Authored by 郭成尧

uid-salt

... ... @@ -363,11 +363,10 @@ class AbstractAction extends Controller_Abstract
$cookieList[1] = intval(Encryption::decrypt($cookieList[1]));
if (isset($cookieList[1]) && $cookieList[1]) {
if ($useSession) {
$token = $this->getSession('_TOKEN');
if (empty($token)) {
$token = $this->getCookie('_TOKEN');
}
if ($token === Helpers::makeToken($cookieList[1])) {
$token = $cookieList[3];
$salt = substr($token, -8);
if ($token === Helpers::makeToken($cookieList[1] . $salt)) {
$this->_uid = $cookieList[1];
}
} else {
... ...