From 476e57b04646416e24e24c56133c9fadf9e52b95 Mon Sep 17 00:00:00 2001 From: Alexandre Alapetite Date: Mon, 15 Dec 2025 22:06:05 +0100 Subject: Reverse hash and nonce (#8320) Safer password evaluation --- p/scripts/extra.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'p/scripts') diff --git a/p/scripts/extra.js b/p/scripts/extra.js index 9eeefabfb..6f896f959 100644 --- a/p/scripts/extra.js +++ b/p/scripts/extra.js @@ -75,7 +75,7 @@ function init_crypto_forms() { try { const strong = window.Uint32Array && window.crypto && (typeof window.crypto.getRandomValues === 'function'); const s = bcrypt.hashSync(crypto_form.querySelector('.passwordPlain').value, json.salt1); - const c = bcrypt.hashSync(json.nonce + s, strong ? bcrypt.genSaltSync(4) : poormanSalt()); + const c = bcrypt.hashSync(s + json.nonce, strong ? bcrypt.genSaltSync(4) : poormanSalt()); challenge.value = c; if (!s || !c) { openNotification('Crypto error!', 'bad'); -- cgit v1.2.3