aboutsummaryrefslogtreecommitdiff
path: root/app/Controllers/javascriptController.php
diff options
context:
space:
mode:
authorGravatar Alexandre Alapetite <alexandre@alapetite.fr> 2015-10-25 13:28:14 +0100
committerGravatar Alexandre Alapetite <alexandre@alapetite.fr> 2015-10-25 13:28:14 +0100
commit8ba8728bd708dcac08076e07eea4625fb6fcffbf (patch)
treeca6b7e48d34f8046e88db7017222f66f69700529 /app/Controllers/javascriptController.php
parente21187df20e7c9893ffdc5f65d778ab1a30356fb (diff)
parent7bb28c3f2b77b109451e2514e83fa99789fee35e (diff)
Merge branch 'login403' into dev
Diffstat (limited to 'app/Controllers/javascriptController.php')
-rwxr-xr-xapp/Controllers/javascriptController.php8
1 files changed, 6 insertions, 2 deletions
diff --git a/app/Controllers/javascriptController.php b/app/Controllers/javascriptController.php
index 421cf6f72..f8746240c 100755
--- a/app/Controllers/javascriptController.php
+++ b/app/Controllers/javascriptController.php
@@ -43,7 +43,11 @@ class FreshRSS_javascript_Controller extends Minz_ActionController {
} else {
Minz_Log::notice('Nonce failure due to invalid username!');
}
- $this->view->nonce = ''; //Failure
- $this->view->salt1 = '';
+ //Failure: Return random data.
+ $this->view->salt1 = sprintf('$2a$%02d$', FreshRSS_user_Controller::BCRYPT_COST);
+ for ($i = 22; $i > 0; $i--) {
+ $this->view->salt1 .= './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'[rand(0, 63)];
+ }
+ $this->view->nonce = sha1(rand());
}
}