Skip to content

Avoid user-not-found timing attacks w/ dummy hash#15

Merged
cognifloyd merged 2 commits into
masterfrom
dummy-pw-hash
Sep 13, 2025
Merged

Avoid user-not-found timing attacks w/ dummy hash#15
cognifloyd merged 2 commits into
masterfrom
dummy-pw-hash

Conversation

@cognifloyd

Copy link
Copy Markdown
Member

Now that we have dropped passlib, this reimplements passlib's dummy verify feature to maintain the same security posture.

See: https://github.com/StackStorm/st2-auth-backend-flat-file/pull/14/files/f1b09ea9a12f49c14b6572c15410506e57544672#r2341493677

Now that we have dropped passlib, this reimplements passlib's dummy
verify feature to maintain the same security posture.
@cognifloyd cognifloyd requested a review from nzlosh September 13, 2025 13:53
@cognifloyd cognifloyd self-assigned this Sep 13, 2025
@cognifloyd cognifloyd mentioned this pull request Sep 13, 2025
@cognifloyd cognifloyd merged commit 93a8115 into master Sep 13, 2025
8 checks passed
@cognifloyd cognifloyd deleted the dummy-pw-hash branch September 13, 2025 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants