--- a/web/common.php Mon Nov 25 18:54:00 2013 +0100
+++ b/web/common.php Mon Nov 25 19:06:54 2013 +0100
@@ -23,6 +23,8 @@
$C_event_props = __DIR__ . "/event_props";
$C_event_users = array('polemictweet' => 'polemictweet'.date('Y/m/d'));
+$C_openssl_cipher_iv_length = 16; //openssl_cipher_iv_length('aes256')
+
$archives_list = array(
"rsln", "rsln-opendata", "rsln-mercedes-bunz",
"enmi2011-technologie-confiance", "CPV", array("fens_FabLab_Design_Metadata","fablab"),
--- a/web/event_list.php Mon Nov 25 18:54:00 2013 +0100
+++ b/web/event_list.php Mon Nov 25 19:06:54 2013 +0100
@@ -6,8 +6,8 @@
if(isset($_REQUEST['delete']) && !empty($_REQUEST['delete'])) {
$delete_enc = base64_decode($_REQUEST['delete']);
- $iv = substr($delete_enc, 0, openssl_cipher_iv_length('aes256'));
- $delete_dec = openssl_decrypt(substr($delete_enc, openssl_cipher_iv_length('aes256')), 'aes256', hash('sha256', SECRET, true), 0, $iv);
+ $iv = substr($delete_enc, 0, $C_openssl_cipher_iv_length);
+ $delete_dec = openssl_decrypt(substr($delete_enc, $C_openssl_cipher_iv_length), 'aes256', hash('sha256', SECRET, true), 0, $iv);
if(is_file($dir."/".$delete_dec)) {
unlink($dir."/".$delete_dec);
}
@@ -96,7 +96,7 @@
<ul class="event-list">
<?php
$files = scandir($dir);
- $iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length('aes256'));
+ $iv = openssl_random_pseudo_bytes($C_openssl_cipher_iv_length);
foreach($files as $ind_file) {
if (stripos($ind_file, '.') !== 0) {