FEATURE: change SSO to use sha256 HMAC, which is more secure
This commit is contained in:
parent
8cbff3672f
commit
890d06ac04
|
@ -43,7 +43,7 @@ class SingleSignOn
|
||||||
end
|
end
|
||||||
|
|
||||||
def sign(payload)
|
def sign(payload)
|
||||||
Digest::SHA2.hexdigest(payload + sso_secret)
|
OpenSSL::HMAC.hexdigest("sha256", sso_secret, payload)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue