fixed guessable CSRF token when detect_record_change, thanks Stephen Röttger

This commit is contained in:
mdipierro
2014-07-02 08:27:02 -05:00
parent eec39aeeec
commit 55016cbd4d
4 changed files with 6 additions and 6 deletions
+2 -2
View File
@@ -2101,7 +2101,7 @@ class FORM(DIV):
status = False
if status and session:
# check if editing a record that has been modified by the server
if hasattr(self, 'record_hash') and self.record_hash != formkey:
if hasattr(self, 'record_hash') and self.record_hash != formkey.split(':')[0]:
status = False
self.record_changed = changed = True
status = self._traverse(status, hideerror)
@@ -2129,7 +2129,7 @@ class FORM(DIV):
status = False
if not session is None:
if hasattr(self, 'record_hash'):
formkey = self.record_hash
formkey = self.record_hash+':'+web2py_uuid()
else:
formkey = web2py_uuid()
self.formkey = formkey