mirror of
https://github.com/fatedier/frp.git
synced 2026-05-15 16:15:49 -06:00
[PR #5240] [CLOSED] fix: use ConstantTimeEqString for visitor auth key comparison #5198
Labels
No labels
In Progress
WIP
WaitingForInfo
bug
doc
duplicate
easy
enhancement
future
help wanted
invalid
lifecycle/stale
need-issue-template
need-usage-help
no plan
proposal
pull-request
question
todo
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/frp#5198
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/fatedier/frp/pull/5240
Author: @karesansui-u
Created: 3/16/2026
Status: ❌ Closed
Base:
dev← Head:fix/visitor-auth-constant-time-compare📝 Commits (1)
0d0d59cfix: use ConstantTimeEqString for visitor auth key comparison📊 Changes
1 file changed (+1 additions, -1 deletions)
View changed files
📝
server/visitor/visitor.go(+1 -1)📄 Description
server/visitor/visitor.gocompares the visitor auth key using!=,while
pkg/auth/token.goandpkg/nathole/controller.gouseutil.ConstantTimeEqString()for the sameGetAuthKeycomparison.This aligns the visitor auth path with the existing pattern.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.