SAP / SAP/gigya-python-sdk

Replace randrange with secrets.randbelow when generating nonce

Open Beginner friendly
#36 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
8
Forks
11
PR merge metrics
No merged PRs in 30d

Description

When generating the nonce random randrange is used, it would be better to swap this out to use the secrets module randbelow function instead

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the nonce-generation code and the use of random randrange in the repository. Replace that usage with the secrets module's randbelow function, then run the existing test suite and verify nonce generation still behaves as expected.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
backend, security
Issue type
Refactor
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.