From 25be923e821438abe161cf6fac734cd60dabecfa Mon Sep 17 00:00:00 2001 From: marcus Date: Mon, 1 Sep 2008 09:13:16 +0000 Subject: Additional per-session random token, additional randomness protection against CSRF. Report problems. git-svn-id: https://code.elgg.org/elgg/trunk@2048 36083f99-b078-4883-b0ff-0f9b5a30f544 --- engine/lib/sessions.php | 3 +++ 1 file changed, 3 insertions(+) (limited to 'engine/lib/sessions.php') diff --git a/engine/lib/sessions.php b/engine/lib/sessions.php index 0a35fec1a..3dd9ac9e1 100644 --- a/engine/lib/sessions.php +++ b/engine/lib/sessions.php @@ -204,6 +204,9 @@ { $_SESSION['__elgg_fingerprint'] = get_session_fingerprint(); } + + // Generate a simple token + if (!isset($_SESSION['__elgg_session'])) $_SESSION['__elgg_session'] = md5(microtime().rand()); if (empty($_SESSION['guid'])) { if (isset($_COOKIE['elggperm'])) { -- cgit v1.2.3