Skip to content

fix: use time-constant comparison for security tokens#12191

Closed
TatuLund wants to merge 3 commits intomasterfrom
csrf-fix2-1
Closed

fix: use time-constant comparison for security tokens#12191
TatuLund wants to merge 3 commits intomasterfrom
csrf-fix2-1

Conversation

@TatuLund
Copy link
Contributor

@TatuLund TatuLund commented Jan 28, 2021

This is the same as #12190, but also applied for the upload security key
and the push id since both of those are also used to protect against
cross-site attacks. In addition, documentation for the push id is
clarified to point out its role.

Backport of #12189


This change is Reviewable

This is the same as #12190, but also applied for the upload security key
and the push id since both of those are also used to protect against
cross-site attacks. In addition, documentation for the push id is
clarified to point out its role.
@TatuLund TatuLund changed the title Update FileUploadHandler.java fix: use time-constant comparison for security tokens Jan 28, 2021
@TatuLund TatuLund closed this Jan 28, 2021
@Ansku Ansku deleted the csrf-fix2-1 branch January 28, 2021 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant