fix: Constant time comparison for webhook authentication
This commit is contained in:
parent
f22b3953b1
commit
0b072db36d
|
|
@ -2,6 +2,7 @@ package webhooks
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"crypto/hmac"
|
"crypto/hmac"
|
||||||
|
"crypto/subtle"
|
||||||
"crypto/sha1"
|
"crypto/sha1"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
|
|
@ -105,7 +106,9 @@ func (v *AuthVerifier) verifyBearer(r *http.Request) bool {
|
||||||
}
|
}
|
||||||
|
|
||||||
token := strings.TrimPrefix(authHeader, "Bearer ")
|
token := strings.TrimPrefix(authHeader, "Bearer ")
|
||||||
return token == v.config.Secret
|
tokenBytes := []byte(token)
|
||||||
|
secretBytes := []byte(v.config.Secret)
|
||||||
|
return len(tokenBytes) == len(secretBytes) && subtle.ConstantTimeCompare(tokenBytes, secretBytes) == 1
|
||||||
}
|
}
|
||||||
|
|
||||||
func (v *AuthVerifier) verifyBasic(r *http.Request) bool {
|
func (v *AuthVerifier) verifyBasic(r *http.Request) bool {
|
||||||
|
|
|
||||||
|
|
@ -12,7 +12,6 @@ import (
|
||||||
type WebhookMatcher struct {
|
type WebhookMatcher struct {
|
||||||
config config.WebhookConfig
|
config config.WebhookConfig
|
||||||
req *http.Request
|
req *http.Request
|
||||||
body interface{}
|
|
||||||
bodyBytes []byte
|
bodyBytes []byte
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -50,9 +49,9 @@ func (m *WebhookMatcher) matchHeaders() bool {
|
||||||
actualValue := m.req.Header.Get(key)
|
actualValue := m.req.Header.Get(key)
|
||||||
if !m.compareValues(actualValue, expectedValue) {
|
if !m.compareValues(actualValue, expectedValue) {
|
||||||
log.WithFields(log.Fields{
|
log.WithFields(log.Fields{
|
||||||
"header": key,
|
"header": key,
|
||||||
"expected": expectedValue,
|
"expected": expectedValue,
|
||||||
"actual": actualValue,
|
"actual": actualValue,
|
||||||
}).Debugf("Header mismatch")
|
}).Debugf("Header mismatch")
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
@ -70,9 +69,9 @@ func (m *WebhookMatcher) matchQuery() bool {
|
||||||
actualValue := query.Get(key)
|
actualValue := query.Get(key)
|
||||||
if !m.compareValues(actualValue, expectedValue) {
|
if !m.compareValues(actualValue, expectedValue) {
|
||||||
log.WithFields(log.Fields{
|
log.WithFields(log.Fields{
|
||||||
"query": key,
|
"query": key,
|
||||||
"expected": expectedValue,
|
"expected": expectedValue,
|
||||||
"actual": actualValue,
|
"actual": actualValue,
|
||||||
}).Debugf("Query parameter mismatch")
|
}).Debugf("Query parameter mismatch")
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
@ -144,7 +143,7 @@ func (m *WebhookMatcher) ExtractArguments() (map[string]string, error) {
|
||||||
value, err := matcher.ExtractValue(jsonPath)
|
value, err := matcher.ExtractValue(jsonPath)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.WithFields(log.Fields{
|
log.WithFields(log.Fields{
|
||||||
"argName": argName,
|
"argName": argName,
|
||||||
"jsonPath": jsonPath,
|
"jsonPath": jsonPath,
|
||||||
"error": err,
|
"error": err,
|
||||||
}).Debugf("Failed to extract value")
|
}).Debugf("Failed to extract value")
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue