Browse Source

Use === operator in authentication.

pull/40/head
Michael Save 11 years ago
parent
commit
774e27caf5
  1. 2
      inc/mod/auth.php

2
inc/mod/auth.php

@ -108,7 +108,7 @@ if (isset($_COOKIE[$config['cookies']['mod']])) {
$user = $query->fetch();
// validate password hash
if ($cookie[1] != mkhash($cookie[0], $user['password'], $cookie[2])) {
if ($cookie[1] !== mkhash($cookie[0], $user['password'], $cookie[2])) {
// Malformed cookies
destroyCookies();
error($config['error']['malformed']);

Loading…
Cancel
Save