Sha256: f6318bc79f75491ca2ccdc79f96191def9b793ca3c48e7bfabe623e76e07c07c

Contents?: true

Size: 1.25 KB

Versions: 10

Compression:

Stored size: 1.25 KB

Contents

# frozen_string_literal: true

module ActiveSupport
  module SecurityUtils
    # Constant time string comparison, for fixed length strings.
    #
    # The values compared should be of fixed length, such as strings
    # that have already been processed by HMAC. Raises in case of length mismatch.

    if defined?(OpenSSL.fixed_length_secure_compare)
      def fixed_length_secure_compare(a, b)
        OpenSSL.fixed_length_secure_compare(a, b)
      end
    else
      def fixed_length_secure_compare(a, b)
        raise ArgumentError, "string length mismatch." unless a.bytesize == b.bytesize

        l = a.unpack "C#{a.bytesize}"

        res = 0
        b.each_byte { |byte| res |= byte ^ l.shift }
        res == 0
      end
    end
    module_function :fixed_length_secure_compare

    # Secure string comparison for strings of variable length.
    #
    # While a timing attack would not be able to discern the content of
    # a secret compared via secure_compare, it is possible to determine
    # the secret length. This should be considered when using secure_compare
    # to compare weak, short secrets to user input.
    def secure_compare(a, b)
      a.length == b.length && fixed_length_secure_compare(a, b)
    end
    module_function :secure_compare
  end
end

Version data entries

10 entries across 10 versions & 2 rubygems

Version Path
tdiary-5.1.6 vendor/bundle/ruby/2.7.0/gems/activesupport-6.1.3.1/lib/active_support/security_utils.rb
activesupport-6.1.3.2 lib/active_support/security_utils.rb
activesupport-6.1.3.1 lib/active_support/security_utils.rb
activesupport-6.1.3 lib/active_support/security_utils.rb
activesupport-6.1.2.1 lib/active_support/security_utils.rb
activesupport-6.1.2 lib/active_support/security_utils.rb
activesupport-6.1.1 lib/active_support/security_utils.rb
activesupport-6.1.0 lib/active_support/security_utils.rb
activesupport-6.1.0.rc2 lib/active_support/security_utils.rb
activesupport-6.1.0.rc1 lib/active_support/security_utils.rb