SL-12422 Clear cert cache to enshure there is no carry-over between failed logins

meow-7.2.2
Andrey Kleshchev 2021-01-20 20:19:28 +02:00
parent 83127d2299
commit 0d324bb24d
3 changed files with 12 additions and 2 deletions

View File

@ -264,7 +264,9 @@ public:
virtual void validate(int validation_policy,
LLPointer<LLCertificateChain> cert_chain,
const LLSD& validation_params) =0;
// Clear cache if any
virtual void clearSertCache()=0;
};

View File

@ -177,7 +177,10 @@ public:
virtual void validate(int validation_policy,
LLPointer<LLCertificateChain> ca_chain,
const LLSD& validation_params);
// Clears cache of certs validated agains store
virtual void clearSertCache() { mTrustedCertCache.clear(); }
protected:
std::vector<LLPointer<LLCertificate> > mCerts;

View File

@ -2824,6 +2824,11 @@ void reset_login()
// Hide any other stuff
LLFloaterReg::hideVisibleInstances();
LLStartUp::setStartupState( STATE_BROWSER_INIT );
// Clear any verified certs and verify them again on next login
// to ensure cert matches server instead of just getting reused
LLPointer<LLCertificateStore> store = gSecAPIHandler->getCertificateStore("");
store->clearSertCache();
}
//---------------------------------------------------------------------------