aboutsummaryrefslogtreecommitdiff
path: root/llm/codeinterpreter
diff options
context:
space:
mode:
authorXe Iaso <me@xeiaso.net>2025-01-26 16:03:35 -0500
committerXe Iaso <me@xeiaso.net>2025-01-26 16:03:38 -0500
commite09d0226a628f04b1d80fd83bee777894a45cd02 (patch)
treef29ff26bc09a5a59b1535e1695a4bde004fcabe5 /llm/codeinterpreter
parent7bd7b209f4f1b897de85ec8973458dc8be606a8b (diff)
downloadx-e09d0226a628f04b1d80fd83bee777894a45cd02.tar.xz
x-e09d0226a628f04b1d80fd83bee777894a45cd02.zip
cmd/anubis: forbid bypassing auth by faking the challenge difficulty
This fixes a trivial auth bypass where a user requests a challenge, formulates any nonce they want (such as 42069), and then passes the challenge with difficulty zero. This was fixed by not using the difficulity the client specified and instead using the fixed difficulty at the server level. The difficulty has also been encoded into the challenge in 7bd7b209f4f1. Thanks to Coral Pink for finding this and reporting it over email. Signed-off-by: Xe Iaso <me@xeiaso.net>
Diffstat (limited to 'llm/codeinterpreter')
0 files changed, 0 insertions, 0 deletions