aboutsummaryrefslogtreecommitdiff
path: root/app/Controllers/authController.php
diff options
context:
space:
mode:
authorGravatar Inverle <inverle@proton.me> 2025-08-30 21:40:00 +0200
committerGravatar GitHub <noreply@github.com> 2025-08-30 21:40:00 +0200
commit200eafb352f807bd70592b2ccc06745017328a85 (patch)
treef06f77ee648d3e9a421346bf9749893a8cd01607 /app/Controllers/authController.php
parent585875cda7e3e261062a9b4f9d836bd8671b838e (diff)
Regenerate session ID on login (#7829)
Follow-up to #7762 * Regenerate session ID on login * Send only one cookie * Improvements * Delete old session file * Simplify * Make function consistent with others
Diffstat (limited to 'app/Controllers/authController.php')
-rw-r--r--app/Controllers/authController.php10
1 files changed, 4 insertions, 6 deletions
diff --git a/app/Controllers/authController.php b/app/Controllers/authController.php
index 6b8d924d6..453851d22 100644
--- a/app/Controllers/authController.php
+++ b/app/Controllers/authController.php
@@ -152,6 +152,7 @@ class FreshRSS_auth_Controller extends FreshRSS_ActionController {
);
if ($ok) {
// Set session parameter to give access to the user.
+ Minz_Session::regenerateID('FreshRSS');
Minz_Session::_params([
Minz_User::CURRENT_USER => $username,
'passwordHash' => FreshRSS_Context::userConf()->passwordHash,
@@ -203,6 +204,7 @@ class FreshRSS_auth_Controller extends FreshRSS_ActionController {
$ok = password_verify($password, $s);
unset($password);
if ($ok) {
+ Minz_Session::regenerateID('FreshRSS');
Minz_Session::_params([
Minz_User::CURRENT_USER => $username,
'passwordHash' => $s,
@@ -243,6 +245,7 @@ class FreshRSS_auth_Controller extends FreshRSS_ActionController {
)) {
Minz_Request::setBadNotification(_t('feedback.auth.login.invalid'));
} else {
+ Minz_Session::regenerateID('FreshRSS');
Minz_Session::_param('lastReauth', time());
Minz_Request::forward($redirect, true);
return;
@@ -259,12 +262,7 @@ class FreshRSS_auth_Controller extends FreshRSS_ActionController {
if (Minz_Request::isPost()) {
invalidateHttpCache();
FreshRSS_Auth::removeAccess();
-
- ini_set('session.use_cookies', '1');
- Minz_Session::lock();
- Minz_Session::regenerateID();
- Minz_Session::unlock();
-
+ Minz_Session::regenerateID('FreshRSS');
Minz_Request::good(_t('feedback.auth.logout.success'), [ 'c' => 'index', 'a' => 'index' ]);
} else {
Minz_Error::error(403);