Reviewed. This is OK.

Revert "may be exploitable in current form - awaiting review"

This reverts commit 7bff60edac.
This commit is contained in:
zotlabs 2017-09-03 00:59:51 -07:00
parent 7bff60edac
commit 499b7de0d2
3 changed files with 1 additions and 6 deletions

View File

@ -64,8 +64,6 @@ class Cdav extends \Zotlabs\Web\Controller {
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
$record = null;
}
// requires security review
$record = null;
if($record['account']) {
authenticate_success($record['account']);
if($channel_login) {

View File

@ -73,8 +73,6 @@ class Dav extends \Zotlabs\Web\Controller {
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
$record = null;
}
// requires security review
$record = null;
if($record['account']) {
authenticate_success($record['account']);
if($channel_login) {

View File

@ -85,8 +85,7 @@ function api_login(&$a){
else {
continue;
}
// requires security review
$record = null;
if($record) {
$verified = \Zotlabs\Web\HTTPSig::verify('',$record['channel']['channel_pubkey']);
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {