Loading core/lib/Drupal/Core/Access/CsrfTokenGenerator.php +7 −1 Changes for core/lib/Drupal/Core/Access/CsrfTokenGenerator.php: 7 added lines, 1 removed line. Original line number Diff line number Diff line Loading @@ -86,8 +86,14 @@ public function validate($token, $value = '') { if (empty($seed)) { return FALSE; } $value = $this->computeToken($seed, $value); // PHP 8.0 strictly typehints for hash_equals. Maintain BC until we can // enforce scalar typehints on this method. if (!is_string($token)) { return FALSE; } return hash_equals($this->computeToken($seed, $value), $token); return hash_equals($value, $token); } /** Loading Loading
core/lib/Drupal/Core/Access/CsrfTokenGenerator.php +7 −1 Changes for core/lib/Drupal/Core/Access/CsrfTokenGenerator.php: 7 added lines, 1 removed line. Original line number Diff line number Diff line Loading @@ -86,8 +86,14 @@ public function validate($token, $value = '') { if (empty($seed)) { return FALSE; } $value = $this->computeToken($seed, $value); // PHP 8.0 strictly typehints for hash_equals. Maintain BC until we can // enforce scalar typehints on this method. if (!is_string($token)) { return FALSE; } return hash_equals($this->computeToken($seed, $value), $token); return hash_equals($value, $token); } /** Loading