mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Append fewer characters to id_secret by default for encrypting csrf tokens.
Seems there is a maximum length and main hit it. It never did for job files - so this should be fine. If you have a secret that is near the maximum lenght one just needs to set ``per_kind_id_secret_base`` to something shorter than id_secret.
This commit is contained in:
@@ -888,7 +888,7 @@ class GalaxyWebTransaction(base.DefaultWebTransaction,
|
||||
token = ''
|
||||
if self.galaxy_session:
|
||||
token = self.security.encode_id(
|
||||
self.galaxy_session.id, kind="session_csrf_token"
|
||||
self.galaxy_session.id, kind="csrf"
|
||||
)
|
||||
return token
|
||||
|
||||
|
||||
Reference in New Issue
Block a user