Commit 4c83a034 authored by Dries's avatar Dries
Browse files

- Patch #36591 by chx: use session id to check form submissions, rather than the IP address.

parent 2fa3490e
......@@ -68,7 +68,7 @@ function drupal_get_form($form_id, &$form, $callback = NULL) {
variable_set('drupal_private_key', mt_rand());
}
$form['form_token'] = array('#type' => 'hidden', '#value' => md5($_SERVER['REMOTE_ADDR'] . $form['#token'] . variable_get('drupal_private_key', '')));
$form['form_token'] = array('#type' => 'hidden', '#value' => md5(session_id() . $form['#token'] . variable_get('drupal_private_key', '')));
}
$form['form_id'] = array('#type' => 'hidden', '#default_value' => $form_id);
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment