fix(backend): login timing-guard uses a valid bcrypt hash so the compare actually runs
This commit is contained in:
@@ -33,7 +33,7 @@ func (a *api) login(c *gin.Context) {
|
||||
return
|
||||
}
|
||||
// 用户不存在也走一次 bcrypt,防用户名枚举时序差
|
||||
auth.CheckPassword("$2a$12$000000000000000000000000000000000000000000000000000O", req.Password)
|
||||
auth.CheckPassword("$2a$12$V5TmlpkEi9G/DFAmnkt9YunNdGLnnW921/5TcSo4OeE6iaaLDPN1K", req.Password)
|
||||
err(c, http.StatusUnauthorized, "unauthorized", "bad credentials")
|
||||
return
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user