Skip to content
GitLab
Explore
Projects
Groups
Topics
Snippets
Projects
Groups
Topics
Snippets
/
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
Menu
fusiondirectory
fusiondirectory
Commits
aaf236ae
Verified
Commit
aaf236ae
authored
3 weeks ago
by
dockx thibault
Browse files
Options
Download
Patches
Plain Diff
(login) - session fix security
Security purposes - regen session id
parent
fb35a648
core-php8
No related merge requests found
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
include/login/class_LoginMethod.inc
+1
-2
include/login/class_LoginMethod.inc
with
1 addition
and
2 deletions
+1
-2
include/login/class_LoginMethod.inc
+
1
−
2
View file @
aaf236ae
...
@@ -160,8 +160,7 @@ class LoginMethod
...
@@ -160,8 +160,7 @@ class LoginMethod
$ui
=
session
::
get
(
'ui'
);
$ui
=
session
::
get
(
'ui'
);
// Create new session ID in order to have session_fixation security issues after success login
// Create new session ID in order to have session_fixation security issues after success login
echo
'before_refreshing_id'
;
session_regenerate_id
();
//session_regenerate_id();
/* Not account expired or password forced change go to main page */
/* Not account expired or password forced change go to main page */
logging
::
log
(
'security'
,
'login'
,
$ui
->
uid
,
[],
'Logged in successfully'
);
logging
::
log
(
'security'
,
'login'
,
$ui
->
uid
,
[],
'Logged in successfully'
);
...
...
This diff is collapsed.
Click to expand it.
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment
Menu
Explore
Projects
Groups
Topics
Snippets