mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 02:21:17 +02:00
Backport #29205 (including #29172) Use a clearly defined "signing secret" for token signing.
This commit is contained in:
1 parent
7ea2ffaf16
commit
511298e452
13 files changed
+130
-70
No files matched your search
@@ -129,7 +129,7 @@ func CreateTimeLimitCode(data string, minutes int, startInf any) string {
|
||||
|
||||
// create sha1 encode string
|
||||
sh := sha1.New()
|
||||
_, _ = sh.Write([]byte(fmt.Sprintf("%s%s%s%s%d", data, setting.SecretKey, startStr, endStr, minutes)))
|
||||
_, _ = sh.Write([]byte(fmt.Sprintf("%s%s%s%s%d", data, hex.EncodeToString(setting.GetGeneralTokenSigningSecret()), startStr, endStr, minutes)))
|
||||
encoded := hex.EncodeToString(sh.Sum(nil))
|
||||
|
||||
code := fmt.Sprintf("%s%06d%s", startStr, minutes, encoded)
|
||||
|
||||
Reference in new issue
Block a user