Always use length of database link_token for token validation
[MAILPOET-2364]
This commit is contained in:
committed by
Jack Kitterhing
parent
2b02d22232
commit
09db91bc33
@ -138,10 +138,12 @@ class Subscriber extends Model {
|
||||
}
|
||||
|
||||
function verifyToken($token) {
|
||||
$database_token = $this->getLinkToken();
|
||||
$request_token = substr($token, 0, strlen($database_token));
|
||||
return call_user_func(
|
||||
'hash_equals',
|
||||
$this->getLinkToken(),
|
||||
$token
|
||||
$database_token,
|
||||
$request_token
|
||||
);
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user