From 89ce44803ea5cf38b778e61bb7eedfc7b952ce12 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Wed, 27 Sep 2017 13:11:55 -0400 Subject: [PATCH] Append fewer characters to id_secret by default for encrypting csrf tokens. Seems there is a maximum length and main hit it. It never did for job files - so this should be fine. If you have a secret that is near the maximum lenght one just needs to set ``per_kind_id_secret_base`` to something shorter than id_secret. --- lib/galaxy/web/framework/webapp.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/web/framework/webapp.py b/lib/galaxy/web/framework/webapp.py index 786e9c4396f..3b185bb5a1f 100644 --- a/lib/galaxy/web/framework/webapp.py +++ b/lib/galaxy/web/framework/webapp.py @@ -888,7 +888,7 @@ class GalaxyWebTransaction(base.DefaultWebTransaction, token = '' if self.galaxy_session: token = self.security.encode_id( - self.galaxy_session.id, kind="session_csrf_token" + self.galaxy_session.id, kind="csrf" ) return token