Roeland Jago Douma
bb94b39745
This is a hacky way to allow the use case of #1303. What happens is 1. User tries to login 2. PreLoginHook kicks in and figures out that the user need to change their LDAP password or whatever => redirects user 3. While loading the redirect some logic of ours kicks in and logouts the user (thus clearing the session). 4. We render the new page but now the session and the page disagree about the CSRF token This is kind of hacky but I don't think it introduces new attack vectors. Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl> |
7 years ago | |
---|---|---|
.. | ||
composer | Bump autoloader | 7 years ago |
l10n | [tx-robot] updated from transifex | 7 years ago |
private | Do not clear CSRF token on logout (fix for #1303) | 7 years ago |
public | Allow searching for favorites | 7 years ago |
autoloader.php | Add a magic wrapper from hell to allow phpunit4 to run the code again | 7 years ago |
base.php | Remove legacy class OC_Group and OC_User | 7 years ago |