Changelog, constant time compare

This commit is contained in:
binwiederhier
2026-06-22 21:21:48 -04:00
parent 3bfb9f334b
commit 74240328dc
2 changed files with 3 additions and 1 deletions
+1
View File
@@ -1967,6 +1967,7 @@ since I do have to reset emails on a regular basis.
* Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (`crypto/rand`) instead of a clock-seeded PRNG
* `X-Email: yes` (also `true`/`1`) now sends to your primary verified email regardless of the `smtp-sender-verify` setting (previously it was rejected unless verification was enabled); it requires being logged in with a verified address
* Grant users full access to their own sync topic (`st_...`) so cross-device subscription sync works under `auth-default-access: deny-all` ([#733](https://github.com/binwiederhier/ntfy/issues/733), [#1795](https://github.com/binwiederhier/ntfy/pull/1795), thanks to [@lmorchard](https://github.com/lmorchard) for the contribution)
### ntfy Android v1.25.x (UNRELEASED)
+2 -1
View File
@@ -2,6 +2,7 @@
package user
import (
"crypto/subtle"
"database/sql"
"encoding/json"
"errors"
@@ -680,7 +681,7 @@ func (a *Manager) Authorize(user *User, topic string, perm Permission) error {
// to sync subscriptions/settings across devices. Without this, an
// auth-default-access of "deny-all" locks the user out of their own sync
// topic (no ACL entry is created for it at user creation). See #733.
if user != nil && user.SyncTopic != "" && topic == user.SyncTopic {
if user != nil && user.SyncTopic != "" && subtle.ConstantTimeCompare([]byte(topic), []byte(user.SyncTopic)) == 1 {
return nil
}
username := Everyone