@@ -580,9 +580,9 @@ discard block  | 
                                                    ||
| 580 | 580 | |
| 581 | 581 |                                  if ($entries['count'] > 0) { | 
                                                        
| 582 | 582 | // Now check if group fits  | 
                                                        
| 583 | -                                    for ($i=0; $i<$entries['count']; $i++) { | 
                                                        |
| 584 | - $parsr=ldap_explode_dn($entries[$i]['dn'], 0);  | 
                                                        |
| 585 | -                                        if (str_replace(array('CN=','cn='), '', $parsr[0]) === $SETTINGS['ldap_usergroup']) { | 
                                                        |
| 583 | +                                    for ($i = 0; $i < $entries['count']; $i++) { | 
                                                        |
| 584 | + $parsr = ldap_explode_dn($entries[$i]['dn'], 0);  | 
                                                        |
| 585 | +                                        if (str_replace(array('CN=', 'cn='), '', $parsr[0]) === $SETTINGS['ldap_usergroup']) { | 
                                                        |
| 586 | 586 | $GroupRestrictionEnabled = true;  | 
                                                        
| 587 | 587 | break;  | 
                                                        
| 588 | 588 | }  | 
                                                        
@@ -917,11 +917,7 @@ discard block  | 
                                                    ||
| 917 | 917 | $data['id']  | 
                                                        
| 918 | 918 | );  | 
                                                        
| 919 | 919 | |
| 920 | -                    echo '[{' + | 
                                                        |
| 921 | - '"value" : "<img src=\"'.$new_2fa_qr.'\">", ' +  | 
                                                        |
| 922 | - '"user_admin":"', /** @scrutinizer ignore-type */ isset($_SESSION['user_admin']) ? +  | 
                                                        |
| 923 | - $antiXss->xss_clean($_SESSION['user_admin']) : "", '", ' +  | 
                                                        |
| 924 | - '"initial_url" : "'.@$_SESSION['initial_url'].'", "error" : "'.$logError.'"}]';  | 
                                                        |
| 920 | +                    echo '[{' +'"value" : "<img src=\"'.$new_2fa_qr.'\">", ' +'"user_admin":"', /** @scrutinizer ignore-type */ isset($_SESSION['user_admin']) ? +$antiXss->xss_clean($_SESSION['user_admin']) : "", '", ' +'"initial_url" : "'.@$_SESSION['initial_url'].'", "error" : "'.$logError.'"}]'; | 
                                                        |
| 925 | 921 | |
| 926 | 922 | exit();  | 
                                                        
| 927 | 923 | }  |