Files
airsonic-custom/airsonic-main
jvoisin 3e07ea5288 Use a random key to "encrypt" the remember-me cookie's value
Since Spring's default remember-me technique is
terrible security-wise (`user:timstamp:md5(use:timestamp:password:key)`),
we should at least use a random key, instead of a fixed one,
otherwise, and attacker able to capture the cookies
might be able to trivially bruteforce offline
the password of the associated user.
2019-04-01 11:33:35 +02:00
..