Skip to:
Content

BuddyPress.org


Ignore:
Timestamp:
05/24/2016 02:45:08 PM (10 years ago)
Author:
boonebgorges
Message:

Better hash building for activation keys, password reset keys, and filenames.

There is no need to use user-facing info for these hashes.

Ports [10800] to the 2.5 branch.

Props DJPaul, vortfu.

Location:
branches/2.5
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • branches/2.5

    • Property svn:mergeinfo changed
      /trunk (added)merged: 10800
  • branches/2.5/src/bp-members/bp-members-functions.php

    r10601 r10801  
    17921792                $user_login     = preg_replace( '/\s+/', '', sanitize_user( $user_login, true ) );
    17931793                $user_email     = sanitize_email( $user_email );
    1794                 $activation_key = substr( md5( time() . rand() . $user_email ), 0, 16 );
     1794                $activation_key = wp_generate_password( 32, false );
    17951795
    17961796                /**
     
    18141814                        }
    18151815
    1816                         $activation_key = wp_hash( $user_id );
    18171816                        bp_update_user_meta( $user_id, 'activation_key', $activation_key );
    18181817                }
     
    19381937                $user_id = username_exists( $signup->user_login );
    19391938
    1940                 // Create the user.
     1939                // Create the user. This should only be necessary if BP_SIGNUPS_SKIP_USER_CREATION is true.
    19411940                if ( ! $user_id ) {
    19421941                        $user_id = wp_create_user( $signup->user_login, $password, $signup->user_email );
    19431942
    1944                 // If a user ID is found, this may be a legacy signup, or one
    1945                 // created locally for backward compatibility. Process it.
    1946                 } elseif ( $key == wp_hash( $user_id ) ) {
     1943                // Otherwise, update the existing user's status.
     1944                } elseif ( $key === bp_get_user_meta( $user_id, 'activation_key', true ) || $key === wp_hash( $user_id ) ) {
     1945
    19471946                        // Change the user's status so they become active.
    19481947                        if ( ! $wpdb->query( $wpdb->prepare( "UPDATE {$wpdb->users} SET user_status = 0 WHERE ID = %d", $user_id ) ) ) {
     
    21042103                // Rebuild the activation key, if missing.
    21052104                if ( empty( $signup->activation_key ) ) {
    2106                         $signup->activation_key = wp_hash( $signup->ID );
     2105                        $signup->activation_key = wp_generate_password( 32, false );
    21072106                }
    21082107
Note: See TracChangeset for help on using the changeset viewer.