Browse Source

remove pointless escaping of the password (refs #392)

Andrew Dolgov 8 years ago
parent
commit
4044a5fa52
3 changed files with 6 additions and 6 deletions
  1. 2 2
      api/index.php
  2. 1 1
      functions.php
  3. 3 3
      modules/pref-prefs.php

+ 2 - 2
api/index.php

@@ -80,8 +80,8 @@
 
 		case "login":
 			$login = db_escape_string($_REQUEST["user"]);
-			$password = db_escape_string($_REQUEST["password"]);
-			$password_base64 = db_escape_string(base64_decode($_REQUEST["password"]));
+			$password = $_REQUEST["password"];
+			$password_base64 = base64_decode($_REQUEST["password"]);
 
 			if (SINGLE_USER_MODE) $login = "admin";
 

+ 1 - 1
functions.php

@@ -2111,7 +2111,7 @@
 			# try to authenticate user if called from login form
 			if ($login_action == "do_login") {
 				$login = db_escape_string($_POST["login"]);
-				$password = db_escape_string($_POST["password"]);
+				$password = $_POST["password"];
 				$remember_me = $_POST["remember_me"];
 
 				if (authenticate_user($link, $login, $password)) {

+ 3 - 3
modules/pref-prefs.php

@@ -21,9 +21,9 @@
 
 		if ($subop == "change-password") {
 
-			$old_pw = db_escape_string($_POST["old_password"]);
-			$new_pw = db_escape_string($_POST["new_password"]);
-			$con_pw = db_escape_string($_POST["confirm_password"]);
+			$old_pw = $_POST["old_password"];
+			$new_pw = $_POST["new_password"];
+			$con_pw = $_POST["confirm_password"];
 
 			if ($old_pw == "") {
 				print "ERROR: ".__("Old password cannot be blank.");