Skip to content

Commit

Permalink
Merge pull request #282 from silinternational/fix-call-to-updateUserL…
Browse files Browse the repository at this point in the history
…astLogin

Release 10.1.1 fix updateUserLastLogin is called regardless of validity of rememberMeToken
  • Loading branch information
hobbitronics authored Oct 9, 2024
2 parents 2d8f4dd + 342c05e commit 6664fdc
Showing 1 changed file with 5 additions and 3 deletions.
8 changes: 5 additions & 3 deletions modules/mfa/src/Auth/Process/Mfa.php
Original file line number Diff line number Diff line change
Expand Up @@ -700,9 +700,11 @@ public static function isRememberMeCookieValid(
if ((int)$expireDate > time()) {
$expectedString = self::generateRememberMeCookieString($rememberSecret, $state['employeeId'], $expireDate, $mfaOptions);
$isValid = password_verify($expectedString, $cookieHash);

$idBrokerClient = self::getIdBrokerClient($state['idBrokerConfig']);
$idBrokerClient->updateUserLastLogin($state['employeeId']);

if ($isValid) {
$idBrokerClient = self::getIdBrokerClient($state['idBrokerConfig']);
$idBrokerClient->updateUserLastLogin($state['employeeId']);
}

return $isValid;
}
Expand Down

0 comments on commit 6664fdc

Please sign in to comment.