use hmac_hash

This commit is contained in:
Cloud Wu
2015-04-16 10:41:23 +08:00
parent 57c0ad694c
commit 7b783076e5

View File

@@ -178,7 +178,7 @@ function server.start(conf)
end
local text = string.format("%s:%s", username, index)
local v = crypt.hmac64(crypt.hashkey(text), u.secret)
local v = crypt.hmac_hash(u.secret, text) -- equivalent to crypt.hmac64(crypt.hashkey(text), u.secret)
if v ~= hmac then
return "401 Unauthorized"
end