fix(backend): login timing-guard uses a valid bcrypt hash so the compare actually runs

This commit is contained in:
2026-09-04 23:59:39 +08:00
parent bc88cabc47
commit 18e31396f3
+1 -1
View File
@@ -33,7 +33,7 @@ func (a *api) login(c *gin.Context) {
return
}
// 用户不存在也走一次 bcrypt,防用户名枚举时序差
auth.CheckPassword("$2a$12$000000000000000000000000000000000000000000000000000O", req.Password)
auth.CheckPassword("$2a$12$V5TmlpkEi9G/DFAmnkt9YunNdGLnnW921/5TcSo4OeE6iaaLDPN1K", req.Password)
err(c, http.StatusUnauthorized, "unauthorized", "bad credentials")
return
}