Append fewer characters to id_secret by default for encrypting csrf tokens.

Seems there is a maximum length and main hit it. It never did for job files - so this should be fine. If you have a secret that is near the maximum lenght one just needs to set ``per_kind_id_secret_base`` to something shorter than id_secret.
This commit is contained in:
John Chilton
2017-09-27 13:13:33 -04:00
parent 8230d14fad
commit 89ce44803e
+1 -1
View File
@@ -888,7 +888,7 @@ class GalaxyWebTransaction(base.DefaultWebTransaction,
token = ''
if self.galaxy_session:
token = self.security.encode_id(
self.galaxy_session.id, kind="session_csrf_token"
self.galaxy_session.id, kind="csrf"
)
return token