Use phpseclib's Crypt::Random to generate CSRF token
Signed-off-by: Michal Čihař <michal@cihar.com>
This commit is contained in:
parent
dbb267308d
commit
f20970d32c
@ -13,6 +13,8 @@ if (! defined('PHPMYADMIN')) {
|
||||
exit;
|
||||
}
|
||||
|
||||
require PHPSECLIB_INC_DIR . '/Crypt/Random.php';
|
||||
|
||||
// verify if PHP supports session, die if it does not
|
||||
|
||||
if (!@function_exists('session_name')) {
|
||||
@ -111,7 +113,7 @@ if (! isset($_COOKIE[$session_name])) {
|
||||
* (we use "space PMA_token space" to prevent overwriting)
|
||||
*/
|
||||
if (! isset($_SESSION[' PMA_token '])) {
|
||||
$_SESSION[' PMA_token '] = md5(uniqid(rand(), true));
|
||||
$_SESSION[' PMA_token '] = bin2hex(phpseclib\Crypt\Random::string(16));
|
||||
}
|
||||
|
||||
/**
|
||||
@ -130,5 +132,5 @@ function PMA_secureSession()
|
||||
) {
|
||||
session_regenerate_id(true);
|
||||
}
|
||||
$_SESSION[' PMA_token '] = md5(uniqid(rand(), true));
|
||||
$_SESSION[' PMA_token '] = bin2hex(phpseclib\Crypt\Random::string(16));
|
||||
}
|
||||
|
||||
Loading…
Reference in New Issue
Block a user