From 83bdc4bc426e838498bb89d3d2daa50463bf192b Mon Sep 17 00:00:00 2001 From: Florian Pritz Date: Fri, 26 Feb 2010 17:30:44 +0100 Subject: move password salt to config Signed-off-by: Florian Pritz --- system/application/config/example/config.php | 1 + system/application/models/file_mod.php | 3 +-- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/system/application/config/example/config.php b/system/application/config/example/config.php index 33a436d31..7b325a3e0 100755 --- a/system/application/config/example/config.php +++ b/system/application/config/example/config.php @@ -343,6 +343,7 @@ $config['upload_max_text_size'] = 2*1024*1024; $config['upload_max_age'] = 60*60*24*5; // 5 days $config['paste_show_url'] = 'file/show_url/'; // "s/" with url rewrite $config['paste_download_url'] = 'file/download/'; // "d/" with url rewrite +$config['passwordsalt'] = ''; // just enter any strign you want here /* End of file config.php */ /* Location: ./system/application/config/config.php */ diff --git a/system/application/models/file_mod.php b/system/application/models/file_mod.php index fae20492c..23c3002af 100644 --- a/system/application/models/file_mod.php +++ b/system/application/models/file_mod.php @@ -66,8 +66,7 @@ class File_mod extends Model { function hash_password($password) { - // TODO: move salt to config - return sha1('w9yFMeU6ITrkrPBlRJfA'.$password); + return sha1($this->config->item('passwordsalt').$password); } private function unused_file($hash) -- cgit v1.2.3-24-g4f1b