Pontoporeia
f398a0f1ff
Fix non-constant-time credential comparisons
...
- account.php: replace !== CSRF token check with hash_equals
- ShareLink::setPassword(): also encrypt and store plain-text password
alongside the hash, matching create() behavior so the decrypted_password
decoration stays correct after password updates
2026-05-31 17:49:43 +02:00
..
2026-05-19 23:58:51 +02:00
2026-05-19 00:08:06 +02:00
2026-05-19 00:08:05 +02:00
2026-05-31 17:49:43 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 23:58:51 +02:00
2026-05-19 23:58:51 +02:00
2026-05-19 00:08:06 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 23:58:51 +02:00
2026-05-05 11:04:52 +02:00
2026-05-05 11:04:52 +02:00
2026-05-20 12:49:23 +02:00
2026-05-19 23:58:51 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 23:58:51 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 00:08:06 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 00:08:06 +02:00
2026-05-19 00:08:05 +02:00
2026-05-19 23:58:51 +02:00
2026-05-19 00:08:06 +02:00
2026-05-19 00:08:05 +02:00