Skip to content

Conversation

@ChristophWurst
Copy link
Member

@ChristophWurst ChristophWurst commented Feb 2, 2017

I noticed this inconsistency when I took a look at #3361.

The cookie is set here:

setcookie('nc_token', $token, $expires, $webRoot, '', $secureCookie, true);

@LukasReschke as discussed 😉

Signed-off-by: Christoph Wurst <[email protected]>
@ChristophWurst ChristophWurst added 2. developing Work in progress bug labels Feb 2, 2017
@ChristophWurst ChristophWurst added this to the Nextcloud 12.0 milestone Feb 2, 2017
@mention-bot
Copy link

@ChristophWurst, thanks for your PR! By analyzing the history of the files in this pull request, we identified @nickvergessen, @LukasReschke and @tanghus to be potential reviewers.

@nickvergessen
Copy link
Member

Any noticable impact?

@ChristophWurst
Copy link
Member Author

Any noticable impact?

Dunno, but I hope @LukasReschke does 😉

@ChristophWurst ChristophWurst added 3. to review Waiting for reviews and removed 2. developing Work in progress labels Feb 6, 2017
*/
public function logout() {
$loginToken = $this->request->getCookie('oc_token');
$loginToken = $this->request->getCookie('nc_token');
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please prepare backport of this single change also to all older versions where you changed the cookie name.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

okidoke 👷

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Backport in #3511

Only nc11 is affected: #1347 was not backported

@LukasReschke
Copy link
Member

LukasReschke commented Feb 6, 2017

Any noticable impact?

Nothing too horrible:

  • Same-Site cookies not triggered on login via remember me. But after the login they are (because of session_name).
  • Remember me token isn't deleted if someone presses logout.

The second one should be backported. The first one I'd avoid. @ChristophWurst can you take care of that? THX.

Copy link
Member

@MorrisJobke MorrisJobke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested and works fine 👍

@nickvergessen nickvergessen merged commit ac841ee into master Feb 9, 2017
@nickvergessen nickvergessen deleted the fix/nc-token-cookie-name branch February 9, 2017 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Waiting for reviews bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants