fix: use constant-time secret comparisons

Co-Authored-By: OpenAI <noreply@openai.com>
This commit is contained in:
Stavros
2026-09-06 19:56:58 +03:00
co-authored by OpenAI
parent b61fc6b54e
commit 0cf64e8598
2 changed files with 7 additions and 2 deletions
+5 -1
View File
@@ -1,6 +1,8 @@
package controller
import (
"crypto/sha256"
"crypto/subtle"
"encoding/json"
"errors"
"fmt"
@@ -545,7 +547,9 @@ func (controller *OIDCController) Token(c *gin.Context) {
return
}
if client.ClientSecret != creds.ClientSecret {
clientSecretHash := sha256.Sum256([]byte(client.ClientSecret))
providedSecretHash := sha256.Sum256([]byte(creds.ClientSecret))
if subtle.ConstantTimeCompare(clientSecretHash[:], providedSecretHash[:]) != 1 {
controller.log.App.Warn().Str("clientId", creds.ClientID).Msg("Invalid client secret")
c.JSON(400, gin.H{
"error": "invalid_client",
+2 -1
View File
@@ -6,6 +6,7 @@ import (
"crypto/rand"
"crypto/rsa"
"crypto/sha256"
"crypto/subtle"
"crypto/x509"
"encoding/base64"
"encoding/json"
@@ -882,7 +883,7 @@ func (service *OIDCService) ValidatePKCE(codeChallenge string, codeVerifier stri
if codeChallenge == "" {
return true
}
return codeChallenge == service.hashAndEncodePKCE(codeVerifier)
return subtle.ConstantTimeCompare([]byte(codeChallenge), []byte(service.hashAndEncodePKCE(codeVerifier))) == 1
}
func (service *OIDCService) hashAndEncodePKCE(codeVerifier string) string {