aboutsummaryrefslogtreecommitdiff
path: root/node_modules/tsscmp/lib
diff options
context:
space:
mode:
authornanalelfe <nargiza.nosirova@mail.utoronto.ca>2016-07-21 06:40:43 +0000
committernanalelfe <nargiza.nosirova@mail.utoronto.ca>2016-07-21 06:40:43 +0000
commit39ef1b6fd37bb9b725676d3a98f13e3450798200 (patch)
treeeeec60d5b56e5c69a3ba251d98a27f4684d47066 /node_modules/tsscmp/lib
parentee8e1a13b60a6adfdc691b2a9b57289188397641 (diff)
parent76757d227f64e35a093d47facc260d9266e2bf38 (diff)
MERGED
Diffstat (limited to 'node_modules/tsscmp/lib')
-rw-r--r--node_modules/tsscmp/lib/index.js33
1 files changed, 33 insertions, 0 deletions
diff --git a/node_modules/tsscmp/lib/index.js b/node_modules/tsscmp/lib/index.js
new file mode 100644
index 0000000..7c86142
--- /dev/null
+++ b/node_modules/tsscmp/lib/index.js
@@ -0,0 +1,33 @@
+'use strict';
+
+// Implements Brad Hill's Double HMAC pattern from
+// https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verification/.
+// The approach is similar to the node's native implementation of timing safe buffer comparison that will be available on v6+.
+// https://github.com/nodejs/node/issues/3043
+// https://github.com/nodejs/node/pull/3073
+
+var crypto = require('crypto');
+
+function bufferEqual(a, b) {
+ if (a.length !== b.length) {
+ return false;
+ }
+ for (var i = 0; i < a.length; i++) {
+ if (a[i] !== b[i]) {
+ return false;
+ }
+ }
+ return true;
+}
+
+function timeSafeCompare(a, b) {
+ var sa = String(a);
+ var sb = String(b);
+ var key = crypto.pseudoRandomBytes(32);
+ var ah = crypto.createHmac('sha256', key).update(sa).digest();
+ var bh = crypto.createHmac('sha256', key).update(sb).digest();
+
+ return bufferEqual(ah, bh) && a === b;
+}
+
+module.exports = timeSafeCompare;