Commit f2c21c11 authored by catch's avatar catch
Browse files

Issue #3156880 by alexpott, Gábor Hojtsy, andypost, hussainweb:...

Issue #3156880 by alexpott, Gábor Hojtsy, andypost, hussainweb: \Drupal\Core\Access\CsrfTokenGenerator::validate() - ensure $token is a string before calling hash_equals()
parent 7982e4a2
Loading
Loading
Loading
Loading
+7 −1
Changes for core/lib/Drupal/Core/Access/CsrfTokenGenerator.php: 7 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -86,8 +86,14 @@ public function validate($token, $value = '') {
    if (empty($seed)) {
      return FALSE;
    }
    $value = $this->computeToken($seed, $value);
    // PHP 8.0 strictly typehints for hash_equals. Maintain BC until we can
    // enforce scalar typehints on this method.
    if (!is_string($token)) {
      return FALSE;
    }

    return hash_equals($this->computeToken($seed, $value), $token);
    return hash_equals($value, $token);
  }

  /**