Ensure users can only login from the right site
This commit is contained in:
@@ -46,7 +46,7 @@ class LoginController extends Controller
|
||||
{
|
||||
$this->validateLogin($request);
|
||||
|
||||
if (Auth::attempt(array_merge($this->credentials($request),['active'=>TRUE]))) {
|
||||
if (Auth::attempt(array_merge($this->credentials($request),['active'=>TRUE,'site_id'=>config('site')->site_id]))) {
|
||||
$request->session()->regenerate();
|
||||
|
||||
return $this->sendLoginResponse($request);
|
||||
|
@@ -43,7 +43,7 @@ class SetSite
|
||||
}
|
||||
|
||||
// Set who we are in SETUP.
|
||||
Config::set('SITE',$so);
|
||||
Config::set('site',$so);
|
||||
if (! $request->ajax())
|
||||
View::share('site',$so);
|
||||
|
||||
|
Reference in New Issue
Block a user