fix: address branch review issues (json tags, share lockout, session expiry, file unlink)
This commit is contained in:
@@ -108,12 +108,35 @@ func (s *Server) handleSharePassword(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
|
||||
key := share.ID
|
||||
s.mu.Lock()
|
||||
if lockTime, locked := s.shareLockout[key]; locked && time.Now().Before(lockTime) {
|
||||
s.mu.Unlock()
|
||||
http.Error(w, "Too many attempts, locked for 60s", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
s.mu.Unlock()
|
||||
|
||||
time.Sleep(500 * time.Millisecond)
|
||||
|
||||
password := r.FormValue("password")
|
||||
if err := bcrypt.CompareHashAndPassword([]byte(share.PasswordHash), []byte(password)); err != nil {
|
||||
s.mu.Lock()
|
||||
s.shareAttempts[key]++
|
||||
if s.shareAttempts[key] >= 5 {
|
||||
s.shareLockout[key] = time.Now().Add(60 * time.Second)
|
||||
s.shareAttempts[key] = 0
|
||||
}
|
||||
s.mu.Unlock()
|
||||
http.Error(w, "Wrong password", http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
|
||||
s.mu.Lock()
|
||||
delete(s.shareAttempts, key)
|
||||
delete(s.shareLockout, key)
|
||||
s.mu.Unlock()
|
||||
|
||||
cookieVal := generateSessionID()
|
||||
s.mu.Lock()
|
||||
if s.shareSessions == nil {
|
||||
|
||||
Reference in New Issue
Block a user