mirror of https://github.com/ospab/ostp.git
check_token() and handle_login() compared bearer tokens, session tokens, and the password hash with plain ==, which short-circuits on the first differing byte - a textbook remote timing side-channel against exactly the long-lived secrets these gates exist to protect. Added subtle (already in the dependency tree transitively via chacha20poly1305) as a direct dependency and route every secret comparison through a small secure_eq() wrapper over ConstantTimeEq. Username comparison in handle_login is left as-is: it isn't treated as a secret in this threat model (one fixed admin username), matching standard practice of only constant-timing the password/token side of an auth check. Added tests for secure_eq() itself (equal, different, different-length, empty) alongside the existing check_token coverage. |
||
|---|---|---|
| .. | ||
| src | ||
| Cargo.toml | ||