dépôts
/
lhc
/
web
/
wiklou.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
| inline |
side by side
SECURITY: Throw exception on unknown hash algorithm
[lhc/web/wiklou.git]
/
includes
/
password
/
MWOldPassword.php
diff --git
a/includes/password/MWOldPassword.php
b/includes/password/MWOldPassword.php
index
2150e56
..
84675c1
100644
(file)
--- a/
includes/password/MWOldPassword.php
+++ b/
includes/password/MWOldPassword.php
@@
-44,5
+44,9
@@
class MWOldPassword extends ParameterizedPassword {
$this->args = [];
$this->hash = md5( $plaintext );
}
+
+ if ( !is_string( $this->hash ) || strlen( $this->hash ) < 32 ) {
+ throw new PasswordError( 'Error when hashing password.' );
+ }
}
}