diff options
author | friendica <info@friendica.com> | 2014-07-29 20:13:01 -0700 |
---|---|---|
committer | friendica <info@friendica.com> | 2014-07-29 20:13:01 -0700 |
commit | 35ed18967a61e9871becbe6676603ce8e43eeec3 (patch) | |
tree | 1c2694dbbd956db6e5fc5dfce3a1d980203b4fb9 /install/database.sql | |
parent | c8829e72434c4d5342d9b2c4a4f22b33e8ea1887 (diff) | |
download | volse-hubzilla-35ed18967a61e9871becbe6676603ce8e43eeec3.tar.gz volse-hubzilla-35ed18967a61e9871becbe6676603ce8e43eeec3.tar.bz2 volse-hubzilla-35ed18967a61e9871becbe6676603ce8e43eeec3.zip |
block channel removal for 48 hours after changing the account password, since the password is required to remove a channel. Somebody looking at an open session on somebody else's computer can simply change the password and then proceed to maliciously remove the channel. This change gives the owner 2 days to discover that something is wrong and recover his/her password and potentially save their channel from getting erased by the vandal. This is most likely to happen if a relationship has gone bad, or something incriminating was found in your private messages when you left your computer briefly unattended.
Diffstat (limited to 'install/database.sql')
-rw-r--r-- | install/database.sql | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/install/database.sql b/install/database.sql index c0440c035..9d0401a44 100644 --- a/install/database.sql +++ b/install/database.sql @@ -55,6 +55,7 @@ CREATE TABLE IF NOT EXISTS `account` ( `account_expire_notified` datetime NOT NULL DEFAULT '0000-00-00 00:00:00', `account_service_class` char(32) NOT NULL DEFAULT '', `account_level` int(10) unsigned NOT NULL DEFAULT '0', + `account_password_changed` datetime NOT NULL DEFAULT '0000-00-00 00:00:00', PRIMARY KEY (`account_id`), KEY `account_email` (`account_email`), KEY `account_service_class` (`account_service_class`), @@ -65,7 +66,8 @@ CREATE TABLE IF NOT EXISTS `account` ( KEY `account_expires` (`account_expires`), KEY `account_default_channel` (`account_default_channel`), KEY `account_external` (`account_external`), - KEY `account_level` (`account_level`) + KEY `account_level` (`account_level`), + KEY `account_password_changed` (`account_password_changed`) ) ENGINE=MyISAM DEFAULT CHARSET=utf8; CREATE TABLE IF NOT EXISTS `addon` ( |