Use hash_hmac on cookie hashes.

This commit is contained in:
Taylor Otwell
2012-09-25 16:43:58 -04:00
parent 064309c0ce
commit 4eac00a009
3 changed files with 19 additions and 8 deletions

View File

@@ -372,7 +372,7 @@ class SessionTest extends PHPUnit_Framework_TestCase {
$cookie = Cookie::$jar[Config::get('session.cookie')];
$this->assertEquals(sha1('foo'.Config::get('application.key')).'+foo', $cookie['value']);
$this->assertEquals(Cookie::hash('foo').'+foo', $cookie['value']);
// Shouldn't be able to test this cause session.lifetime store number of minutes
// while cookie expiration store timestamp when it going to expired.
// $this->assertEquals(Config::get('session.lifetime'), $cookie['expiration']);