|
if ($currentUser->authenticate($_POST['username'],$_POST['password'])) |
Desktop app (Qt) uses this for authentication. It would be better if checklogin.php would use hashed password for validation (hashed and then received by checklogin.php with POST) instead of plain text. This way the real password would never be stored as plain text on client side (Desktop app settings.xml).
livehelperchat/lhc_web/modules/lhxml/checklogin.php
Line 11 in 080e86e
Desktop app (Qt) uses this for authentication. It would be better if checklogin.php would use hashed password for validation (hashed and then received by checklogin.php with POST) instead of plain text. This way the real password would never be stored as plain text on client side (Desktop app settings.xml).