mirror of
https://framagit.org/hubzilla/core.git
synced 2026-06-21 00:52:33 -04:00
air: revert min_livetime of the form security token - it has had its issues and air can be configured for delayed registration verification
This commit is contained in:
@@ -592,10 +592,9 @@ function check_form_security_token($typename = '', $formname = 'form_security_to
|
||||
$hash = $_REQUEST[$formname];
|
||||
|
||||
$max_livetime = 10800; // 3 hours
|
||||
$min_livetime = 3; // 3 sec
|
||||
|
||||
$x = explode('.', $hash);
|
||||
if (time() > (IntVal($x[0]) + $max_livetime) || time() < (IntVal($x[0]) + $min_livetime))
|
||||
if (time() > (IntVal($x[0]) + $max_livetime))
|
||||
return false;
|
||||
|
||||
$sec_hash = hash('whirlpool', App::$observer['xchan_guid'] . ((local_channel()) ? App::$channel['channel_prvkey'] : '') . session_id() . $x[0] . $typename);
|
||||
|
||||
Reference in New Issue
Block a user