r76077 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r76076‎ | r76077 | r76078 >
Date:11:42, 5 November 2010
Author:catrope
Status:reverted
Tags:
Comment:
(bug 25793) Don't output the session ID over HTTP, allows session hijacking because logins that failed because no token was specified would output the session ID
Modified paths:
  • /trunk/phase3/includes/api/ApiLogin.php (modified) (history)

Diff [purge]

Index: trunk/phase3/includes/api/ApiLogin.php
@@ -87,14 +87,12 @@
8888 $result['lgusername'] = $wgUser->getName();
8989 $result['lgtoken'] = $wgUser->getToken();
9090 $result['cookieprefix'] = $wgCookiePrefix;
91 - $result['sessionid'] = session_id();
9291 break;
9392
9493 case LoginForm::NEED_TOKEN:
9594 $result['result'] = 'NeedToken';
9695 $result['token'] = $loginForm->getLoginToken();
9796 $result['cookieprefix'] = $wgCookiePrefix;
98 - $result['sessionid'] = session_id();
9997 break;
10098
10199 case LoginForm::WRONG_TOKEN:

Follow-up revisions

RevisionCommit summaryAuthorDate
r760781.16wmf4: MFT r76077catrope11:47, 5 November 2010
r76079RELEASE-NOTES for r76077catrope11:48, 5 November 2010
r76080Revert r76077, r76079, they were an overreaction to a security bug that wasn'...catrope11:54, 5 November 2010
r760811.16wmf4: Revert r76078: was a merge of r76077 which was revertedcatrope11:59, 5 November 2010

Status & tagging log