mirror of
https://github.com/Piwigo/Piwigo.git
synced 2026-06-02 04:15:05 +02:00
Improve security of sessions:
- use only cookies to store session id on client side - use default php session system with database handler to store sessions on server side git-svn-id: http://piwigo.org/svn/trunk@1004 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
+2
-4
@@ -117,7 +117,7 @@ $template->set_filenames(array('comments'=>'admin/comments.tpl'));
|
||||
|
||||
$template->assign_vars(
|
||||
array(
|
||||
'F_ACTION' => add_session_id(PHPWG_ROOT_PATH.'admin.php?page=comments')
|
||||
'F_ACTION' => PHPWG_ROOT_PATH.'admin.php?page=comments'
|
||||
)
|
||||
);
|
||||
|
||||
@@ -141,10 +141,8 @@ while ($row = mysql_fetch_array($result))
|
||||
'comment',
|
||||
array(
|
||||
'U_PICTURE' =>
|
||||
add_session_id(
|
||||
PHPWG_ROOT_PATH.'admin.php?page=picture_modify'.
|
||||
'&image_id='.$row['image_id']
|
||||
),
|
||||
'&image_id='.$row['image_id'],
|
||||
'ID' => $row['id'],
|
||||
'TN_SRC' => get_thumbnail_src($row['path'], @$row['tn_ext']),
|
||||
'AUTHOR' => $row['author'],
|
||||
|
||||
Reference in New Issue
Block a user