From 6ddba8e005d99dd677cdc91f94d25f941160444e Mon Sep 17 00:00:00 2001 From: Apex Liu Date: Wed, 17 Aug 2022 02:02:56 +0800 Subject: [PATCH] secure hot-fix --- server/www/teleport/webroot/app/controller/auth.py | 1 + 1 file changed, 1 insertion(+) diff --git a/server/www/teleport/webroot/app/controller/auth.py b/server/www/teleport/webroot/app/controller/auth.py index 08f65cf..cec9fdd 100644 --- a/server/www/teleport/webroot/app/controller/auth.py +++ b/server/www/teleport/webroot/app/controller/auth.py @@ -109,6 +109,7 @@ class DoLoginHandler(TPBaseJsonHandler): return self.write_json(TPE_CAPTCHA_EXPIRED, '验证码已失效') if code.lower() != captcha.lower(): return self.write_json(TPE_CAPTCHA_MISMATCH, '验证码错误') + if login_type in [TP_LOGIN_AUTH_USERNAME_OATH, TP_LOGIN_AUTH_USERNAME_PASSWORD_OATH]: if oath is None or len(oath) == 0: return self.write_json(TPE_PARAM, '未提供身份验证器动态验证码')