Secure extracts
Updated extract calls to use EXTR_SKIP.
This commit is contained in:
@@ -89,7 +89,7 @@ class Grammar {
|
||||
|
||||
foreach ($query->joins as $join)
|
||||
{
|
||||
extract($join);
|
||||
extract($join, EXTR_SKIP);
|
||||
|
||||
list($column1, $column2) = array($this->wrap($column1), $this->wrap($column2));
|
||||
|
||||
|
||||
@@ -61,7 +61,7 @@ class Cookie implements Driver {
|
||||
*/
|
||||
public function save($session, $config, $exists)
|
||||
{
|
||||
extract($config);
|
||||
extract($config, EXTR_SKIP);
|
||||
|
||||
$payload = $this->crypter->encrypt(serialize($session));
|
||||
|
||||
|
||||
Reference in New Issue
Block a user