8000 [Security] Prefer clone over unserialize(serialize()) for user refres… · symfony/symfony@a8eba80 · GitHub
[go: up one dir, main page]

Skip to content 8000

Commit a8eba80

Browse files
author
Robin Chalas
committed
[Security] Prefer clone over unserialize(serialize()) for user refreshment
1 parent d1bf595 commit a8eba80

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/Symfony/Component/Security/Http/Firewall/ContextListener.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -170,7 +170,7 @@ protected function refreshUser(TokenInterface $token)
170170

171171
try {
172172
$refreshedUser = $provider->refreshUser($user);
173-
$newToken = unserialize(serialize($token));
173+
$newToken = clone $token;
174174
$newToken->setUser($refreshedUser);
175175

176176
// tokens can be deauthenticated if the user has been changed.

0 commit comments

Comments
 (0)
0