CodeIgniter Forums
_csrf_set_hash() in core security class bug - Printable Version

+- CodeIgniter Forums (https://forum.codeigniter.com)
+-- Forum: Archived Discussions (https://forum.codeigniter.com/forumdisplay.php?fid=20)
+--- Forum: Archived Development & Programming (https://forum.codeigniter.com/forumdisplay.php?fid=23)
+--- Thread: _csrf_set_hash() in core security class bug (/showthread.php?tid=45482)



_csrf_set_hash() in core security class bug - El Forum - 09-23-2011

[eluser]Unknown[/eluser]
When _csrf_set_hash() is call for the very first time a has is generate with


return $this->_csrf_hash = md5(uniqid(rand(), TRUE));


however this has is never set to the cookie