From 51e6f56d257d823664fd3a68d8a164e41c949a66 Mon Sep 17 00:00:00 2001 From: Oguz Bektas Date: Wed, 19 Jun 2019 09:39:33 +0200 Subject: [PATCH] use hmac_sha256 instead of sha1 for csrf token Signed-off-by: Oguz Bektas --- PVE/AccessControl.pm | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/PVE/AccessControl.pm b/PVE/AccessControl.pm index 6ac99ac..e3f90ee 100644 --- a/PVE/AccessControl.pm +++ b/PVE/AccessControl.pm @@ -215,7 +215,7 @@ my $csrf_prevention_secret; my $get_csrfr_secret = sub { if (!$csrf_prevention_secret) { my $input = PVE::Tools::file_get_contents($pve_www_key_fn); - $csrf_prevention_secret = Digest::SHA::sha1_base64($input); + $csrf_prevention_secret = Digest::SHA::hmac_sha256_base64($input); } return $csrf_prevention_secret; }; -- 2.39.2