HomePhabricator
Diffusion Comm 863cdaaa62b7

[services-lib] Use constant-time-eq for token verification

Description

[services-lib] Use constant-time-eq for token verification

Summary:
verify_access_token in Identity Service does this so probably we should do it here too.

Depends on D9241

Test Plan: I did some simple comparisons and it seems to work fine.

Reviewers: varun, michal, jon

Reviewed By: varun, michal

Subscribers: ashoat, tomek

Differential Revision: https://phab.comm.dev/D9242

Details

Provenance
bartekAuthored on Sep 19 2023, 3:56 AM
Reviewer
varun
Differential Revision
D9242: [services-lib] Use constant-time-eq for token verification
Parents
rCOMMe5f09476d959: [services-lib] Add enum for authorization tokens
Branches
Unknown
Tags
Unknown