* @brief Constant-time check of a client-provided token against the configured one. */
| 572 | * @brief Constant-time check of a client-provided token against the configured one. |
| 573 | */ |
| 574 | bool API::Server::verifyToken(const QByteArray& provided) const |
| 575 | { |
| 576 | return !m_authToken.isEmpty() && constantTimeEquals(provided, m_authToken.toUtf8()); |
| 577 | } |
| 578 | |
| 579 | /** |
| 580 | * @brief Gates API-originated device writes behind a one-time user consent prompt. Headless |
no test coverage detected