Skip to content

Sample signature checking code should use secrets.compare_digest, not != #109

@inducer

Description

@inducer

This is in reference to

https://us.prairietest.com/pt/docs/api/exam-access

Due to the existence of a timestamp, a timing attack is less likely, but it's good practice still.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions