From f52337e8bed8df9b4df299808120776096881b80 Mon Sep 17 00:00:00 2001 From: Roeland Jago Douma Date: Fri, 4 Dec 2020 11:42:40 +0100 Subject: [PATCH] Generate a new session id if the decrypting the session data fails Signed-off-by: Roeland Jago Douma --- lib/private/Session/CryptoSessionData.php | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/private/Session/CryptoSessionData.php b/lib/private/Session/CryptoSessionData.php index fc7693b71b..2b5b5c7b5e 100644 --- a/lib/private/Session/CryptoSessionData.php +++ b/lib/private/Session/CryptoSessionData.php @@ -87,6 +87,7 @@ class CryptoSessionData implements \ArrayAccess, ISession { ); } catch (\Exception $e) { $this->sessionValues = []; + $this->regenerateId(true, false); } }