Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Username comparison in freeradius totpcgi-handler.pl #40

Open
Selelvian opened this issue Mar 23, 2017 · 0 comments
Open

Username comparison in freeradius totpcgi-handler.pl #40

Selelvian opened this issue Mar 23, 2017 · 0 comments

Comments

@Selelvian
Copy link

On line 174, there is:
($mesg->entry(0)->get_value($$config{'userAttribute'}) == $RAD_REQUEST{'User-Name'})

I think this should be
($mesg->entry(0)->get_value($$config{'userAttribute'}) eq $RAD_REQUEST{'User-Name'})

Because otherwise it is doing a conversion to a numeric type, and comparing that, which for most usernames will not make sense.

I only discovered this because I had a username of nancy, which was converting to NaN, for which equality breaks, and would not let them log in.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant