From 97dadc9958f26fda7cfc43066eee2ba3baccf3b0 Mon Sep 17 00:00:00 2001 From: Daniel Barreto Date: Wed, 28 Jan 2015 14:17:54 -0500 Subject: [PATCH] Enable secret key security - refs BT#9092 --- .../src/HookAdvancedSubscription.class.php | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/plugin/advancedsubscription/src/HookAdvancedSubscription.class.php b/plugin/advancedsubscription/src/HookAdvancedSubscription.class.php index 0aeef46335..27e81eb916 100644 --- a/plugin/advancedsubscription/src/HookAdvancedSubscription.class.php +++ b/plugin/advancedsubscription/src/HookAdvancedSubscription.class.php @@ -378,7 +378,7 @@ class HookAdvancedSubscription extends HookObserver implements if ($debug) error_log('Params '. print_r($params, 1)); if (!WSHelperVerifyKey($params)) { - //return return_error(WS_ERROR_SECRET_KEY); + return return_error(WS_ERROR_SECRET_KEY); } // Check if category ID is set if (!empty($params['id']) && empty($params['category_name'])) { @@ -416,14 +416,14 @@ class HookAdvancedSubscription extends HookObserver implements if (is_array($data)) { if (!WSHelperVerifyKey($data)) { - //return return_error(WS_ERROR_SECRET_KEY); + return return_error(WS_ERROR_SECRET_KEY); } $result = AdvancedSubscriptionPlugin::create()->encrypt($data); } elseif (is_string($data)) { $data = unserialize($data); if (!WSHelperVerifyKey($data)) { - //return return_error(WS_ERROR_SECRET_KEY); + return return_error(WS_ERROR_SECRET_KEY); } if (is_array($data)) { $result = AdvancedSubscriptionPlugin::create()->encrypt($data); @@ -449,7 +449,7 @@ class HookAdvancedSubscription extends HookObserver implements if ($debug) error_log('Params '. print_r($params, 1)); if (!WSHelperVerifyKey($params)) { - //return return_error(WS_ERROR_SECRET_KEY); + return return_error(WS_ERROR_SECRET_KEY); } $result = return_error(WS_ERROR_NOT_FOUND_RESULT); // Check params @@ -530,7 +530,7 @@ class HookAdvancedSubscription extends HookObserver implements // Check if secret key is valid if(!WSHelperVerifyKey($secretKey)) { - //return return_error(WS_ERROR_SECRET_KEY); + return return_error(WS_ERROR_SECRET_KEY); } // Check if category ID is set