RSS Feed/News remember_cookie from /api/auth/from-session and xf_user cookie

Status
Not open for further replies.

ENXF NET

Administrator
Staff member
Administrator
Moderator
+Lifetime VIP+
S.V.I.P.S Member
S.V.I.P Member
V.I.P Member
Collaborate
Registered
Joined
Nov 13, 2018
Messages
24,727
Points
823

Reputation:

xf_user cookie has urlencoded comma value stored (i.e. 'n%2Cnnnnnnnnn...' instead of just 'n,nnnnnn....'), thus making /api/auth/from-session failing when passing that value as is.

I had to look through the /api source code in order to understand what is wrong and why it did not like my valid xf_user cookie.

Would expect API to do urldecode() of remember_cookie param on its own before running all the checks, otherwise it just fails in...

Read more

Continue reading...
 
Status
Not open for further replies.
Top