* Use a HMAC to sign and validate CSRF tokens, instead of generating random ones and storing them in the session data. Reduces number of writes to sessions table and fixes kanboard issue #4942. * Added missing CSRF check for starting/stopping subtask timers. Co-authored-by: Willemijn Coene <willemijn@irdc.nl> |
||
|---|---|---|
| .. | ||
| AccessMap.php | ||
| AuthenticationManager.php | ||
| AuthenticationProviderInterface.php | ||
| Authorization.php | ||
| OAuthAuthenticationProviderInterface.php | ||
| PasswordAuthenticationProviderInterface.php | ||
| PostAuthenticationProviderInterface.php | ||
| PreAuthenticationProviderInterface.php | ||
| Role.php | ||
| SessionCheckProviderInterface.php | ||
| Token.php | ||