Use Index for CSRF protection tokens.
This commit is contained in:
parent
5d62e6e741
commit
163ff95cdf
2 changed files with 13 additions and 91 deletions
|
@ -214,11 +214,9 @@ if($authToken->isValid()) {
|
|||
AuthToken::nukeCookie();
|
||||
}
|
||||
|
||||
CSRF::setGlobalSecretKey($cfg->getValue('csrf.secret', IConfig::T_STR, 'soup'));
|
||||
CSRF::setGlobalIdentity(
|
||||
UserSession::hasCurrent()
|
||||
? UserSession::getCurrent()->getToken()
|
||||
: ($_SERVER['REMOTE_ADDR'] ?? '::1')
|
||||
CSRF::init(
|
||||
$cfg->getValue('csrf.secret', IConfig::T_STR, 'soup'),
|
||||
(UserSession::hasCurrent() ? UserSession::getCurrent()->getToken() : ($_SERVER['REMOTE_ADDR'] ?? '::1'))
|
||||
);
|
||||
|
||||
function mszLockdown(): void {
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue