MDL-70668 auth: Fix secret validation during user confirmation
Co-authored-by: Michael Hawkins <[email protected]>
This commit is contained in:
committed by
Jenkins
co-authored by
Michael Hawkins
parent
71f444e82d
commit
299fb2f158
+2
-4
@@ -178,10 +178,10 @@ class auth_plugin_email extends auth_plugin_base {
|
||||
if ($user->auth != $this->authtype) {
|
||||
return AUTH_CONFIRM_ERROR;
|
||||
|
||||
} else if ($user->secret == $confirmsecret && $user->confirmed) {
|
||||
} else if ($user->secret === $confirmsecret && $user->confirmed) {
|
||||
return AUTH_CONFIRM_ALREADY;
|
||||
|
||||
} else if ($user->secret == $confirmsecret) { // They have provided the secret key to get in
|
||||
} else if ($user->secret === $confirmsecret) { // They have provided the secret key to get in
|
||||
$DB->set_field("user", "confirmed", 1, array("id"=>$user->id));
|
||||
|
||||
if ($wantsurl = get_user_preferences('auth_email_wantsurl', false, $user)) {
|
||||
@@ -257,5 +257,3 @@ class auth_plugin_email extends auth_plugin_base {
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
|
||||
|
||||
+2
-2
@@ -598,10 +598,10 @@ class auth_plugin_ldap extends auth_plugin_base {
|
||||
if ($user->auth != $this->authtype) {
|
||||
return AUTH_CONFIRM_ERROR;
|
||||
|
||||
} else if ($user->secret == $confirmsecret && $user->confirmed) {
|
||||
} else if ($user->secret === $confirmsecret && $user->confirmed) {
|
||||
return AUTH_CONFIRM_ALREADY;
|
||||
|
||||
} else if ($user->secret == $confirmsecret) { // They have provided the secret key to get in
|
||||
} else if ($user->secret === $confirmsecret) { // They have provided the secret key to get in
|
||||
if (!$this->user_activate($username)) {
|
||||
return AUTH_CONFIRM_FAIL;
|
||||
}
|
||||
|
||||
@@ -372,10 +372,10 @@ class auth extends \auth_plugin_base {
|
||||
if ($user->auth != $this->authtype) {
|
||||
return AUTH_CONFIRM_ERROR;
|
||||
|
||||
} else if ($user->secret == $confirmsecret && $user->confirmed) {
|
||||
} else if ($user->secret === $confirmsecret && $user->confirmed) {
|
||||
return AUTH_CONFIRM_ALREADY;
|
||||
|
||||
} else if ($user->secret == $confirmsecret) { // They have provided the secret key to get in.
|
||||
} else if ($user->secret === $confirmsecret) { // They have provided the secret key to get in.
|
||||
$DB->set_field("user", "confirmed", 1, array("id" => $user->id));
|
||||
return AUTH_CONFIRM_OK;
|
||||
}
|
||||
|
||||
@@ -709,7 +709,7 @@ class core_user {
|
||||
$fields['lastlogin'] = array('type' => PARAM_INT, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['currentlogin'] = array('type' => PARAM_INT, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['lastip'] = array('type' => PARAM_NOTAGS, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['secret'] = array('type' => PARAM_RAW, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['secret'] = array('type' => PARAM_ALPHANUM, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['picture'] = array('type' => PARAM_INT, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['url'] = array('type' => PARAM_URL, 'null' => NULL_NOT_ALLOWED);
|
||||
$fields['description'] = array('type' => PARAM_RAW, 'null' => NULL_ALLOWED);
|
||||
|
||||
Reference in New Issue
Block a user