Delete code for compatibility with old forms of authentication.
This commit is contained in:
@@ -2582,10 +2582,10 @@ class Bootstrap
|
||||
$passwordHashConfig = Bootstrap::getPasswordHashConfig();
|
||||
$hashTypeCurrent = $passwordHashConfig['current'];
|
||||
$hashTypePrevious = $passwordHashConfig['previous'];
|
||||
if ((Bootstrap::hashPassword($pass, $hashTypeCurrent) == $userPass) || ($pass === $hashTypeCurrent . ':' . $userPass)) {
|
||||
if (Bootstrap::hashPassword($pass, $hashTypeCurrent) == $userPass) {
|
||||
return true;
|
||||
}
|
||||
if ((Bootstrap::hashPassword($pass, $hashTypePrevious) == $userPass) || ($pass === $hashTypePrevious . ':' . $userPass)) {
|
||||
if (Bootstrap::hashPassword($pass, $hashTypePrevious) == $userPass) {
|
||||
return true;
|
||||
}
|
||||
return false;
|
||||
|
||||
@@ -41,18 +41,6 @@ try {
|
||||
die();
|
||||
}
|
||||
|
||||
//Check if the password contains the password hashes
|
||||
if (!empty($_POST['form']['USR_PASSWORD']) && strlen($_POST['form']['USR_PASSWORD']) > 32) {
|
||||
$pass = trim($_POST['form']['USR_PASSWORD']);
|
||||
foreach (Bootstrap::getPasswordHashConfig() as $key => $hash) {
|
||||
$search = substr($pass, 0, strlen($hash) + 1);
|
||||
if ($search == $hash . ':') {
|
||||
$pass = substr($pass, strlen($hash) + 1);
|
||||
}
|
||||
}
|
||||
$_POST['form']['USR_PASSWORD'] = $pass;
|
||||
}
|
||||
|
||||
$frm = $_POST['form'];
|
||||
|
||||
if (isset($frm['USR_USERNAME'])) {
|
||||
|
||||
Reference in New Issue
Block a user