[TYPO3-core] RFC #9384: FE session hijacking

Dmitry Dulepov [typo3] dmitry at typo3.org
Thu Sep 18 22:31:16 CEST 2008


Hi!

Martin Kutschker wrote:
> Ok, but for the existing releases (including 4.0) I suggest setting
> $hash_length to 32 (the real md5 hash size). This seems more in spirit
> of a patch-level-release.

It is already set to 32 in the parent class (t3lib_userAuth, near line 147).

-- 
Dmitry Dulepov
TYPO3 Core team
My TYPO3 book: http://www.packtpub.com/typo3-extension-development/book
In the blog: http://typo3bloke.net/post-details/tag_your_typo3_extension_releases_in_svn/


More information about the TYPO3-team-core mailing list