login: status 403 for initial unauthorised redirects
[minimedit.git] / login / index.php
index 86af0744a4587ea1d9aeab162384a34cb5371641..897346d98275f712f1fdfa8906bacbf2085b4eaa 100644 (file)
@@ -35,22 +35,49 @@ elseif (isset($_GET['logout'])) {
        $message = "Je bent uitgelogd. Graag tot ziens!";
 }
 
-if (empty($User)) {
-       ob_clean();
+if (!$User or !$User->login) {
+       $Article->title = 'Inloggen';
+       if (isset($_REQUEST['goto'])) {
+               if (empty($message)) http_response_code(403);
+               $target = ltrim($_REQUEST['goto'], '/');
+               $target = new ArchiveArticle("$target.html");
+
+               if ($Page = $target->handler and $target->handler == 'melding') {
+                       $caller = $Article;
+                       $Article = $target;
+                       $Args = $target->path;
+                       ob_start();
+                       include "./{$target->handler}/index.php";
+                       ob_end_clean();
+                       $Article = $caller;
+               }
+
+               if ($target->title) {
+                       $Article->title .= ' voor ' . $target->title;
+               }
+               if ($target->image) {
+                       $Article->image = $target->image;
+               }
+       }
+       ob_start();
        require_once 'login/form.inc.php';
+       $Article->raw = ob_get_clean();
        $Place['warn'] = $message;
        return TRUE;
 }
 
-if (isset($_GET['goto'])) {
-       ob_clean();
-       $target = ltrim($_GET['goto'], '/');
+if (isset($_REQUEST['goto'])) {
+       $target = ltrim($_REQUEST['goto'], '/');
        header("Location: /$target");
        http_response_code(302);
        exit;
 }
 
-if (empty($Args) and !empty($User['admin'])) {
+if (isset($Article->raw)) {
+       print $Article->raw;
+}
+if (empty($Args) and $User->admin) {
        include_once 'login/admin.html';
 }
 
+return;