Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove AID / CID / Hash(AID) / Hash(CID) / HASH(password) from the result page #5

Open
vthibault opened this issue Aug 9, 2013 · 2 comments

Comments

@vthibault
Copy link
Contributor

To avoid some future hacks, it's better to remove all account id and character id occurrences in the control panel (code source, url, browser storage) for regular users.

They don't need the account id in the URL, since they can just check/modify their own account.
The character id can be replace by the character slot, more secured.

It should also be removed if it's a md5 hash, in the URL OR in the cookie.
The cookie should also not contain the md5 of the user password to avoid hack, really.

@FlippAcademy
Copy link
Owner

That's true. Lets not forget that this code is pretty out-dated to say the least :(

@FlippAcademy
Copy link
Owner

Sorry for the late reply. I didnt seem to get a notification of this =/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants