parent
a30213dd5c
commit
be02df63c4
6 changed files with 28 additions and 17 deletions
@ -1,10 +1,10 @@ |
||||
--- htdocs/main.inc.php.orig 2021-04-09 19:02:49.957818778 +0200
|
||||
+++ htdocs/main.inc.php 2021-04-21 18:10:31.597094173 +0200
|
||||
@@ -455,6 +455,7 @@
|
||||
}
|
||||
--- /opt/dolibarr_1/web/htdocs/main.inc.php.orig 2021-08-27 11:40:42.177502730 +0200
|
||||
+++ /opt/dolibarr_1/web/htdocs/main.inc.php 2021-08-27 11:41:02.821219393 +0200
|
||||
@@ -507,6 +507,7 @@
|
||||
}
|
||||
|
||||
$sessiontokenforthisurl = (empty($_SESSION['token']) ? '' : $_SESSION['token']);
|
||||
+ $_GET['token'] = $_SESSION['token']; // Tmp workaround for https://github.com/Dolibarr/dolibarr/issues/16096
|
||||
if (GETPOSTISSET('token') && GETPOST('token', 'alpha') != $_SESSION['token'])
|
||||
{
|
||||
dol_syslog("--- Access to ".$_SERVER["PHP_SELF"]." refused due to invalid token, so we disable POST and some GET parameters - referer=".$_SERVER['HTTP_REFERER'].", action=".GETPOST('action', 'aZ09').", _GET|POST['token']=".GETPOST('token', 'alpha').", _SESSION['token']=".$_SESSION['token'], LOG_WARNING);
|
||||
// TODO Get the sessiontokenforthisurl into the array of session token
|
||||
if (GETPOSTISSET('token') && GETPOST('token') != 'notrequired' && GETPOST('token', 'alpha') != $sessiontokenforthisurl) {
|
||||
dol_syslog("--- Access to ".(empty($_SERVER["REQUEST_METHOD"])?'':$_SERVER["REQUEST_METHOD"].' ').$_SERVER["PHP_SELF"]." refused due to invalid token, so we disable POST and some GET parameters - referer=".$_SERVER['HTTP_REFERER'].", action=".GETPOST('action', 'aZ09').", _GET|POST['token']=".GETPOST('token', 'alpha').", _SESSION['token']=".$_SESSION['token'], LOG_WARNING);
|
||||
|
@ -0,0 +1,9 @@ |
||||
ALTER TABLE `certificate` |
||||
DROP KEY `pki_realm_2`, |
||||
ADD KEY `pki_realm_req_key` (`pki_realm`,`req_key`), |
||||
ADD KEY `req_key` (`req_key`); |
||||
|
||||
ALTER TABLE `csr_attributes` |
||||
ADD KEY `pki_realm_req_key` (`pki_realm`,`req_key`); |
||||
|
||||
|
Loading…
Reference in new issue