3 ms·
On disk at least. They're temporarily logged to memory in the clear: (def good-login (user pw ip) (let record (list (seconds) ip user pw) (if (and
by brett 19y ago
On disk at least. They're temporarily logged to memory in the clear:
(def good-login (user pw ip)
(let record (list (seconds) ip user pw)
(if (and user pw (aand (shash pw) (is it (hpasswords* user))))
(do (unless (user->cookie* user) (cook-user user))
(enq-limit record good-logins*)
user)
(do (enq-limit record bad-logins*)
nil))))
It might be good to pull the pw out of the record list:
...
(let record (list (seconds) ip user)
...
- pg 19y agoOk, I took it out. Turns out nothing later ever needs the pw anyway.