From 7bee9b7e0968b650b3dbe2e35bf3a0d7d6e5e00e Mon Sep 17 00:00:00 2001 From: nanalelfe Date: Wed, 27 Jul 2016 08:46:04 -0400 Subject: Removed some unused modules with prune --- node_modules/tsscmp/lib/index.js | 33 --------------------------------- 1 file changed, 33 deletions(-) delete mode 100644 node_modules/tsscmp/lib/index.js (limited to 'node_modules/tsscmp/lib/index.js') diff --git a/node_modules/tsscmp/lib/index.js b/node_modules/tsscmp/lib/index.js deleted file mode 100644 index 7c86142..0000000 --- a/node_modules/tsscmp/lib/index.js +++ /dev/null @@ -1,33 +0,0 @@ -'use strict'; - -// Implements Brad Hill's Double HMAC pattern from -// https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2011/february/double-hmac-verification/. -// The approach is similar to the node's native implementation of timing safe buffer comparison that will be available on v6+. -// https://github.com/nodejs/node/issues/3043 -// https://github.com/nodejs/node/pull/3073 - -var crypto = require('crypto'); - -function bufferEqual(a, b) { - if (a.length !== b.length) { - return false; - } - for (var i = 0; i < a.length; i++) { - if (a[i] !== b[i]) { - return false; - } - } - return true; -} - -function timeSafeCompare(a, b) { - var sa = String(a); - var sb = String(b); - var key = crypto.pseudoRandomBytes(32); - var ah = crypto.createHmac('sha256', key).update(sa).digest(); - var bh = crypto.createHmac('sha256', key).update(sb).digest(); - - return bufferEqual(ah, bh) && a === b; -} - -module.exports = timeSafeCompare; -- cgit v1.2.3