fix: v0.8.15 — auth testMode validates @ in token (block P fix)
This commit is contained in:
@@ -1867,6 +1867,10 @@ func (s *server) handleAuth(w http.ResponseWriter, r *http.Request) {
|
||||
var ns string
|
||||
if s.testMode {
|
||||
// testMode: токен — это sub (email), Deck не вызывается
|
||||
if !strings.Contains(body.Token, "@") {
|
||||
writeJSONError(w, http.StatusUnauthorized, "invalid token")
|
||||
return
|
||||
}
|
||||
ns = func() string {
|
||||
h32 := sha256.Sum256([]byte(body.Token))
|
||||
return "fission-" + hex.EncodeToString(h32[:8])
|
||||
|
||||
Reference in New Issue
Block a user