[pmg-devel] [PATCH pmg-api 1/2] use hmac_sha_256 for csrf token

Stoiko Ivanov s.ivanov at proxmox.com
Fri Aug 16 16:02:22 CEST 2019


From: Oguz Bektas <o.bektas at proxmox.com>
Signed-off-by: Stoiko Ivanov <s.ivanov at proxmox.com>
---
 src/PMG/Ticket.pm | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/PMG/Ticket.pm b/src/PMG/Ticket.pm
index c9cf096..b1408da 100644
--- a/src/PMG/Ticket.pm
+++ b/src/PMG/Ticket.pm
@@ -139,7 +139,7 @@ my $read_csrf_secret = sub {
 
    my $input = <$fh>;
 
-   return Digest::SHA::sha1_base64($input);
+   return Digest::SHA::hmac_sha256_base64($input);
 };
 
 PVE::INotify::register_file('csrf_secret', $pmg_csrf_key_fn,
-- 
2.20.1




More information about the pmg-devel mailing list