11 lines
634 B
JavaScript
11 lines
634 B
JavaScript
// Constant-time comparison of a presented secret with the configured one (round 4, X28: `===` on secrets leaks the
|
|
// matching prefix length through timing). No dependencies, so `node --test relay/test` covers it.
|
|
import { timingSafeEqual } from 'node:crypto';
|
|
|
|
export function sameSecret(given, expected) {
|
|
if (typeof given !== 'string' || typeof expected !== 'string' || !expected) return false;
|
|
const a = Buffer.from(given, 'utf8');
|
|
const b = Buffer.from(expected, 'utf8');
|
|
if (a.length !== b.length) return false; // lengths are not secret: every token and key here has a fixed length
|
|
return timingSafeEqual(a, b);
|
|
}
|