1234567891011121314151617181920212223242526272829303132333435363738 |
- 'use strict';
- var crypto = require('crypto');
- function bufferEqual(a, b) {
- if (a.length !== b.length) {
- return false;
- }
-
-
- if (crypto.timingSafeEqual) {
- return crypto.timingSafeEqual(a, b);
- }
- for (var i = 0; i < a.length; i++) {
- if (a[i] !== b[i]) {
- return false;
- }
- }
- return true;
- }
- function timeSafeCompare(a, b) {
- var sa = String(a);
- var sb = String(b);
- var key = crypto.pseudoRandomBytes(32);
- var ah = crypto.createHmac('sha256', key).update(sa).digest();
- var bh = crypto.createHmac('sha256', key).update(sb).digest();
- return bufferEqual(ah, bh) && a === b;
- }
- module.exports = timeSafeCompare;
|