Commit aa2d268c authored by Nigel McNie's avatar Nigel McNie Committed by Nigel McNie
Don't show the login page if the session has timed out and the page

is public. Check for the password having being changed just after the
login_submit function has determined that the user is logged in.
log_debug('session timed out');
log_debug('session timed out');
// @todo<nigel>: if page is public, no need to show the login page again
if (!defined('PUBLIC')) {
else {
// There is no session, so we check to see if one needs to be started.
......@@ -525,6 +526,7 @@ function login_submit($values) {
$USER = call_static_method($authclass, 'get_user_info', $username);
$USER->logout_time = $SESSION->get('logout_time');
else {
// Login attempt failed
