diff --git a/pages/login.php b/pages/login.php index 9fc90df..3d6024e 100644 --- a/pages/login.php +++ b/pages/login.php @@ -25,11 +25,11 @@ if(hash_equals(md5(md5($_POST['password']).":".$res['passwordSalt']), $res['passwordHash'])) { session_unset(); // Unset pre-session variables, next request will generate a new CSRF token - $_SESSION['FIRSTNAME'] = trim($rowUser['FirstName']); - $_SESSION['LASTNAME'] = trim($rowUser['LastName']); - $_SESSION['EMAIL'] = trim($rowUser['Email']); - $_SESSION['PASSWORD'] = $rowAuth['passwordHash']; - $_SESSION['SALT'] = $rowAuth['passwordSalt']; + $_SESSION['FIRSTNAME'] = $rowUser['FirstName']; + $_SESSION['LASTNAME'] = $rowUser['LastName']; + $_SESSION['EMAIL'] = $rowUser['Email']; + $_SESSION['PASSWORD'] = $rowUser['passwordHash']; + $_SESSION['SALT'] = $rowUser['passwordSalt']; $_SESSION['UUID'] = $rowUser['PrincipalID']; $_SESSION['LEVEL'] = $rowUser['UserLevel']; $_SESSION['DISPLAYNAME'] = strtoupper($rowUser['FirstName'].' '.$rowUser['LastName']);