Skip to content
Permalink
Browse files

Revert "MDL-31248 - lib - Alteration to the rc4encrypt function to al…

…low for old password use."

This reverts commit 6704edc.
  • Loading branch information...
stronk7 committed Mar 9, 2012
1 parent 929eeb0 commit f852a52aad93cd9ec79d27c9c14c9cfac54ae0b4
Showing with 13 additions and 31 deletions.
  1. +10 −20 lib/moodlelib.php
  2. +3 −11 lib/sessionlib.php
@@ -6852,35 +6852,25 @@ protected function prepare_emoticon_object($text, $imagename, $altidentifier = n
*
* @todo Finish documenting this function
*
* @param string $data Data to encrypt.
* @param bool $usesecurekey Lets us know if we are using the old or new password.
* @return string The now encrypted data.
* @param string $data Data to encrypt
* @return string The now encrypted data
*/
function rc4encrypt($data, $usesecurekey = false) {
if (!$usesecurekey) {
$passwordkey = 'nfgjeingjk';
} else {
$passwordkey = get_site_identifier();
}
return endecrypt($passwordkey, $data, '');
function rc4encrypt($data) {
$password = get_site_identifier();
return endecrypt($password, $data, '');
}
/**
* rc4decrypt
*
* @todo Finish documenting this function
*
* @param string $data Data to decrypt.
* @param bool $usesecurekey Lets us know if we are using the old or new password.
* @return string The now decrypted data.
* @param string $data Data to decrypt
* @return string The now decrypted data
*/
function rc4decrypt($data, $usesecurekey = false) {
if (!$usesecurekey) {
$passwordkey = 'nfgjeingjk';
} else {
$passwordkey = get_site_identifier();
}
return endecrypt($passwordkey, $data, 'de');
function rc4decrypt($data) {
$password = get_site_identifier();
return endecrypt($password, $data, 'de');
}
/**
@@ -828,7 +828,7 @@ function set_moodle_cookie($username) {
if ($username !== '') {
// set username cookie for 60 days
setcookie($cookiename, rc4encrypt($username, true), time()+(DAYSECS*60), $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
setcookie($cookiename, rc4encrypt($username), time()+(DAYSECS*60), $CFG->sessioncookiepath, $CFG->sessioncookiedomain, $CFG->cookiesecure, $CFG->cookiehttponly);
}
}
@@ -849,18 +849,10 @@ function get_moodle_cookie() {
if (empty($_COOKIE[$cookiename])) {
return '';
} else {
$username = rc4decrypt($_COOKIE[$cookiename], true);
if ($username != clean_param($username, PARAM_USERNAME)) {
$username = rc4decrypt($_COOKIE[$cookiename]);
if ($username == clean_param($username, PARAM_USERNAME)) {
set_moodle_cookie($username);
} else {
$username = '';
}
}
$username = rc4decrypt($_COOKIE[$cookiename]);
if ($username === 'guest' or $username === 'nobody') {
// backwards compatibility - we do not set these cookies any more
$username = '';
return '';
}
return $username;
}

0 comments on commit f852a52

Please sign in to comment.
You can’t perform that action at this time.