ConsumeAuthId removed the entry before checking the address or the account, so anyone landing on a live id burned it. Its owner then arrived to "unable to find auth id" and had to start the login over -- from a packet they had no part in. Look, then take. A mismatch leaves the id alone and yields no entry; only a presenter that matches both the address and the account spends it. The reason given for taking it unconditionally -- that a guessed id must not be reusable to probe for its owner -- does not survive checking the order. The address is compared first, so a guesser from anywhere else is rejected before a username is ever looked at, and one from the victim's own address is already on their network. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Application | ||
| BuildTool | ||
| Logger | ||
| Server | ||
| Server.Tests | ||
| UOContent | ||
| UOContent.Tests | ||