99designs / 99designs/http-signatures-php

Use hash_equals instead of double HMAC approach for signature comparison

Open
#29 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
PHP
Stars
46
Forks
35
PR merge metrics
No merged PRs in 30d

Description

See https://github.com/99designs/http-signatures-php/pull/28 for what prompted this.

We're currently using a double HMAC approach for signature comparison, as that was the only way for us to securely compare HMAC signatures without making it a breaking change, as the [hash_equals](https://secure.php.net/hash_equals) function we need isn't available until PHP 5.7, and we support PHP 5.5+

When we roll out our next major version we should increase the minimum PHP version to 5.7 or higher, and swap to using `hash_equals`.

Contributor guide

No contributing guide indexed for this repository

Research direction

Look for signature comparison code in the codebase, likely in a class handling HMAC verification. Replace the double HMAC comparison with hash_equals. Check the PHP version requirement in composer.json to ensure it's 5.7+. Run existing tests to verify the change doesn't break functionality.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
security
Issue type
Refactor
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.