From 74240328dc00c66f83c04747f58b3937936f17ee Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 22 Jun 2026 21:21:48 -0400 Subject: [PATCH] Changelog, constant time compare --- docs/releases.md | 1 + user/manager.go | 3 ++- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/releases.md b/docs/releases.md index a3c7db5c..2b97796d 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -1967,6 +1967,7 @@ since I do have to reset emails on a regular basis. * Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (`crypto/rand`) instead of a clock-seeded PRNG * `X-Email: yes` (also `true`/`1`) now sends to your primary verified email regardless of the `smtp-sender-verify` setting (previously it was rejected unless verification was enabled); it requires being logged in with a verified address +* Grant users full access to their own sync topic (`st_...`) so cross-device subscription sync works under `auth-default-access: deny-all` ([#733](https://github.com/binwiederhier/ntfy/issues/733), [#1795](https://github.com/binwiederhier/ntfy/pull/1795), thanks to [@lmorchard](https://github.com/lmorchard) for the contribution) ### ntfy Android v1.25.x (UNRELEASED) diff --git a/user/manager.go b/user/manager.go index ea99ede2..ba2c77d3 100644 --- a/user/manager.go +++ b/user/manager.go @@ -2,6 +2,7 @@ package user import ( + "crypto/subtle" "database/sql" "encoding/json" "errors" @@ -680,7 +681,7 @@ func (a *Manager) Authorize(user *User, topic string, perm Permission) error { // to sync subscriptions/settings across devices. Without this, an // auth-default-access of "deny-all" locks the user out of their own sync // topic (no ACL entry is created for it at user creation). See #733. - if user != nil && user.SyncTopic != "" && topic == user.SyncTopic { + if user != nil && user.SyncTopic != "" && subtle.ConstantTimeCompare([]byte(topic), []byte(user.SyncTopic)) == 1 { return nil } username := Everyone