mirror of
https://github.com/PretendoNetwork/account.git
synced 2026-09-30 14:18:22 -05:00
Changed decryptToken to always use the account server key
This commit is contained in:
@@ -104,7 +104,7 @@ export async function getPNIDByBearerAuth(token: string): Promise<HydratedPNIDDo
|
||||
verifyConnected();
|
||||
|
||||
try {
|
||||
const decryptedToken: Buffer = await decryptToken(config.aes_key, Buffer.from(token, 'hex'));
|
||||
const decryptedToken: Buffer = await decryptToken(Buffer.from(token, 'hex'));
|
||||
const unpackedToken: Token = unpackToken(decryptedToken);
|
||||
|
||||
const pnid: HydratedPNIDDocument | null = await getPNIDByPID(unpackedToken.pid);
|
||||
|
||||
@@ -2,7 +2,6 @@ import express from 'express';
|
||||
import bcrypt from 'bcrypt';
|
||||
import { PNID } from '@/models/pnid';
|
||||
import { decryptToken, unpackToken, nintendoPasswordHash } from '@/util';
|
||||
import { config } from '@/config-manager';
|
||||
import { Token } from '@/types/common/token';
|
||||
import { HydratedPNIDDocument } from '@/types/mongoose/pnid';
|
||||
|
||||
@@ -29,7 +28,7 @@ router.post('/', async (request: express.Request, response: express.Response) =>
|
||||
|
||||
let unpackedToken: Token;
|
||||
try {
|
||||
const decryptedToken: Buffer = await decryptToken(config.aes_key, Buffer.from(token, 'base64'));
|
||||
const decryptedToken: Buffer = await decryptToken(Buffer.from(token, 'base64'));
|
||||
unpackedToken = unpackToken(decryptedToken);
|
||||
} catch (error) {
|
||||
console.log(error);
|
||||
|
||||
@@ -78,9 +78,9 @@ export function generateToken(key: string, options: TokenOptions): Buffer | null
|
||||
]);
|
||||
}
|
||||
|
||||
export function decryptToken(key: string, token: Buffer): Buffer {
|
||||
export function decryptToken(token: Buffer): Buffer {
|
||||
const iv: Buffer = Buffer.alloc(16);
|
||||
const decipher: crypto.Decipher = crypto.createDecipheriv('aes-256-cbc', Buffer.from(key, 'hex'), iv);
|
||||
const decipher: crypto.Decipher = crypto.createDecipheriv('aes-256-cbc', Buffer.from(config.aes_key, 'hex'), iv);
|
||||
|
||||
return Buffer.concat([
|
||||
decipher.update(token),
|
||||
|
||||
Reference in New Issue
Block a user