From 87bb8e37fbcc19375bc034afbf8365547185f767 Mon Sep 17 00:00:00 2001 From: Andrew Williams Date: Wed, 24 Mar 2010 11:10:30 +0000 Subject: [PATCH] Dont use settings secretkey for password resets --- sso/services/jabber/xmppclient.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/sso/services/jabber/xmppclient.py b/sso/services/jabber/xmppclient.py index 7044a94..2de63dd 100644 --- a/sso/services/jabber/xmppclient.py +++ b/sso/services/jabber/xmppclient.py @@ -2,7 +2,6 @@ import time import xmpp import random import hashlib -import settings class JabberAdmin(): """ Adds a jabber user to a remote Jabber server """ @@ -128,7 +127,7 @@ class JabberAdmin(): except: return False - pass = hashlib.sha1('%s%s%s' % (username, settings.SECRET_KEY, random.randint(0, 2147483647))).hexdigest() + pass = hashlib.sha1('%s%s%s' % (username, random.randint(0, 2147483647))).hexdigest() if self.resetpassword(username, pass): return self.kickuser(username) else: