fix: safe registration_open default + TOTP constant-time comparison (T-199, T-201)

This commit is contained in:
jevb
2026-03-31 16:27:21 +02:00
parent 3faac8742a
commit ce64be4e14
2 changed files with 3 additions and 2 deletions
+1 -1
View File
@@ -793,7 +793,7 @@ func isRequire2FAEnabled(database *db.DB) (bool, error) {
}
func isRegistrationOpen(database *db.DB) (bool, error) {
return getBooleanSetting(database, "registration_open", false)
return getBooleanSetting(database, "registration_open", true)
}
func getBooleanSetting(database *db.DB, key string, defaultValue bool) (bool, error) {
+2 -1
View File
@@ -4,6 +4,7 @@ import (
"crypto/hmac"
"crypto/rand"
"crypto/sha1"
"crypto/subtle"
"encoding/base32"
"encoding/binary"
"encoding/hex"
@@ -204,7 +205,7 @@ func VerifyTOTPCode(secret, code string, at time.Time) bool {
}
for _, offset := range []int{-1, 0, 1} {
candidate, err := GenerateTOTPCode(secret, at.Add(time.Duration(offset)*totpPeriod))
if err == nil && candidate == code {
if err == nil && subtle.ConstantTimeCompare([]byte(candidate), []byte(code)) == 1 {
return true
}
}