Skip to content

Commit 8ce431b

Browse files
committed
Checking sec-websocket-accept against expected instead of actual. Issue #295
Signed-off-by: James Sutton <james.sutton@uk.ibm.com>
1 parent 2eba11a commit 8ce431b

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

  • org.eclipse.paho.client.mqttv3/src/main/java/org/eclipse/paho/client/mqttv3/internal/websocket

org.eclipse.paho.client.mqttv3/src/main/java/org/eclipse/paho/client/mqttv3/internal/websocket/WebSocketHandshake.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -197,7 +197,7 @@ private void verifyWebSocketKey(String key, String accept) throws NoSuchAlgorith
197197
// then we check that the response is the same.
198198
byte[] sha1Bytes = sha1(key + ACCEPT_SALT);
199199
String encodedSha1Bytes = Base64.encodeBytes(sha1Bytes).trim();
200-
if(!encodedSha1Bytes.equals(encodedSha1Bytes)){
200+
if(!encodedSha1Bytes.equals(accept.trim())){
201201
throw new HandshakeFailedException();
202202
}
203203
}

0 commit comments

Comments
 (0)