Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
erp5-Boxiang
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Hamza
erp5-Boxiang
Commits
e3da398b
Commit
e3da398b
authored
May 11, 2016
by
Georgios Dagkakis
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
erp5_access_token: use hmac.compare_digest instead of string comparison
in order to avoid timing attacks /reviewed-on
!115
parent
61d69940
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
4 additions
and
2 deletions
+4
-2
bt5/erp5_access_token/SkinTemplateItem/portal_skins/erp5_access_token/RestrictedAccessToken_getExternalLogin.py
...p5_access_token/RestrictedAccessToken_getExternalLogin.py
+4
-2
No files found.
bt5/erp5_access_token/SkinTemplateItem/portal_skins/erp5_access_token/RestrictedAccessToken_getExternalLogin.py
View file @
e3da398b
from
zExceptions
import
Unauthorized
import
hmac
if
REQUEST
is
not
None
:
raise
Unauthorized
...
...
@@ -14,8 +15,9 @@ if access_token_document.getValidationState() == 'validated':
reference
=
request
.
getHeader
(
"X-ACCESS-TOKEN-SECRET"
,
None
)
if
reference
is
None
:
reference
=
request
.
form
.
get
(
"access_token_secret"
,
"INVALID_REFERERENCE"
)
if
access_token_document
.
getReference
()
!=
reference
:
# use hmac.compare_digest and not string comparison to avoid timing attacks
if
not
hmac
.
compare_digest
(
access_token_document
.
getReference
(),
reference
):
return
None
agent_document
=
access_token_document
.
getAgentValue
()
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment