tka: use constant-time comparison of disablement secret (#19064)
The actual secret is passed through argon2 first, so a timing attack is not feasible remotely, and pretty unlikely locally. Still, clean this up. Fixes #19063 Signed-off-by: Andrew Lytvynov <awly@tailscale.com>main
parent
ffa7df2789
commit
34477cf3e7
Loading…
Reference in new issue