mirror of
https://github.com/discourse/discourse.git
synced 2025-02-25 18:55:32 -06:00
store honeypot challenge in redis for extra security
This commit is contained in:
parent
011d3cf779
commit
90dddb4395
@ -415,7 +415,13 @@ class UsersController < ApplicationController
|
||||
end
|
||||
|
||||
def challenge_value
|
||||
'3019774c067cc2b'
|
||||
challenge = $redis.get('SECRET_CHALLENGE')
|
||||
unless challenge && challenge.length == 16*2
|
||||
challenge = SecureRandom.hex(16)
|
||||
$redis.set('SECRET_CHALLENGE',challenge)
|
||||
end
|
||||
|
||||
challenge
|
||||
end
|
||||
|
||||
def suspicious?(params)
|
||||
|
Loading…
Reference in New Issue
Block a user