From 3824c1c6f259bc0632ede2a021ef418c1f7831dd Mon Sep 17 00:00:00 2001 From: fredtempez Date: Wed, 16 Jan 2019 19:54:44 +0100 Subject: [PATCH] Contremesure faille CRSF --- core/module/user/user.php | 8 -------- 1 file changed, 8 deletions(-) diff --git a/core/module/user/user.php b/core/module/user/user.php index eaff5317..9c4ac943 100755 --- a/core/module/user/user.php +++ b/core/module/user/user.php @@ -160,19 +160,11 @@ class user extends common { 'notification' => 'Jeton invalide' ]); } -<<<<<<< HEAD - elseif ($this->getUrl(4) !== $_SESSION['csrf']) { - // Valeurs en sortie - $this->addOutput([ - 'redirect' => helper::baseUrl() . 'user', - 'notification' => 'Suppression non autorisée' -======= if ($this->getUrl(4) !== $_SESSION['csrf']) { // Valeurs en sortie $this->addOutput([ 'redirect' => helper::baseUrl() . 'user', 'notification' => 'Action non autorisée' ->>>>>>> master_v8 ]); } // Accès autorisé