fix(backend): login timing-guard uses a valid bcrypt hash so the compare actually runs
This commit is contained in:
@@ -33,7 +33,7 @@ func (a *api) login(c *gin.Context) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
// 用户不存在也走一次 bcrypt,防用户名枚举时序差
|
// 用户不存在也走一次 bcrypt,防用户名枚举时序差
|
||||||
auth.CheckPassword("$2a$12$000000000000000000000000000000000000000000000000000O", req.Password)
|
auth.CheckPassword("$2a$12$V5TmlpkEi9G/DFAmnkt9YunNdGLnnW921/5TcSo4OeE6iaaLDPN1K", req.Password)
|
||||||
err(c, http.StatusUnauthorized, "unauthorized", "bad credentials")
|
err(c, http.StatusUnauthorized, "unauthorized", "bad credentials")
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user