Merge pull request #5719 from erasche/constant-time-sha-compare

Swap for the constant time comparison algorithm
This commit is contained in:
John Chilton
2018-03-19 09:52:52 -04:00
committed by GitHub
+1 -1
View File
@@ -31,7 +31,7 @@ def check_password(guess, hashed):
return True
else:
# Passwords were originally encoded with sha1 and hexed
if hashlib.sha1(guess).hexdigest() == hashed:
if safe_str_cmp(hashlib.sha1(guess).hexdigest(), hashed):
return True
# Password does not match
return False