Permalink
Please sign in to comment.
Browse files
Fixed timing attack in signature verification in the cookie session s…
…tore by replacing = with secure-compare. Adapted from http://codahale.com/a-lesson-in-timing-attacks/ Not using Java's MessageDigest.isEqual since that had a vulnerability until recently
- Loading branch information...
Showing
with
11 additions
and 2 deletions.
13
ring-core/src/ring/middleware/session/cookie.clj
0 comments on commit
0e68817