Skip to content

Commit 6671cc5

Browse files
MacDadafabpot
authored andcommitted
[Security] TokenBasedRememberMeServices test to show why encoding username is required
1 parent e906970 commit 6671cc5

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

RememberMe/TokenBasedRememberMeServices.php

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,8 @@ protected function onLoginSuccess(Request $request, Response $response, TokenInt
125125
*/
126126
protected function generateCookieValue($class, $username, $expires, $password)
127127
{
128+
// $username is encoded because it might contain COOKIE_DELIMITER,
129+
// we assume other values don't
128130
return $this->encodeCookie(array(
129131
$class,
130132
base64_encode($username),

0 commit comments

Comments
 (0)