make remember login token also dependent on password to protect against some brute force attacks on this token

This commit is contained in:
Robin Appelman 2011-12-14 13:26:34 +01:00
parent 88c0d82daa
commit b216ba7120

View file

@ -88,7 +88,7 @@ else {
if(defined("DEBUG") && DEBUG) {
error_log("Setting remember login to cookie");
}
$token = md5($_POST["user"].time());
$token = md5($_POST["user"].time().$_POST['password']);
OC_Preferences::setValue($_POST['user'], 'login', 'token', $token);
OC_User::setMagicInCookie($_POST["user"], $token);
}