[TYPO3-core] RFC #9384: FE session hijacking

Martin Kutschker masi-no at spam-typo3.org
Thu Sep 18 23:50:14 CEST 2008


Dmitry Dulepov [typo3] schrieb:
> Hi!
> 
> Martin Kutschker wrote:
>> Ok, but for the existing releases (including 4.0) I suggest setting
>> $hash_length to 32 (the real md5 hash size). This seems more in spirit
>> of a patch-level-release.
> 
> It is already set to 32 in the parent class (t3lib_userAuth, near line
> 147).

Sorry, I didn't look that up. Then +1 as-is.

Masi


More information about the TYPO3-team-core mailing list