silverwind / droppy

**ARCHIVED** Self-hosted file storage
BSD 2-Clause "Simplified" License
1.62k stars 195 forks source link

Fix a timing attack issue with CSRF token validation. #393

Open katanacrimson opened 4 years ago

katanacrimson commented 4 years ago

Replacing the lazy string comparison with a constant-time string comparison provided by nodejs's internal crypto module.