tls13: Improve sanity check in get_early_data_status
Signed-off-by: Ronald Cron <ronald.cron@arm.com>
diff --git a/library/ssl_tls13_client.c b/library/ssl_tls13_client.c
index 5fbcf45..df0519a 100644
--- a/library/ssl_tls13_client.c
+++ b/library/ssl_tls13_client.c
@@ -2321,7 +2321,7 @@
int mbedtls_ssl_get_early_data_status(mbedtls_ssl_context *ssl)
{
- if ((ssl->conf->endpoint == MBEDTLS_SSL_IS_SERVER) ||
+ if ((ssl->conf->endpoint != MBEDTLS_SSL_IS_CLIENT) ||
(!mbedtls_ssl_is_handshake_over(ssl))) {
return MBEDTLS_ERR_SSL_BAD_INPUT_DATA;
}