[security]이메일 인증 페이지 접근 토큰을 HMAC-SHA256으로 강화

This commit is contained in:
thisgun
2026-04-16 02:21:23 +00:00
parent c00c73465a
commit 2894c269ea
3 changed files with 22 additions and 3 deletions
+1 -1
View File
@@ -54,7 +54,7 @@ if ($mb['mb_leave_date'] && $mb['mb_leave_date'] <= date("Ymd", G5_SERVER_TIME))
// 메일인증 설정이 되어 있다면
if ( is_use_email_certify() && !preg_match("/[1-9]/", $mb['mb_email_certify'])) {
$ckey = md5($mb['mb_ip'].$mb['mb_datetime']);
$ckey = function_exists('get_email_cert_key') ? get_email_cert_key($mb_id, $mb['mb_datetime']) : md5($mb['mb_ip'].$mb['mb_datetime']);
confirm("{$mb['mb_email']} 메일로 메일인증을 받으셔야 로그인 가능합니다. 다른 메일주소로 변경하여 인증하시려면 취소를 클릭하시기 바랍니다.", G5_URL, G5_BBS_URL.'/register_email.php?mb_id='.$mb_id.'&ckey='.$ckey);
}
+2 -2
View File
@@ -18,9 +18,9 @@ if (substr($mb['mb_email_certify'],0,1)!=0) {
}
$ckey = isset($_GET['ckey']) ? trim($_GET['ckey']) : '';
$key = md5($mb['mb_ip'].$mb['mb_datetime']);
$key = function_exists('get_email_cert_key') ? get_email_cert_key($mb_id, $mb['mb_datetime']) : md5($mb['mb_ip'].$mb['mb_datetime']);
if(!$ckey || $ckey != $key)
if(!$ckey || $ckey !== $key)
alert('올바른 방법으로 이용해 주십시오.', G5_URL);
?>
+19
View File
@@ -2467,6 +2467,25 @@ function check_token()
return true;
}
/**
* 이메일 미인증 회원의 메일주소 변경 페이지 접근 토큰을 생성한다.
*
* HMAC-SHA256 + 서버 시크릿(G5_TOKEN_ENCRYPTION_KEY)
* @param string $mb_id
* @param string $mb_datetime
* @return string 64자 hex
*/
function get_email_cert_key($mb_id, $mb_datetime)
{
$key = (defined('G5_TOKEN_ENCRYPTION_KEY') && G5_TOKEN_ENCRYPTION_KEY)
? G5_TOKEN_ENCRYPTION_KEY
: (defined('G5_TABLE_PREFIX') ? G5_TABLE_PREFIX : '');
$payload = 'email_cert|' . $mb_id . '|' . $mb_datetime;
return hash_hmac('sha256', $payload, $key);
}
/**
* CSRF 방지용 Origin/Referer 검증 (OWASP 권장 패턴).
*