Sha256: 5b0f2b29ff6679961192d528ef8c401d32ac05c51b406c3a8a29e9c76f388651

Contents?: true

Size: 989 Bytes

Versions: 48

Compression:

Stored size: 989 Bytes

Contents

# frozen_string_literal: true

require "digest/sha2"

module ActiveSupport
  module SecurityUtils
    # Constant time string comparison, for fixed length strings.
    #
    # The values compared should be of fixed length, such as strings
    # that have already been processed by HMAC. Raises in case of length mismatch.
    def fixed_length_secure_compare(a, b)
      raise ArgumentError, "string length mismatch." unless a.bytesize == b.bytesize

      l = a.unpack "C#{a.bytesize}"

      res = 0
      b.each_byte { |byte| res |= byte ^ l.shift }
      res == 0
    end
    module_function :fixed_length_secure_compare

    # Constant time string comparison, for variable length strings.
    #
    # The values are first processed by SHA256, so that we don't leak length info
    # via timing attacks.
    def secure_compare(a, b)
      fixed_length_secure_compare(::Digest::SHA256.digest(a), ::Digest::SHA256.digest(b)) && a == b
    end
    module_function :secure_compare
  end
end

Version data entries

48 entries across 46 versions & 7 rubygems

Version Path
mumukit-content-type-1.12.1 vendor/bundle/ruby/2.7.0/gems/activesupport-6.0.6.1/lib/active_support/security_utils.rb
mumukit-content-type-1.12.0 vendor/bundle/ruby/2.7.0/gems/activesupport-6.0.6.1/lib/active_support/security_utils.rb
activesupport-6.0.6.1 lib/active_support/security_utils.rb
activesupport-6.0.6 lib/active_support/security_utils.rb
activesupport-6.0.5.1 lib/active_support/security_utils.rb
activesupport-6.0.5 lib/active_support/security_utils.rb
activesupport-6.0.4.8 lib/active_support/security_utils.rb
activesupport-6.0.4.7 lib/active_support/security_utils.rb
activesupport-6.0.4.6 lib/active_support/security_utils.rb
activesupport-6.0.4.5 lib/active_support/security_utils.rb
activesupport-6.0.4.4 lib/active_support/security_utils.rb
activesupport-6.0.4.3 lib/active_support/security_utils.rb
activesupport-6.0.4.2 lib/active_support/security_utils.rb
activesupport-6.0.4.1 lib/active_support/security_utils.rb
mumukit-content-type-1.11.1 vendor/bundle/ruby/2.6.0/gems/activesupport-6.0.4/lib/active_support/security_utils.rb
activesupport-6.0.4 lib/active_support/security_utils.rb
activesupport-6.0.3.7 lib/active_support/security_utils.rb
activesupport-6.0.3.6 lib/active_support/security_utils.rb
activesupport-6.0.3.5 lib/active_support/security_utils.rb
activesupport-6.0.3.4 lib/active_support/security_utils.rb