auth_internal: use type-strict comparison when checking OTP code
This commit is contained in:
parent
89d53a7f49
commit
0757ad0406
|
@ -52,7 +52,7 @@ class Auth_Internal extends Plugin implements IAuthModule {
|
||||||
$totp_legacy = new \OTPHP\TOTP($secret_legacy);
|
$totp_legacy = new \OTPHP\TOTP($secret_legacy);
|
||||||
$otp_check_legacy = $totp_legacy->now();
|
$otp_check_legacy = $totp_legacy->now();
|
||||||
|
|
||||||
if ($otp != $otp_check && $otp != $otp_check_legacy) {
|
if ($otp !== $otp_check && $otp !== $otp_check_legacy) {
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
|
Loading…
Reference in New Issue