Generate longer more secure Key for browser extension
This commit is contained in:
2
post.php
2
post.php
@@ -324,7 +324,7 @@ if(isset($_POST['edit_profile'])){
|
|||||||
// Enable extension access, only if it isn't already setup (user doesn't have cookie)
|
// Enable extension access, only if it isn't already setup (user doesn't have cookie)
|
||||||
if(isset($_POST['extension']) && $_POST['extension'] == 'Yes'){
|
if(isset($_POST['extension']) && $_POST['extension'] == 'Yes'){
|
||||||
if(!isset($_COOKIE['user_extension_key'])){
|
if(!isset($_COOKIE['user_extension_key'])){
|
||||||
$extension_key = keygen();
|
$extension_key = bin2hex(random_bytes(78));
|
||||||
mysqli_query($mysqli, "UPDATE users SET user_extension_key = '$extension_key' WHERE user_id = $user_id");
|
mysqli_query($mysqli, "UPDATE users SET user_extension_key = '$extension_key' WHERE user_id = $user_id");
|
||||||
|
|
||||||
$extended_log_description .= ", extension access enabled";
|
$extended_log_description .= ", extension access enabled";
|
||||||
|
|||||||
Reference in New Issue
Block a user