From 84a8646b8ec1dc873568b12b1e9705692df74ea7 Mon Sep 17 00:00:00 2001 From: Lewis Crichton Date: Fri, 7 Apr 2023 00:41:01 +0100 Subject: [PATCH] swap user id and secret to stop jumpscaring users --- main.go | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/main.go b/main.go index c867227..873d35f 100644 --- a/main.go +++ b/main.go @@ -57,9 +57,9 @@ func requireAuth(c *fiber.Ctx) error { }) } - // decode base64 token and split by : - // token[0] = username - // token[1] = password + // decode base64 token and split by: + // token[0] = secret + // token[1] = user id token, err := base64.StdEncoding.DecodeString(authToken) if err != nil { @@ -77,8 +77,8 @@ func requireAuth(c *fiber.Ctx) error { }) } - userId := tokenSplit[0] - secret := tokenSplit[1] + secret := tokenSplit[0] + userId := tokenSplit[1] storedSecret, err := rdb.Get(c.Context(), "secrets:"+hash(os.Getenv("PEPPER_SECRETS")+userId)).Result()