From e3c35e58de4ad7d1b86c1295171688d85a44d4c2 Mon Sep 17 00:00:00 2001 From: lgb <353856593@qq.com> Date: Thu, 27 Jul 2023 13:11:07 +0800 Subject: [PATCH] guard passkey check passkey length --- app/Providers/AuthServiceProvider.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Providers/AuthServiceProvider.php b/app/Providers/AuthServiceProvider.php index 4a8b3b14..3b9be3ca 100644 --- a/app/Providers/AuthServiceProvider.php +++ b/app/Providers/AuthServiceProvider.php @@ -66,7 +66,7 @@ class AuthServiceProvider extends ServiceProvider Auth::viaRequest('passkey', function (Request $request) { $passkey = $request->passkey; - if (empty($passkey)) { + if (strlen($passkey) != 32) { return null; } return User::query()->where('passkey', $passkey)->first();