From 87e1454cd25eaeebd8882782d5bb6b662d418a11 Mon Sep 17 00:00:00 2001 From: Sam Minnee Date: Mon, 16 Nov 2009 03:25:41 +0000 Subject: [PATCH] BUGFIX: Include salt in legacy password encryptor git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/sapphire/trunk@91743 467b73ca-7a2a-4603-9d3b-597d59a354a9 --- security/PasswordEncryptor.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/security/PasswordEncryptor.php b/security/PasswordEncryptor.php index a720d445b..d9a08b3c3 100644 --- a/security/PasswordEncryptor.php +++ b/security/PasswordEncryptor.php @@ -161,7 +161,7 @@ class PasswordEncryptor_PHPHash extends PasswordEncryptor { */ class PasswordEncryptor_LegacyPHPHash extends PasswordEncryptor_PHPHash { function encrypt($password, $salt = null, $member = null) { - $password = parent::encrypt($password, $member, $salt); + $password = parent::encrypt($password . $salt, $member, $salt); // Legacy fix: This shortening logic is producing unpredictable results. //