We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 5139f7d + 40599c6 commit 3ed3329Copy full SHA for 3ed3329
app/code/Magento/Backend/App/AbstractAction.php
@@ -16,6 +16,7 @@
16
use Magento\Framework\Data\Form\FormKey\Validator as FormKeyValidator;
17
use Magento\Framework\Locale\ResolverInterface;
18
use Magento\Framework\View\Element\AbstractBlock;
19
+use Magento\Framework\Encryption\Helper\Security;
20
21
/**
22
* Generic backend controller
@@ -386,7 +387,7 @@ protected function _validateSecretKey()
386
387
}
388
389
$secretKey = $this->getRequest()->getParam(UrlInterface::SECRET_KEY_PARAM_NAME, null);
- if (!$secretKey || $secretKey != $this->_backendUrl->getSecretKey()) {
390
+ if (!$secretKey || !Security::compareStrings($secretKey, $this->_backendUrl->getSecretKey())) {
391
return false;
392
393
return true;
0 commit comments