Slide 4
Slide 4 text
~/awesome/project master=
∴ git show f19c712702c9fced2461eabd2443c1009baffebb
commit f19c712702c9fced2461eabd2443c1009baffebb
Author: Rubens Stulzer
Date: Wed Apr 13 17:27:40 2016 -0300
Improves security when comparing password
diff --git a/app/models/session.rb b/app/models/session.rb
index 7041c8a..685c247 100644
--- a/app/models/session.rb
+++ b/app/models/session.rb
@@ -89,7 +89,7 @@ private
def password_match?
- salted_user_password == salted_db_password
+ ActiveSupport::SecurityUtils.secure_compare(salted_user_password,
salted_db_password)
end