MAPG-142 redefine tokens and increase OAuth security with nonce
This commit is contained in:
10 files changed
+63
-32
No files matched your search
@@ -71,6 +71,11 @@ if (isset($_COOKIE['COOKIES_CONSENT'])) {
|
||||
'cookie_httponly' => true,
|
||||
'cookie_samesite' => 'Lax'
|
||||
]);
|
||||
|
||||
// this is needed to handle old type of session IDs
|
||||
if (!Container::$sessionHandler->validateId(session_id())) {
|
||||
session_regenerate_id(true);
|
||||
}
|
||||
} else {
|
||||
$_SESSION = [];
|
||||
}
|
||||
@@ -78,5 +83,5 @@ if (isset($_COOKIE['COOKIES_CONSENT'])) {
|
||||
Container::$request = new MapGuesser\Request\Request($_SERVER['REQUEST_SCHEME'] . '://' . $_SERVER['HTTP_HOST'], $_GET, $_POST, $_SESSION);
|
||||
|
||||
if (!Container::$request->session()->has('anti_csrf_token')) {
|
||||
Container::$request->session()->set('anti_csrf_token', hash('sha256', random_bytes(10) . microtime()));
|
||||
Container::$request->session()->set('anti_csrf_token', bin2hex(random_bytes(16)));
|
||||
}
|
||||
Reference in new issue
Block a user