token: do not expose full checkin timestamp
This commit is contained in:
parent
b725d7d52c
commit
2406fc4efe
3 changed files with 4 additions and 4 deletions
|
@ -471,7 +471,7 @@ sub status_token_ok {
|
|||
$ts2 //= $ts2_ext;
|
||||
|
||||
if ( $eva == $status->{dep_eva}
|
||||
and $ts == $status->{timestamp}->epoch
|
||||
and $ts == $status->{timestamp}->epoch % 337
|
||||
and $ts2 == $status->{sched_departure}->epoch )
|
||||
{
|
||||
return 1;
|
||||
|
@ -491,7 +491,7 @@ sub journey_token_ok {
|
|||
$ts2 //= $ts2_ext;
|
||||
|
||||
if ( $eva == $journey->{from_eva}
|
||||
and $ts == $journey->{checkin_ts}
|
||||
and $ts == $journey->{checkin_ts} % 337
|
||||
and $ts2 == $journey->{sched_dep_ts} )
|
||||
{
|
||||
return 1;
|
||||
|
|
|
@ -286,7 +286,7 @@
|
|||
data-url="<%= url_for('/status')->to_abs->scheme('https') %>/<%= $user->{name} %>/<%= $journey->{sched_departure}->epoch %>"
|
||||
% }
|
||||
% elsif ($journey_visibility eq 'travelynx' or $journey_visibility eq 'unlisted') {
|
||||
data-url="<%= url_for('/status')->to_abs->scheme('https') %>/<%= $user->{name} %>/<%= $journey->{sched_departure}->epoch %>?token=<%= $journey->{dep_eva} %>-<%= $journey->{timestamp}->epoch %>"
|
||||
data-url="<%= url_for('/status')->to_abs->scheme('https') %>/<%= $user->{name} %>/<%= $journey->{sched_departure}->epoch %>?token=<%= $journey->{dep_eva} %>-<%= $journey->{timestamp}->epoch % 337 %>"
|
||||
% }
|
||||
>
|
||||
<i class="material-icons left" aria-hidden="true">share</i> Teilen
|
||||
|
|
|
@ -250,7 +250,7 @@
|
|||
data-url="<%= url_for('public_journey', name => current_user()->{name}, id => $journey->{id} )->to_abs->scheme('https'); %>"
|
||||
% }
|
||||
% else {
|
||||
data-url="<%= url_for('public_journey', name => current_user()->{name}, id => $journey->{id} )->to_abs->scheme('https'); %>?token=<%= $journey->{from_eva} %>-<%= $journey->{checkin_ts} %>-<%= $journey->{sched_dep_ts} %>"
|
||||
data-url="<%= url_for('public_journey', name => current_user()->{name}, id => $journey->{id} )->to_abs->scheme('https'); %>?token=<%= $journey->{from_eva} %>-<%= $journey->{checkin_ts} % 337 %>-<%= $journey->{sched_dep_ts} %>"
|
||||
% }
|
||||
data-text="<%= stash('share_text') %>"
|
||||
>
|
||||
|
|
Loading…
Reference in a new issue