Pārlūkot izejas kodu

[Form] fixed default CSRF token generation as a token must be tied to the user somewhat

Fabien Potencier 14 gadi atpakaļ
vecāks
revīzija
d326c398e2
1 mainītis faili ar 1 papildinājumiem un 1 dzēšanām
  1. 1 1
      src/Symfony/Component/Form/Form.php

+ 1 - 1
src/Symfony/Component/Form/Form.php

@@ -60,7 +60,7 @@ class Form extends FieldGroup
         if (self::$defaultCsrfSecret !== null) {
             $this->setCsrfSecret(self::$defaultCsrfSecret);
         } else {
-            $this->setCsrfSecret(md5(__FILE__.php_uname()));
+            $this->setCsrfSecret(md5(__FILE__.session_id()));
         }
 
         if (self::$defaultCsrfProtection !== false) {