diff options
author | thomascube <thomas@roundcube.net> | 2011-03-22 07:49:43 +0000 |
---|---|---|
committer | thomascube <thomas@roundcube.net> | 2011-03-22 07:49:43 +0000 |
commit | ec045b0a24bbb0de2b203961b453a9f5bd640f34 (patch) | |
tree | 5e54169b90512bd0a4dda9fc517f21eb518540eb /program | |
parent | a8d7c659f1b343d2f0d6c954fcd3e0688e512736 (diff) |
Revert r4609 and use stateless request tokens; no need to save them in session and thus no keep-alive necessary; fixes #1487829
Diffstat (limited to 'program')
-rw-r--r-- | program/include/rcmail.php | 11 | ||||
-rw-r--r-- | program/js/app.js | 2 |
2 files changed, 5 insertions, 8 deletions
diff --git a/program/include/rcmail.php b/program/include/rcmail.php index d9bb30bbe..0fc744605 100644 --- a/program/include/rcmail.php +++ b/program/include/rcmail.php @@ -1106,12 +1106,8 @@ class rcmail */ public function get_request_token() { - $key = $this->task; - - if (!$_SESSION['request_tokens'][$key]) - $_SESSION['request_tokens'][$key] = md5(uniqid($key . mt_rand(), true)); - - return $_SESSION['request_tokens'][$key]; + $sess_id = $_COOKIE[ini_get('session.name')]; + return md5('RT' . $this->task . $this->config->get('des_key') . $sess_id); } @@ -1124,7 +1120,8 @@ class rcmail public function check_request($mode = RCUBE_INPUT_POST) { $token = get_input_value('_token', $mode); - return !empty($token) && $_SESSION['request_tokens'][$this->task] == $token; + $sess_id = $_COOKIE[ini_get('session.name')]; + return !empty($sess_id) && $token == $this->get_request_token(); } diff --git a/program/js/app.js b/program/js/app.js index ebbbae24b..384f45f80 100644 --- a/program/js/app.js +++ b/program/js/app.js @@ -5431,7 +5431,7 @@ function rcube_webmail() if (this.env.keep_alive && !this.env.framed && this.task == 'mail' && this.gui_objects.mailboxlist) this._int = setInterval(function(){ ref.check_for_recent(false); }, this.env.keep_alive * 1000); - else if (this.env.keep_alive && !this.env.framed && this.env.action != 'print') + else if (this.env.keep_alive && !this.env.framed && this.task != 'login' && this.env.action != 'print') this._int = setInterval(function(){ ref.send_keep_alive(); }, this.env.keep_alive * 1000); }; |