Reviewed. This is OK.
Revert "may be exploitable in current form - awaiting review"
This reverts commit 7bff60edac
.
This commit is contained in:
parent
7bff60edac
commit
499b7de0d2
@ -64,8 +64,6 @@ class Cdav extends \Zotlabs\Web\Controller {
|
||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||
$record = null;
|
||||
}
|
||||
// requires security review
|
||||
$record = null;
|
||||
if($record['account']) {
|
||||
authenticate_success($record['account']);
|
||||
if($channel_login) {
|
||||
|
@ -73,8 +73,6 @@ class Dav extends \Zotlabs\Web\Controller {
|
||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||
$record = null;
|
||||
}
|
||||
// requires security review
|
||||
$record = null;
|
||||
if($record['account']) {
|
||||
authenticate_success($record['account']);
|
||||
if($channel_login) {
|
||||
|
@ -85,8 +85,7 @@ function api_login(&$a){
|
||||
else {
|
||||
continue;
|
||||
}
|
||||
// requires security review
|
||||
$record = null;
|
||||
|
||||
if($record) {
|
||||
$verified = \Zotlabs\Web\HTTPSig::verify('',$record['channel']['channel_pubkey']);
|
||||
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
|
||||
|
Reference in New Issue
Block a user