Browse Source

Use random_bytes() to generate IV where available (PHP 7.x)

pull/40/head
Kitty Cat 7 years ago
parent
commit
f978c1b83e
  1. 6
      inc/mod/auth.php

6
inc/mod/auth.php

@ -70,7 +70,11 @@ function test_password($password, $salt, $test) {
function generate_salt() {
// 128 bits of entropy
return strtr(base64_encode(mcrypt_create_iv(16, MCRYPT_DEV_URANDOM)), '+', '.');
if (function_exists('random_bytes')) {
return strtr(base64_encode(random_bytes(16)), '+', '.');
} else {
return strtr(base64_encode(mcrypt_create_iv(16, MCRYPT_DEV_URANDOM)), '+', '.');
}
}
function login($username, $password) {

Loading…
Cancel
Save