// Constant-time comparison of a presented secret with the configured one (round 4, X28: `===` on secrets leaks the // matching prefix length through timing). No dependencies, so `node --test relay/test` covers it. import { timingSafeEqual } from 'node:crypto'; export function sameSecret(given, expected) { if (typeof given !== 'string' || typeof expected !== 'string' || !expected) return false; const a = Buffer.from(given, 'utf8'); const b = Buffer.from(expected, 'utf8'); if (a.length !== b.length) return false; // lengths are not secret: every token and key here has a fixed length return timingSafeEqual(a, b); }