Fix non-ASCII token authentication crashes
This commit is contained in:
+4
-2
@@ -199,7 +199,9 @@ def create_app(data_dir=None, provider_transport=None):
|
||||
return JSONResponse({'detail': 'Fremde Herkunft nicht erlaubt.'}, status_code=403)
|
||||
if path == '/mcp' or path.startswith('/mcp/'):
|
||||
supplied = request.headers.get('authorization', '')
|
||||
if not secrets.compare_digest(supplied, 'Bearer ' + mcp_token):
|
||||
# ASGI headers are decoded as Latin-1; compare their original bytes.
|
||||
# compare_digest(str, str) rejects non-ASCII characters.
|
||||
if not secrets.compare_digest(supplied.encode('latin-1'), ('Bearer ' + mcp_token).encode('utf-8')):
|
||||
return JSONResponse({'detail': 'MCP-Token erforderlich.'}, status_code=401)
|
||||
elif path.startswith('/api/') and path != '/api/login':
|
||||
session = request.cookies.get('atelier_session', '')
|
||||
@@ -237,7 +239,7 @@ def create_app(data_dir=None, provider_transport=None):
|
||||
attempts[ip] = recent
|
||||
if len(recent) >= 10:
|
||||
raise HTTPException(429, 'Zu viele Versuche. Bitte eine Minute warten.')
|
||||
if not secrets.compare_digest(body.token, admin_token):
|
||||
if not secrets.compare_digest(body.token.encode('utf-8'), admin_token.encode('utf-8')):
|
||||
recent.append(stamp)
|
||||
raise HTTPException(401, 'Zugangsschlüssel stimmt nicht.')
|
||||
for key in list(sessions):
|
||||
|
||||
Reference in New Issue
Block a user