From fd5ad283f73d20273f7074485b932ab3cb7dcdfd Mon Sep 17 00:00:00 2001 From: Antoine Jacquin Date: Fri, 18 Sep 2026 21:16:23 +0200 Subject: [PATCH] =?UTF-8?q?Comparer=20le=20token=20d'API=20=C3=A0=20temps?= =?UTF-8?q?=20constant?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- lidar_pipeline/webapp.py | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/lidar_pipeline/webapp.py b/lidar_pipeline/webapp.py index c84e05d..e4cd428 100644 --- a/lidar_pipeline/webapp.py +++ b/lidar_pipeline/webapp.py @@ -348,8 +348,11 @@ def _require_token(x_lidar_token: str = Header(None)): Utilisé par la machine de traitement pour n'accepter que la webapp légère autorisée (qui présente LIDAR_REMOTE_TOKEN) sur le réseau local. """ - if API_TOKEN and x_lidar_token != API_TOKEN: - raise HTTPException(401, "token d'API manquant ou invalide") + if API_TOKEN: + import hmac + presented = x_lidar_token or "" + if not hmac.compare_digest(presented, API_TOKEN): + raise HTTPException(401, "token d'API manquant ou invalide") def _ip_in_regen_cidr(ip):