🛡️ Sentinel: Fix timing side-channel vulnerability in API key verification - #452
🛡️ Sentinel: Fix timing side-channel vulnerability in API key verification#452ightevenmckane187 wants to merge 1 commit into
Conversation
Harden `verify_api_key` in `auth.py` by replacing standard string inequality comparison with `hmac.compare_digest` to prevent timing side-channel attacks during authentication token verification. Add test coverage in `tests/test_share_system.py` to assert secure rejection of invalid API keys across key formats and lengths.
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
🛡️ Sentinel Security Improvement
!=) inverify_api_keyinauth.pywas vulnerable to timing side-channel attacks where an attacker could measure execution duration differences to deduce valid API key/token characters.hmac.compare_digest(provided_key, CYPHER_API_KEY)to ensure constant-time comparison.test_api_create_share_link_timing_safetyintests/test_share_system.pyasserting proper 401/403 responses across various key formats and lengths. All Python and TypeScript unit test suites pass cleanly.PR created automatically by Jules for task 10152525788508241593 started by @ightevenmckane187