Actions
Feature #71739
closedSecurity Improvement: (salted) hash session id before storing in the database
Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Security
Target version:
Start date:
2015-11-20
Due date:
% Done:
0%
Estimated time:
PHP Version:
Tags:
security
Complexity:
Sprint Focus:
Description
To make it harder to exploit read SQL injections, session id should not be stored in "clear text"
Besides that all other similar hashes (e.g. password reset hash) should be treated in the same way
Actions