Skip to content

Commit

Permalink
Fix cookie session timestamp validation
Browse files Browse the repository at this point in the history
In certain scenarios localhost could be blocked or take a long time to
resolve, hence the cookie session validation now uses the loopback
address directly instead of localhost
  • Loading branch information
loocars committed Dec 19, 2024
1 parent ec23e88 commit 7cdcc3c
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 1 deletion.
2 changes: 2 additions & 0 deletions ChangeLog
Original file line number Diff line number Diff line change
@@ -1,4 +1,6 @@
1.9.45
* FIX: Fix not working cookie session timestamps validation introduced with 1.9.43 in
when localhost is blocked or takes a long time to resolve

1.9.44
* FIX: Fix not working cookie session timestamps validation introduced with 1.9.43 in
Expand Down
2 changes: 1 addition & 1 deletion share/server/core/classes/CoreLogonMultisite.php
Original file line number Diff line number Diff line change
Expand Up @@ -138,7 +138,7 @@ private function checkAuthCookie($cookieName) {
// Check session periods validity
$site = getenv('OMD_SITE');
$port = $_SERVER['SERVER_PORT'];
$url = "http://localhost:$port/$site/check_mk/api/1.0/version";
$url = "http://127.0.0.1:$port/$site/check_mk/api/1.0/version";

$headers = [
'Content-type: application/json',
Expand Down

0 comments on commit 7cdcc3c

Please sign in to comment.