SECURITY: Fix User::setToken() call on User::newSystemUser
This was supposed to reset the user token but did set it to '1' because User::setToken accepts bool/string but only treats true as bool. Bug: T125161 Change-Id: Ia4196eba92cd4d170a3023db0f540a2972ffad4f
This commit is contained in:
parent
fcdd643a46
commit
13f2f09a19
1 changed files with 1 additions and 1 deletions
|
|
@ -539,7 +539,7 @@ final class SessionManager implements SessionManagerInterface {
|
|||
// Reset the user's token to kill existing sessions
|
||||
$user = User::newFromName( $username );
|
||||
if ( $user && $user->getToken( false ) ) {
|
||||
$user->setToken( true );
|
||||
$user->setToken();
|
||||
$user->saveSettings();
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue