mirror of
https://github.com/Pathduck/gallery3.git
synced 2026-05-01 02:29:10 -04:00
Add more randomness to reset password mechanism.
This commit is contained in:
@@ -52,7 +52,7 @@ class Password_Controller extends Controller {
|
||||
$user_name = $form->reset->inputs["name"]->value;
|
||||
$user = user::lookup_by_name($user_name);
|
||||
if ($user && !empty($user->email)) {
|
||||
$user->hash = md5(rand());
|
||||
$user->hash = md5(uniqid(mt_rand(), true));
|
||||
$user->save();
|
||||
$message = new View("reset_password.html");
|
||||
$message->confirm_url = url::abs_site("password/do_reset?key=$user->hash");
|
||||
|
||||
Reference in New Issue
Block a user