Fix timing attack on signin
Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -505,7 +505,7 @@ func (s AuthService) CheckCredentials(
|
||||
// Perform a password comparison even when the identity does not exist to mitigate timing attacks
|
||||
// and prevent revealing account existence.
|
||||
if identity.ID == gid.Nil {
|
||||
_, _ = s.hp.ComparePasswordAndHash([]byte(password+"qwertyuiop1234567890"), []byte("qwertyuiop1234567890"))
|
||||
_, _ = s.hp.ComparePasswordAndHash([]byte(password), s.dummyHash)
|
||||
return NewInvalidCredentialsError("invalid email or password")
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user