ebf6151738
There already are dedicated tokens for: - CSRF protection - user stay-signed-in feature, via cookie This token was most likely intended as a randomly generated, server-side, secret key to be used when generating hashes. See http://sebsauvage.net/wiki/doku.php?id=php:session [FR] Relevant section: Une clé secrète unique aléatoire est générée côté serveur (et jamais envoyée). Elle peut servir pour signer les formulaires (HMAC) ou générer des token de formulaires (protection contre XSRF). Voir $_SESSION['uid']. Translation: A unique, server-side secret key is randomly generated (and never transmitted). It can be used to sign forms (HMAC) or generate form tokens (protection against XSRF). See $_SESSION['uid'] Signed-off-by: VirtualTam <virtualtam@flibidi.net> |
||
---|---|---|
.. | ||
api | ||
config | ||
exceptions | ||
security | ||
.htaccess | ||
ApplicationUtils.php | ||
Base64Url.php | ||
Cache.php | ||
CachedPage.php | ||
FeedBuilder.php | ||
FileUtils.php | ||
History.php | ||
HttpUtils.php | ||
Languages.php | ||
LinkDB.php | ||
LinkFilter.php | ||
LinkUtils.php | ||
NetscapeBookmarkUtils.php | ||
PageBuilder.php | ||
PluginManager.php | ||
Router.php | ||
ThemeUtils.php | ||
TimeZone.php | ||
Updater.php | ||
Url.php | ||
Utils.php |