Skip to content

Commit 70e215c

Browse files
committed
backport mix phx.gen.auth security improvement
1 parent 0872852 commit 70e215c

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

lib/galaxies_web/live/player_settings_live.ex

+1-1
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ defmodule GalaxiesWeb.PlayerSettingsLive do
6868
<input
6969
name={@password_form[:email].name}
7070
type="hidden"
71-
id="hidden_players_email"
71+
id="hidden_player_email"
7272
value={@current_email}
7373
/>
7474
<.input field={@password_form[:password]} type="password" label="New password" required />

lib/galaxies_web/player_auth.ex

+2
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,8 @@ defmodule GalaxiesWeb.PlayerAuth do
6060
# end
6161
#
6262
defp renew_session(conn) do
63+
delete_csrf_token()
64+
6365
conn
6466
|> configure_session(renew: true)
6567
|> clear_session()

0 commit comments

Comments
 (0)