From 56604b02a8c0bd2905c82e854f47d41caaeaf9ca Mon Sep 17 00:00:00 2001 From: Roeland Jago Douma Date: Fri, 4 Dec 2020 11:42:40 +0100 Subject: [PATCH] Generate a new session id if the decrypting the session data fails Signed-off-by: Roeland Jago Douma --- lib/private/Session/CryptoSessionData.php | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/private/Session/CryptoSessionData.php b/lib/private/Session/CryptoSessionData.php index a0178c7eea273..24677330dc9fd 100644 --- a/lib/private/Session/CryptoSessionData.php +++ b/lib/private/Session/CryptoSessionData.php @@ -87,6 +87,7 @@ protected function initializeSession() { ); } catch (\Exception $e) { $this->sessionValues = []; + $this->regenerateId(true, false); } }