Skip to content

Commit

Permalink
Revert r4609 and use stateless request tokens; no need to save them i…
Browse files Browse the repository at this point in the history
…n session and thus no keep-alive necessary; fixes #1487829
  • Loading branch information
thomascube committed Mar 22, 2011
1 parent a8d7c65 commit ec045b0
Show file tree
Hide file tree
Showing 4 changed files with 8 additions and 12 deletions.
1 change: 1 addition & 0 deletions CHANGELOG
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
CHANGELOG Roundcube Webmail
===========================

- Stateless request tokens. No keep-alive necessary on login page (#1487829)
- PEAR::Net_SMTP 1.5.1
- Allow multiple concurrent compose sessions
- Force names of unique constraints in PostgreSQL DDL
Expand Down
6 changes: 2 additions & 4 deletions index.php
Original file line number Diff line number Diff line change
Expand Up @@ -154,9 +154,7 @@

// not logged in -> show login page
if (empty($RCMAIL->user->ID)) {
if ($RCMAIL->action == 'keep-alive')
$OUTPUT->send();
else if ($OUTPUT->ajax_call)
if ($OUTPUT->ajax_call)
$OUTPUT->redirect(array(), 2000);

if (!empty($_REQUEST['_framed']))
Expand Down Expand Up @@ -184,7 +182,7 @@

// check client X-header to verify request origin
if ($OUTPUT->ajax_call) {
if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token()) {
if (rc_request_header('X-Roundcube-Request') != $RCMAIL->get_request_token() && !$RCMAIL->config->get('devel_mode')) {
header('HTTP/1.1 404 Not Found');
die("Invalid Request");
}
Expand Down
11 changes: 4 additions & 7 deletions program/include/rcmail.php
Original file line number Diff line number Diff line change
Expand Up @@ -1106,12 +1106,8 @@ public function shutdown()
*/
public function get_request_token()
{
$key = $this->task;

if (!$_SESSION['request_tokens'][$key])
$_SESSION['request_tokens'][$key] = md5(uniqid($key . mt_rand(), true));

return $_SESSION['request_tokens'][$key];
$sess_id = $_COOKIE[ini_get('session.name')];
return md5('RT' . $this->task . $this->config->get('des_key') . $sess_id);
}


Expand All @@ -1124,7 +1120,8 @@ public function get_request_token()
public function check_request($mode = RCUBE_INPUT_POST)
{
$token = get_input_value('_token', $mode);
return !empty($token) && $_SESSION['request_tokens'][$this->task] == $token;
$sess_id = $_COOKIE[ini_get('session.name')];
return !empty($sess_id) && $token == $this->get_request_token();
}


Expand Down
2 changes: 1 addition & 1 deletion program/js/app.js
Original file line number Diff line number Diff line change
Expand Up @@ -5431,7 +5431,7 @@ function rcube_webmail()

if (this.env.keep_alive && !this.env.framed && this.task == 'mail' && this.gui_objects.mailboxlist)
this._int = setInterval(function(){ ref.check_for_recent(false); }, this.env.keep_alive * 1000);
else if (this.env.keep_alive && !this.env.framed && this.env.action != 'print')
else if (this.env.keep_alive && !this.env.framed && this.task != 'login' && this.env.action != 'print')
this._int = setInterval(function(){ ref.send_keep_alive(); }, this.env.keep_alive * 1000);
};

Expand Down

0 comments on commit ec045b0

Please sign in to comment.