diff --git a/lidar_pipeline/webapp.py b/lidar_pipeline/webapp.py index c84e05d..e4cd428 100644 --- a/lidar_pipeline/webapp.py +++ b/lidar_pipeline/webapp.py @@ -348,8 +348,11 @@ def _require_token(x_lidar_token: str = Header(None)): Utilisé par la machine de traitement pour n'accepter que la webapp légère autorisée (qui présente LIDAR_REMOTE_TOKEN) sur le réseau local. """ - if API_TOKEN and x_lidar_token != API_TOKEN: - raise HTTPException(401, "token d'API manquant ou invalide") + if API_TOKEN: + import hmac + presented = x_lidar_token or "" + if not hmac.compare_digest(presented, API_TOKEN): + raise HTTPException(401, "token d'API manquant ou invalide") def _ip_in_regen_cidr(ip):