mirror of
https://github.com/nextcloud/server.git
synced 2026-06-14 19:20:35 -04:00
make remember login token also dependent on password to protect against some brute force attacks on this token
This commit is contained in:
parent
88c0d82daa
commit
b216ba7120
1 changed files with 1 additions and 1 deletions
|
|
@ -88,7 +88,7 @@ else {
|
|||
if(defined("DEBUG") && DEBUG) {
|
||||
error_log("Setting remember login to cookie");
|
||||
}
|
||||
$token = md5($_POST["user"].time());
|
||||
$token = md5($_POST["user"].time().$_POST['password']);
|
||||
OC_Preferences::setValue($_POST['user'], 'login', 'token', $token);
|
||||
OC_User::setMagicInCookie($_POST["user"], $token);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue