fix: check the challenge substring
This commit is contained in:
parent
1b680dd399
commit
db46fcd774
|
@ -280,7 +280,7 @@ func (h *HttpHandler) AccountRegister(jc jape.Context) {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if !bytes.Equal(decodedResponse, decodedChallenge) {
|
if !bytes.Equal(decodedResponse[1:33], decodedChallenge) {
|
||||||
errored(errInvalidChallengeErr)
|
errored(errInvalidChallengeErr)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
@ -451,7 +451,7 @@ func (h *HttpHandler) AccountLogin(jc jape.Context) {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if !bytes.Equal(decodedResponse, decodedChallenge) {
|
if !bytes.Equal(decodedResponse[1:33], decodedChallenge) {
|
||||||
errored(errInvalidChallengeErr)
|
errored(errInvalidChallengeErr)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue