liquid_feedback_frontend

diff model/member.lua @ 224:bf735d8095aa

Fixed security related bug, security tokens were exposed through trace output.
author bsw
date Tue May 17 03:23:16 2011 +0200 (2011-05-17)
parents 5e35add677ee
children 7196685f9dd7 a34142b39bd8
line diff
     1.1 --- a/model/member.lua	Sat Feb 05 19:47:35 2011 +0100
     1.2 +++ b/model/member.lua	Tue May 17 03:23:16 2011 +0200
     1.3 @@ -313,6 +313,7 @@
     1.4  end
     1.5  
     1.6  function Member.object:set_notify_email(notify_email)
     1.7 +  trace.disable()
     1.8    local expiry = db:query("SELECT now() + '7 days'::interval as expiry", "object").expiry
     1.9    self.notify_email_unconfirmed = notify_email
    1.10    self.notify_email_secret = multirand.string( 24, "23456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz" )

Impressum / About Us