mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore!: ensure consistent secret token generation and hashing (#20388)
This PR uses the same sha256 hashing technique as we use for APIKeys. So now all randomly generated secrets will be hashed with sha256 for consistency. This is a breaking change for the oauth tokens. Since oauth is only allowed for dev builds and experimental, this is ok.
This commit is contained in:
@@ -3956,7 +3956,7 @@ type OAuth2ProviderApp struct {
|
||||
// RFC 7591: Version of the client software
|
||||
SoftwareVersion sql.NullString `db:"software_version" json:"software_version"`
|
||||
// RFC 7592: Hashed registration access token for client management
|
||||
RegistrationAccessToken sql.NullString `db:"registration_access_token" json:"registration_access_token"`
|
||||
RegistrationAccessToken []byte `db:"registration_access_token" json:"registration_access_token"`
|
||||
// RFC 7592: URI for client configuration endpoint
|
||||
RegistrationClientUri sql.NullString `db:"registration_client_uri" json:"registration_client_uri"`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user