Jump to conversation
Unresolved conversations (1)
@phosphore phosphore Mar 10, 2020
I would prefer a constant-time comparison algorithm here to prevent timing attacks (e.g. crypto.timingSafeEqual https://nodejs.org/api/crypto.html#crypto_crypto_timingsafeequal_a_b)
...on-node/token/electron-token-validator.ts
Resolved conversations (9)
@paul-marechal paul-marechal Feb 25, 2020
Upgrade done on HTTP-server level instead of ws @akosyakov
.../node/messaging/messaging-contribution.ts
akosyakov
@akosyakov akosyakov Feb 24, 2020
leftover? left and right sides already of `ReconnectingWebSocket` type
Outdated
...owser/messaging/ws-connection-provider.ts
paul-marechal
@akosyakov akosyakov Feb 24, 2020
Is it necessary? Not against, just wonder what for.
...nager/src/generator/frontend-generator.ts
akosyakov paul-marechal
@akosyakov akosyakov Feb 24, 2020
Why named? `@inject(ElectronSecurityToken)`? But I don't get why we cannot use process.env here?
Outdated
...on-node/token/electron-token-validator.ts
paul-marechal akosyakov
@akosyakov akosyakov Feb 24, 2020
why so complicated? Could we just use `toConstant`? Or just use `process.env[ElectronSecurityToken]` directly? I would better wait till someone asks for something like that.
Outdated
...de/token/electron-token-backend-module.ts
paul-marechal akosyakov
@akosyakov akosyakov Feb 24, 2020
Given that all web socket connections are created by `MessagingContribution` it would work. If a 3rd party extension adds another way it won't. Probably it is alright if we communicate it.
Outdated
...en/electron-token-backend-contribution.ts
paul-marechal
@akosyakov akosyakov Feb 24, 2020
Could you elaborate what kind of refactoring?
Outdated
...en/electron-token-backend-contribution.ts
paul-marechal
@akosyakov akosyakov Feb 24, 2020
Why don't inline `ElectronTokenValidator` in `ElectronTokenBackendContribution`? One `BackendApplicationContribution` will be enough.
...en/electron-token-backend-contribution.ts
akosyakov paul-marechal
@akosyakov akosyakov Feb 24, 2020
It should go to own file.
Outdated
...en/electron-token-backend-contribution.ts
paul-marechal