Move CSRF token handling into MediaWiki\Session\Session
authorBrad Jorsch <bjorsch@wikimedia.org>
Tue, 22 Sep 2015 14:33:24 +0000 (10:33 -0400)
committerBrad Jorsch <bjorsch@wikimedia.org>
Wed, 27 Jan 2016 20:27:20 +0000 (15:27 -0500)
commit94ba53f67731b0553a6178841d9506e384f74496
treea60da8b4c98a7e0d34f5d2fa212f6c275d54ca6b
parent36a87a890291b651d332c510ed9ed791472e4f44
Move CSRF token handling into MediaWiki\Session\Session

User keeps most of its token-related methods because anon edit tokens
are special. Login and createaccount tokens are completely moved.

Change-Id: I524218fab7e2d78fd24482ad364428e98dc48bdf
20 files changed:
RELEASE-NOTES-1.27
autoload.php
docs/hooks.txt
includes/api/ApiBase.php
includes/api/ApiCheckToken.php
includes/api/ApiCreateAccount.php
includes/api/ApiLogin.php
includes/api/ApiQueryTokens.php
includes/api/ApiTokens.php
includes/session/Session.php
includes/session/Token.php [new file with mode: 0644]
includes/specials/SpecialChangePassword.php
includes/specials/SpecialUserlogin.php
includes/user/LoggedOutEditToken.php [new file with mode: 0644]
includes/user/User.php
tests/phpunit/includes/api/ApiCreateAccountTest.php
tests/phpunit/includes/api/ApiLoginTest.php
tests/phpunit/includes/api/ApiTestCase.php
tests/phpunit/includes/session/SessionTest.php
tests/phpunit/includes/session/TokenTest.php [new file with mode: 0644]