fix: use constant-time comparison for tokens and consolidate admin auth #5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/constant-time-auth"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replace
==/!=withsecrets.compare_digestfor admin token checks andtoken_maplookups.Remove duplicated
verify_adminfrom admin router in favour of the sharedrequire_admindependency inauth.py.