##// END OF EJS Templates
Use ActiveSupport::SecureRandom to generate tokens (#3351)....
Jean-Philippe Lang -
r2641:3e523839887f
parent child
Show More
@@ -1,44 +1,41
1 # redMine - project management software
1 # redMine - project management software
2 # Copyright (C) 2006 Jean-Philippe Lang
2 # Copyright (C) 2006 Jean-Philippe Lang
3 #
3 #
4 # This program is free software; you can redistribute it and/or
4 # This program is free software; you can redistribute it and/or
5 # modify it under the terms of the GNU General Public License
5 # modify it under the terms of the GNU General Public License
6 # as published by the Free Software Foundation; either version 2
6 # as published by the Free Software Foundation; either version 2
7 # of the License, or (at your option) any later version.
7 # of the License, or (at your option) any later version.
8 #
8 #
9 # This program is distributed in the hope that it will be useful,
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 # GNU General Public License for more details.
12 # GNU General Public License for more details.
13 #
13 #
14 # You should have received a copy of the GNU General Public License
14 # You should have received a copy of the GNU General Public License
15 # along with this program; if not, write to the Free Software
15 # along with this program; if not, write to the Free Software
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
17
17
18 class Token < ActiveRecord::Base
18 class Token < ActiveRecord::Base
19 belongs_to :user
19 belongs_to :user
20
20
21 @@validity_time = 1.day
21 @@validity_time = 1.day
22
22
23 def before_create
23 def before_create
24 self.value = Token.generate_token_value
24 self.value = Token.generate_token_value
25 end
25 end
26
26
27 # Return true if token has expired
27 # Return true if token has expired
28 def expired?
28 def expired?
29 return Time.now > self.created_on + @@validity_time
29 return Time.now > self.created_on + @@validity_time
30 end
30 end
31
31
32 # Delete all expired tokens
32 # Delete all expired tokens
33 def self.destroy_expired
33 def self.destroy_expired
34 Token.delete_all ["action <> 'feeds' AND created_on < ?", Time.now - @@validity_time]
34 Token.delete_all ["action <> 'feeds' AND created_on < ?", Time.now - @@validity_time]
35 end
35 end
36
36
37 private
37 private
38 def self.generate_token_value
38 def self.generate_token_value
39 chars = ("a".."z").to_a + ("A".."Z").to_a + ("0".."9").to_a
39 ActiveSupport::SecureRandom.hex(20)
40 token_value = ''
41 40.times { |i| token_value << chars[rand(chars.size-1)] }
42 token_value
43 end
40 end
44 end
41 end
General Comments 0
You need to be logged in to leave comments. Login now