##// END OF EJS Templates
Use ActiveSupport::SecureRandom to generate tokens (#3351)....
Jean-Philippe Lang -
r2641:3e523839887f
parent child
Show More
@@ -1,44 +1,41
1 1 # redMine - project management software
2 2 # Copyright (C) 2006 Jean-Philippe Lang
3 3 #
4 4 # This program is free software; you can redistribute it and/or
5 5 # modify it under the terms of the GNU General Public License
6 6 # as published by the Free Software Foundation; either version 2
7 7 # of the License, or (at your option) any later version.
8 8 #
9 9 # This program is distributed in the hope that it will be useful,
10 10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 12 # GNU General Public License for more details.
13 13 #
14 14 # You should have received a copy of the GNU General Public License
15 15 # along with this program; if not, write to the Free Software
16 16 # Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
17 17
18 18 class Token < ActiveRecord::Base
19 19 belongs_to :user
20 20
21 21 @@validity_time = 1.day
22 22
23 23 def before_create
24 24 self.value = Token.generate_token_value
25 25 end
26 26
27 27 # Return true if token has expired
28 28 def expired?
29 29 return Time.now > self.created_on + @@validity_time
30 30 end
31 31
32 32 # Delete all expired tokens
33 33 def self.destroy_expired
34 34 Token.delete_all ["action <> 'feeds' AND created_on < ?", Time.now - @@validity_time]
35 35 end
36 36
37 37 private
38 38 def self.generate_token_value
39 chars = ("a".."z").to_a + ("A".."Z").to_a + ("0".."9").to_a
40 token_value = ''
41 40.times { |i| token_value << chars[rand(chars.size-1)] }
42 token_value
39 ActiveSupport::SecureRandom.hex(20)
43 40 end
44 41 end
General Comments 0
You need to be logged in to leave comments. Login now