Page Menu
Home
In-Portal Phabricator
Search
Configure Global Search
Log In
Files
F727016
D472.id1211.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Award Token
Flag For Later
Subscribers
None
File Metadata
Details
File Info
Storage
Attached
Created
Mon, Jan 6, 5:09 AM
Size
459 B
Mime Type
text/x-diff
Expires
Tue, Jan 7, 5:09 AM (2 d, 22 h ago)
Engine
blob
Format
Raw Data
Handle
537084
Attached To
D472: INP-1865 Use cryptographically safe session key generator
D472.id1211.diff
View Options
Index: core/kernel/session/session.php
===================================================================
--- core/kernel/session/session.php
+++ core/kernel/session/session.php
@@ -535,7 +535,10 @@
*/
function GenerateSID()
{
- $this->setSID(kUtil::generateId());
+ $this->setSID(
+ SecurityGenerator::generateNumber(100000000, 999999999)
+ ->resolveForPersisting(TABLE_PREFIX . 'UserSessions', 'SessionKey')
+ );
return $this->SID;
}
Event Timeline
Log In to Comment