mirror of
https://github.com/nextcloud/server.git
synced 2026-10-02 15:58:39 +02:00
The remember-me cookie outlives the session token it refers to in two cases, and cookie login then fails on every request. A session token created as DO_NOT_REMEMBER (user_oidc, Apache login) is removed by the cleanup job after session_lifetime, while the cookies last remember_login_cookie_lifetime. loginWithApache() now creates its token as REMEMBER, and createRememberMeToken() marks a DO_NOT_REMEMBER token as REMEMBER for other callers with the same mismatch. ISession::regenerateId(true, true) moves the token to the new session id but left nc_session_id pointing at the old one (password protected share unlock, Talk password rooms). The cookie is now rewritten with the new id. Signed-off-by: Git'Fellow <12234510+solracsf@users.noreply.github.com>