HOTFIX: fix security issue

This commit is contained in:
Project_IO 2024-09-11 00:36:03 +09:00
parent 98cc3edf93
commit ed35341316

View file

@ -10,7 +10,7 @@ def login(auth: Credential, resp: Response):
data = service.read(auth.username) data = service.read(auth.username)
hashed = hash(auth.password, data.salt) hashed = hash(auth.password, data.salt)
if not data.username == auth.username and not data.password == hashed: if data.username != auth.username or data.password != hashed:
resp.status_code = 401 resp.status_code = 401
return { return {
"ok": 0, "ok": 0,