mirror of
https://github.com/tailscale/tailscale.git
synced 2024-11-29 04:55:31 +00:00
drive: use secret token to authenticate access to file server on localhost
This prevents Mark-of-the-Web bypass attacks in case someone visits the localhost WebDAV server directly. Fixes tailscale/corp#19592 Signed-off-by: Percy Wegmann <percy@tailscale.com>
This commit is contained in:
parent
07e783c7be
commit
745fb31bd4
@ -138,7 +138,7 @@ func (s *FileServer) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
|||||||
|
|
||||||
token := parts[0]
|
token := parts[0]
|
||||||
a, b := []byte(token), []byte(s.secretToken)
|
a, b := []byte(token), []byte(s.secretToken)
|
||||||
if len(a) != len(b) || subtle.ConstantTimeCompare(a, b) != 1 {
|
if subtle.ConstantTimeCompare(a, b) != 1 {
|
||||||
w.WriteHeader(http.StatusForbidden)
|
w.WriteHeader(http.StatusForbidden)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user