Skip to content

Commit d467dae

Browse files
committed
Add empty validation in api_is_valid_secret_key
1 parent 9531caf commit d467dae

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

main/inc/lib/api.lib.php

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6838,7 +6838,11 @@ function api_is_in_group($groupIdParam = null, $courseCodeParam = null)
68386838
*/
68396839
function api_is_valid_secret_key($original_key_secret, $security_key)
68406840
{
6841-
return $original_key_secret == sha1($security_key);
6841+
if (empty($original_key_secret) || empty($security_key)) {
6842+
return false;
6843+
}
6844+
6845+
return $original_key_secret === sha1($security_key);
68426846
}
68436847

68446848
/**

0 commit comments

Comments
 (0)