2
0
forked from Wavyzz/dolibarr

Add: /core/cookie.class.php for create and encrypt/decrypt cookie value with personnal key

configured in conf.php with $dolibarr_main_cookie_cryptkey
This commit is contained in:
Regis Houssin
2009-05-08 19:46:07 +00:00
parent b38fb205f6
commit 865f6198e8

View File

@@ -438,11 +438,17 @@ if (! isset($_SESSION["dol_login"]))
// TODO Remove this as it is a security hole
if ($conf->multicompany->enabled && isset($_POST["entity"]))
{
include_once(DOL_DOCUMENT_ROOT . "/core/cookie.class.php");
$entity = $_POST["entity"];
$entityCookieName = "DOLENTITYID_dolibarr";
if (!isset($HTTP_COOKIE_VARS[$entityCookieName]))
{
setcookie($entityCookieName, $entity, 0, "/", "", 0);
$entityCookie = new DolCookie($dolibarr_main_cookie_cryptkey);
$entityCookie->_setCookie($entityCookieName, $_POST["entity"]);
//setcookie($entityCookieName, $entity, 0, "/", "", 0);
}
}