login: regenerates session id on login

This commit is contained in:
Daniel Lee
2017-08-07 10:00:29 +02:00
parent f547c93a4f
commit 1e5778174c
2 changed files with 9 additions and 0 deletions

View File

@@ -143,6 +143,7 @@ func loginUserWithUser(user *m.User, c *middleware.Context) {
c.SetSuperSecureCookie(user.Rands+user.Password, setting.CookieRememberName, user.Login, days, setting.AppSubUrl+"/")
}
c.Session.RegenerateId(c)
c.Session.Set(middleware.SESS_KEY_USERID, user.Id)
}