From 4cf9b3bd213009158b0069e3375daa7fe917274b Mon Sep 17 00:00:00 2001 From: Peter Rotich <peter@enhancesoft.com> Date: Mon, 26 Aug 2013 18:09:37 +0000 Subject: [PATCH] Require password encryption. --- include/class.email.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/include/class.email.php b/include/class.email.php index a55a0e3e4..9f7ea95b0 100644 --- a/include/class.email.php +++ b/include/class.email.php @@ -245,6 +245,11 @@ class Email { if(!$id && !$vars['passwd']) $errors['passwd']='Password required'; + elseif($vars['passwd'] + && $vars['userid'] + && !Crypto::encrypt($vars['passwd'], SECRET_SALT, $vars['userid']) + ) + $errors['passwd'] = 'Unable to encrypt password - get technical support'; } if($vars['mail_active']) { -- GitLab