calendar:export MDL-17203 prevent disclosing of sensitive information

For more robust solution, please upgrade to 19_STABLE or later
This commit is contained in:
poltawski
2009-01-22 10:11:09 +00:00
parent 54f356203f
commit c615c8b9b5
+2 -2
View File
@@ -11,12 +11,12 @@ $authtoken = required_param('authtoken', PARAM_ALPHANUM);
//Fetch user information
if (!$user = get_complete_user_data('username', $username)) {
//No such user
die("No such user '$username'");
die('Invalid authentication');
}
//Check authentication token
if ($authtoken != sha1($username . $user->password)) {
die('Invalid authentication token');
die('Invalid authentication');
}
$what = optional_param('preset_what', 'all', PARAM_ALPHA);