r76081 MediaWiki - Code Review archive

Repository:MediaWiki
Revision:r76080‎ | r76081 | r76082 >
Date:11:59, 5 November 2010
Author:catrope
Status:ok
Tags:
Comment:
1.16wmf4: Revert r76078: was a merge of r76077 which was reverted
Modified paths:
  • /branches/wmf/1.16wmf4/includes/api/ApiLogin.php (modified) (history)

Diff [purge]

Index: branches/wmf/1.16wmf4/includes/api/ApiLogin.php
@@ -85,6 +85,7 @@
8686 $result['lgusername'] = $wgUser->getName();
8787 $result['lgtoken'] = $wgUser->getToken();
8888 $result['cookieprefix'] = $wgCookiePrefix;
 89+ $result['sessionid'] = session_id();
8990 break;
9091
9192 case LoginForm::NEED_TOKEN:
@@ -92,6 +93,7 @@
9394 $result['result'] = 'NeedToken';
9495 $result['token'] = $loginForm->getLoginToken();
9596 $result['cookieprefix'] = $wgCookiePrefix;
 97+ $result['sessionid'] = session_id();
9698 break;
9799
98100 case LoginForm::WRONG_TOKEN:
Property changes on: branches/wmf/1.16wmf4/includes/api/ApiLogin.php
___________________________________________________________________
Modified: svn:mergeinfo
99101 Reverse-merged /trunk/phase3/includes/api/ApiLogin.php:r76077

Past revisions this follows-up on

RevisionCommit summaryAuthorDate
r76077(bug 25793) Don't output the session ID over HTTP, allows session hijacking b...catrope11:42, 5 November 2010
r760781.16wmf4: MFT r76077catrope11:47, 5 November 2010

Status & tagging log