From 18e31396f3ab309426ad8e0376ae577c424495c9 Mon Sep 17 00:00:00 2001 From: Fendy Date: Fri, 4 Sep 2026 23:59:39 +0800 Subject: [PATCH] fix(backend): login timing-guard uses a valid bcrypt hash so the compare actually runs --- backend/internal/api/auth.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/internal/api/auth.go b/backend/internal/api/auth.go index 0f285b3..d793521 100644 --- a/backend/internal/api/auth.go +++ b/backend/internal/api/auth.go @@ -33,7 +33,7 @@ func (a *api) login(c *gin.Context) { return } // 用户不存在也走一次 bcrypt,防用户名枚举时序差 - auth.CheckPassword("$2a$12$000000000000000000000000000000000000000000000000000O", req.Password) + auth.CheckPassword("$2a$12$V5TmlpkEi9G/DFAmnkt9YunNdGLnnW921/5TcSo4OeE6iaaLDPN1K", req.Password) err(c, http.StatusUnauthorized, "unauthorized", "bad credentials") return }