Update Security Errors #2044

This commit is contained in:
Hillel Coren 2018-04-21 21:59:00 +03:00
parent 1ae25c4ec7
commit 96e2d6734e

View File

@ -282,7 +282,9 @@ class AppController extends BaseController
if (! Utils::isNinjaProd()) {
if ($password = env('UPDATE_SECRET')) {
if (! hash_equals($password, request('secret') ?: '')) {
echo 'Invalid secret: /update?secret=<value>';
$message = 'Invalid secret: /update?secret=<value>';
Utils::logError($message);
echo $message;
exit;
}
}