From 2ce92903011fac8c5246c8384b440e5f3daa190f Mon Sep 17 00:00:00 2001 From: marcus Date: Fri, 1 Aug 2008 11:47:09 +0000 Subject: Closes #190. Note however that logins will be broken until #104 has been resolved! git-svn-id: https://code.elgg.org/elgg/trunk@1647 36083f99-b078-4883-b0ff-0f9b5a30f544 --- engine/lib/sessions.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/engine/lib/sessions.php b/engine/lib/sessions.php index 2c84b2d1f..a47415d64 100644 --- a/engine/lib/sessions.php +++ b/engine/lib/sessions.php @@ -75,7 +75,12 @@ { //$dbpassword = md5($credentials['password']); + if ($user = get_user_by_username($credentials['username'])) { + // Let admins log in without validating their email, but normal users must have validated their email + if ((!$user->admin) && (!$user->validated_email)) + return false; + if ($user->password == generate_user_password($user, $credentials['password'])) { return true; } -- cgit v1.2.3