Create SafeComparisonOfSensitiveInfo.py

This commit is contained in:
Ahmed Farid
2022-08-05 12:46:46 +01:00
committed by GitHub
parent 5eef14a0a9
commit dd61383469

View File

@@ -0,0 +1,17 @@
#!/usr/bin/env python
# -*- coding: UTF-8 -*-
"""
@Desc preventing timing attack sensitive info
"""
import hmac
from flask import Flask
from flask import request
@app.route('/good')
def check_credentials(password):
return hmac.compare_digest(password, "token")
if __name__ == '__main__':
app.debug = True
app.run()