mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore!: ensure consistent secret token generation and hashing (#20388)
This PR uses the same sha256 hashing technique as we use for APIKeys. So now all randomly generated secrets will be hashed with sha256 for consistency. This is a breaking change for the oauth tokens. Since oauth is only allowed for dev builds and experimental, this is ok.
This commit is contained in:
@@ -620,7 +620,7 @@ func TestOAuth2ProviderTokenRefresh(t *testing.T) {
|
||||
CreatedAt: dbtime.Now(),
|
||||
ExpiresAt: expires,
|
||||
HashPrefix: []byte(token.Prefix),
|
||||
RefreshHash: []byte(token.Hashed),
|
||||
RefreshHash: token.Hashed,
|
||||
AppSecretID: secret.ID,
|
||||
APIKeyID: newKey.ID,
|
||||
UserID: user.ID,
|
||||
|
||||
Reference in New Issue
Block a user