Selaa lähdekoodia

When the user is updated increase the salt length and remove special characters that can cause problems.

Mark Crane 10 vuotta sitten
vanhempi
commit
f604551d19
1 muutettua tiedostoa jossa 1 lisäystä ja 1 poistoa
  1. 1 1
      core/users/usersupdate.php

+ 1 - 1
core/users/usersupdate.php

@@ -286,7 +286,7 @@ if (count($_POST) > 0 && $_POST["persistform"] != "1") {
 		}
 		}
 		if (strlen($password) > 0 && $confirm_password == $password) {
 		if (strlen($password) > 0 && $confirm_password == $password) {
 			//salt used with the password to create a one way hash
 			//salt used with the password to create a one way hash
-				$salt = generate_password('20', '4');
+				$salt = uuid();
 			//set the password
 			//set the password
 				$sql .= "password = '".md5($salt.$password)."', ";
 				$sql .= "password = '".md5($salt.$password)."', ";
 				$sql .= "salt = '".$salt."', ";
 				$sql .= "salt = '".$salt."', ";