may be exploitable in current form - awaiting review

This commit is contained in:
zotlabs
2017-09-02 14:04:37 -07:00
parent 5bffae6219
commit 7bff60edac
3 changed files with 6 additions and 1 deletions

View File

@@ -73,6 +73,8 @@ class Dav extends \Zotlabs\Web\Controller {
if(! ($verified && $verified['header_signed'] && $verified['header_valid'])) {
$record = null;
}
// requires security review
$record = null;
if($record['account']) {
authenticate_success($record['account']);
if($channel_login) {