MDL-31248 - lib - Retaining the old password key and creating a new cookie prefix.

This commit is contained in:
Adrian Greeve
2012-03-09 13:37:40 +08:00
parent e356fb68fd
commit 9e7fa5f2bb
2 changed files with 25 additions and 15 deletions
+20 -10
View File
@@ -7264,12 +7264,17 @@ class emoticon_manager {
*
* @todo Finish documenting this function
*
* @param string $data Data to encrypt
* @return string The now encrypted data
* @param string $data Data to encrypt.
* @param bool $usesecurekey Lets us know if we are using the old or new password.
* @return string The now encrypted data.
*/
function rc4encrypt($data) {
$password = get_site_identifier();
return endecrypt($password, $data, '');
function rc4encrypt($data, $usesecurekey = false) {
if (!$usesecurekey) {
$passwordkey = 'nfgjeingjk';
} else {
$passwordkey = get_site_identifier();
}
return endecrypt($passwordkey, $data, '');
}
/**
@@ -7277,12 +7282,17 @@ function rc4encrypt($data) {
*
* @todo Finish documenting this function
*
* @param string $data Data to decrypt
* @return string The now decrypted data
* @param string $data Data to decrypt.
* @param bool $usesecurekey Lets us know if we are using the old or new password.
* @return string The now decrypted data.
*/
function rc4decrypt($data) {
$password = get_site_identifier();
return endecrypt($password, $data, 'de');
function rc4decrypt($data, $usesecurekey = false) {
if (!$usesecurekey) {
$passwordkey = 'nfgjeingjk';
} else {
$passwordkey = get_site_identifier();
}
return endecrypt($passwordkey, $data, 'de');
}
/**
+5 -5
View File
@@ -1016,14 +1016,14 @@ function set_moodle_cookie($username) {
return;
}
$cookiename = 'MOODLEID_'.$CFG->sessioncookie;
$cookiename = 'MOODLEID1_'.$CFG->sessioncookie;
// delete old cookie
setcookie($cookiename, '', time() - HOURSECS, $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
if ($username !== '') {
// set username cookie for 60 days
setcookie($cookiename, rc4encrypt($username), time()+(DAYSECS*60), $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
setcookie($cookiename, rc4encrypt($username, true), time()+(DAYSECS*60), $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
}
}
@@ -1043,15 +1043,15 @@ function get_moodle_cookie() {
return '';
}
$cookiename = 'MOODLEID_'.$CFG->sessioncookie;
$cookiename = 'MOODLEID1_'.$CFG->sessioncookie;
if (empty($_COOKIE[$cookiename])) {
return '';
} else {
$username = rc4decrypt($_COOKIE[$cookiename]);
$username = rc4decrypt($_COOKIE[$cookiename], true);
if ($username === 'guest' or $username === 'nobody') {
// backwards compatibility - we do not set these cookies any more
return '';
$username = '';
}
return $username;
}