Reviewed. This is OK.
Revert "may be exploitable in current form - awaiting review"
This reverts commit 7bff60edac
.
This commit is contained in:
parent
7bff60edac
commit
499b7de0d2
@ -64,8 +64,6 @@ class Cdav extends \Zotlabs\Web\Controller {
|
|||||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||||
$record = null;
|
$record = null;
|
||||||
}
|
}
|
||||||
// requires security review
|
|
||||||
$record = null;
|
|
||||||
if($record['account']) {
|
if($record['account']) {
|
||||||
authenticate_success($record['account']);
|
authenticate_success($record['account']);
|
||||||
if($channel_login) {
|
if($channel_login) {
|
||||||
|
@ -73,8 +73,6 @@ class Dav extends \Zotlabs\Web\Controller {
|
|||||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||||
$record = null;
|
$record = null;
|
||||||
}
|
}
|
||||||
// requires security review
|
|
||||||
$record = null;
|
|
||||||
if($record['account']) {
|
if($record['account']) {
|
||||||
authenticate_success($record['account']);
|
authenticate_success($record['account']);
|
||||||
if($channel_login) {
|
if($channel_login) {
|
||||||
|
@ -85,8 +85,7 @@ function api_login(&$a){
|
|||||||
else {
|
else {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
// requires security review
|
|
||||||
$record = null;
|
|
||||||
if($record) {
|
if($record) {
|
||||||
$verified = \Zotlabs\Web\HTTPSig::verify('',$record['channel']['channel_pubkey']);
|
$verified = \Zotlabs\Web\HTTPSig::verify('',$record['channel']['channel_pubkey']);
|
||||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||||
|
Reference in New Issue
Block a user