]> wagnertech.de Git - mfinanz.git/blobdiff - SL/Dispatcher.pm
Das Benutzer-Passwort nicht im Klartext in Session-Tabelle ablegen
[mfinanz.git] / SL / Dispatcher.pm
index 76fcf6fb7b23f67b5dc6da8966f6f8a466323418..239cdcb96de690bdbf75a60fd3ba997248a02f81 100644 (file)
@@ -202,7 +202,7 @@ sub handle_request {
 
       show_error('login/password_error', 'password') if SL::Auth::OK != $::auth->authenticate($::form->{login}, $::form->{password});
 
-      $::auth->set_session_value('login', $::form->{login}, 'password', $::form->{password});
+      $::auth->store_credentials_in_session(login => $::form->{login}, password => $::form->{password});
       $::auth->create_or_refresh_session;
       $::auth->delete_session_value('FLASH');
       delete $::form->{password};