Re-allow anonymous use of CSRF tokens
This commit is contained in:
parent
96ffe95949
commit
9b38abc32c
|
@ -140,11 +140,7 @@ abstract class BaseModule
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (empty($a->user)) {
|
$sec_hash = hash('whirlpool', ($a->user['guid'] ?? '') . ($a->user['prvkey'] ?? '') . session_id() . $x[0] . $typename);
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
$sec_hash = hash('whirlpool', $a->user['guid'] . $a->user['prvkey'] . session_id() . $x[0] . $typename);
|
|
||||||
|
|
||||||
return ($sec_hash == $x[1]);
|
return ($sec_hash == $x[1]);
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue
Block a user