Skip to content
  • Kasper Skårhøj's avatar
    · 172aeaed
    Kasper Skårhøj authored
    * Added to user authentication that the HTTP_USER_AGENT is hashed and a part of the session lookup (in other words, if the HTTP_USER_AGENT stays constant the session stays as well). Also added possibility of configuring that the IP adresse used to lock down sessions is only part 1,2,3 or 4 (all) used. Mainly this is easily configurable for frontend users (which has had the "security level" set to "2" now instead of disabled totally!). For backend users I didn't make configuration options in TYPO3_CONF_VARS - just wanted to know if people needed it there first (not to bloat options....)
    
    
    git-svn-id: https://svn.typo3.org/TYPO3v4/Core/trunk@218 709f56b5-9817-0410-a4d7-c38de5d9e867
    172aeaed