From 49483bdb4823ed66e2afaa2b642c8c6f2853b41c Mon Sep 17 00:00:00 2001 From: epriestley Date: Thu, 15 Nov 2018 05:28:46 -0800 Subject: [PATCH] Use "%P" to protect session key hashes in SessionEngine queries from DarkConsole Summary: Ref T6960. Ref T13217. Ref T13216. Depends on D19811. Use the recently-introduced "%P" conversion ("Password/Secret") to load sessions in SessionEngine. This secret isn't critical to protect (it's the //hash// of the actual secret and not useful to attackers on its own) but it shows up on every page in DarkConsole and is an obvious case where `%P` is a more appropriate conversion. Test Plan: Note "*********" in the middle of the output here, instead of a session key hash: {F6012805} Reviewers: amckinley Reviewed By: amckinley Maniphest Tasks: T13217, T13216, T6960 Differential Revision: https://secure.phabricator.com/D19812 --- src/applications/auth/engine/PhabricatorAuthSessionEngine.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/applications/auth/engine/PhabricatorAuthSessionEngine.php b/src/applications/auth/engine/PhabricatorAuthSessionEngine.php index 76c0b310a3..98ec8b744a 100644 --- a/src/applications/auth/engine/PhabricatorAuthSessionEngine.php +++ b/src/applications/auth/engine/PhabricatorAuthSessionEngine.php @@ -127,12 +127,12 @@ final class PhabricatorAuthSessionEngine extends Phobject { u.* %Q FROM %T u JOIN %T s ON u.phid = s.userPHID - AND s.type = %s AND s.sessionKey = %s %Q', + AND s.type = %s AND s.sessionKey = %P %Q', $cache_selects, $user_table->getTableName(), $session_table->getTableName(), $session_type, - $session_key, + new PhutilOpaqueEnvelope($session_key), $cache_joins); if (!$info) { -- 2.51.2