Repository navigation
Don't send the account password hash in GetUser replies - #174
Merged
Merged
Conversation
HandleGetUser put the stored bcrypt hash in field 106. A client that sends the field back unchanged in SetUser or UpdateUser has the hash itself hashed and stored, so saving an account without touching its password locks it out. It also hands the hashes to anyone with the Open User privilege. Reply with "x" when the account has a password and omit the field otherwise, as Account.Read already does for the user list.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HandleGetUserputs the stored bcrypt hash in field 106. Two problems follow:This replies with
xwhen the account has a password and leaves the field out otherwise. That matches whatAccount.Readalready sends in the user list (348), and what the original server sends. Clients that send00for an untouched password, the keep-password caseHandleSetUserhandles, behave as before.Tests:
TestHandleGetUsernow covers an account with a password and one without.