Use SecureRandom.uuid to generate Javabuilder session ID #45253
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uses SecureRandom.uuid instead of SecureRandom.hex(18) to generate the Javabuilder session ID to guarantee uniqueness (the previous method was also basically unique, but since we are now using the Javabuilder session ID to lookup project data on every invocation, we could potentially run into collisions).
Links
Testing story
Tested on localhost against prod and local Javabuilder. Verified that the session ID is generated correctly and used to lookup objects in S3 successfully.
Deployment strategy
Follow-up work
Privacy
Security
Caching
PR Checklist: