credentials: min/max length check for credentials.

This commit is contained in:
Krishna Srinivas
2016-03-30 15:17:20 +05:30
parent 2395c42fb5
commit e318925f62
2 changed files with 6 additions and 6 deletions

View File

@@ -311,11 +311,11 @@ func (web *webAPI) SetAuth(r *http.Request, args *SetAuthArgs, reply *SetAuthRep
if !isJWTReqAuthenticated(r) {
return &json2.Error{Message: "Unauthorized request"}
}
if args.AccessKey == "" {
return &json2.Error{Message: "Empty access key not allowed"}
if !isValidAccessKey.MatchString(args.AccessKey) {
return &json2.Error{Message: "Invalid Access Key"}
}
if args.SecretKey == "" {
return &json2.Error{Message: "Empty secret key not allowed"}
if !isValidSecretKey.MatchString(args.SecretKey) {
return &json2.Error{Message: "Invalid Secret Key"}
}
cred := credential{args.AccessKey, args.SecretKey}
serverConfig.SetCredential(cred)