fix: check the challenge substring

This commit is contained in:
Derrick Hammer 2024-01-16 14:45:07 -05:00
parent 1b680dd399
commit db46fcd774
Signed by: pcfreak30
GPG Key ID: C997C339BE476FF2
1 changed files with 2 additions and 2 deletions

View File

@ -280,7 +280,7 @@ func (h *HttpHandler) AccountRegister(jc jape.Context) {
return
}
if !bytes.Equal(decodedResponse, decodedChallenge) {
if !bytes.Equal(decodedResponse[1:33], decodedChallenge) {
errored(errInvalidChallengeErr)
return
}
@ -451,7 +451,7 @@ func (h *HttpHandler) AccountLogin(jc jape.Context) {
return
}
if !bytes.Equal(decodedResponse, decodedChallenge) {
if !bytes.Equal(decodedResponse[1:33], decodedChallenge) {
errored(errInvalidChallengeErr)
return
}