@ api_protect_admin_script(true); * @author Yannick Warnier */ function login_user($user_id) { - //init --------------------------------------------------------------------- + //init //Load $_user to be sure we clean it before logging in global $uidReset, $loginFailed, $_configuration, $_user; @@ -217,7 +217,8 @@ function login_user($user_id) { $main_admin_table = Database :: get_main_table(TABLE_MAIN_ADMIN); $track_e_login_table = Database :: get_statistic_table(TABLE_STATISTIC_TRACK_E_LOGIN); - //logic -------------------------------------------------------------------- + //logic + unset($_user['user_id']); // uid not in session ? prevent any hacking if (!isset ($user_id)) { $uidReset = true; @@ -724,16 +725,11 @@ function status_filter($status) } -/** -============================================================================== - INIT SECTION -============================================================================== -*/ +/** INIT SECTION */ + $action = $_GET["action"]; $login_as_user_id = $_GET["user_id"]; - - // Login as ... if ($_GET['action'] == "login_as" && isset ($login_as_user_id)) { @@ -891,34 +887,34 @@ if ($_GET['action'] == "login_as" && isset ($login_as_user_id)) $form->addElement('html',''); @@ -995,10 +991,4 @@ if ($_GET['action'] == "login_as" && isset ($login_as_user_id)) $table->set_form_actions(array ('delete' => get_lang('DeleteFromPlatform'))); $table->display(); //} -/* -============================================================================== - FOOTER -============================================================================== -*/ -Display :: display_footer(); -?> +Display :: display_footer(); \ No newline at end of file