fix: Constant time comparison for webhook authentication

This commit is contained in:
jamesread 2026-01-06 22:11:41 +00:00
parent f22b3953b1
commit 0b072db36d
2 changed files with 11 additions and 9 deletions

View File

@ -2,6 +2,7 @@ package webhooks
import ( import (
"crypto/hmac" "crypto/hmac"
"crypto/subtle"
"crypto/sha1" "crypto/sha1"
"crypto/sha256" "crypto/sha256"
"encoding/hex" "encoding/hex"
@ -105,7 +106,9 @@ func (v *AuthVerifier) verifyBearer(r *http.Request) bool {
} }
token := strings.TrimPrefix(authHeader, "Bearer ") token := strings.TrimPrefix(authHeader, "Bearer ")
return token == v.config.Secret tokenBytes := []byte(token)
secretBytes := []byte(v.config.Secret)
return len(tokenBytes) == len(secretBytes) && subtle.ConstantTimeCompare(tokenBytes, secretBytes) == 1
} }
func (v *AuthVerifier) verifyBasic(r *http.Request) bool { func (v *AuthVerifier) verifyBasic(r *http.Request) bool {

View File

@ -12,7 +12,6 @@ import (
type WebhookMatcher struct { type WebhookMatcher struct {
config config.WebhookConfig config config.WebhookConfig
req *http.Request req *http.Request
body interface{}
bodyBytes []byte bodyBytes []byte
} }
@ -50,9 +49,9 @@ func (m *WebhookMatcher) matchHeaders() bool {
actualValue := m.req.Header.Get(key) actualValue := m.req.Header.Get(key)
if !m.compareValues(actualValue, expectedValue) { if !m.compareValues(actualValue, expectedValue) {
log.WithFields(log.Fields{ log.WithFields(log.Fields{
"header": key, "header": key,
"expected": expectedValue, "expected": expectedValue,
"actual": actualValue, "actual": actualValue,
}).Debugf("Header mismatch") }).Debugf("Header mismatch")
return false return false
} }
@ -70,9 +69,9 @@ func (m *WebhookMatcher) matchQuery() bool {
actualValue := query.Get(key) actualValue := query.Get(key)
if !m.compareValues(actualValue, expectedValue) { if !m.compareValues(actualValue, expectedValue) {
log.WithFields(log.Fields{ log.WithFields(log.Fields{
"query": key, "query": key,
"expected": expectedValue, "expected": expectedValue,
"actual": actualValue, "actual": actualValue,
}).Debugf("Query parameter mismatch") }).Debugf("Query parameter mismatch")
return false return false
} }
@ -144,7 +143,7 @@ func (m *WebhookMatcher) ExtractArguments() (map[string]string, error) {
value, err := matcher.ExtractValue(jsonPath) value, err := matcher.ExtractValue(jsonPath)
if err != nil { if err != nil {
log.WithFields(log.Fields{ log.WithFields(log.Fields{
"argName": argName, "argName": argName,
"jsonPath": jsonPath, "jsonPath": jsonPath,
"error": err, "error": err,
}).Debugf("Failed to extract value") }).Debugf("Failed to extract value")