CentralAuthUser::validateAuthToken should use constant-time string comparison
Given its non-trivial to pull off a timing attack of this type, I wonder if this patch could go directly on gerrit (/me looks at @csteipp )

Minor, but the argument order should be reversed. From

It is important to provide the user-supplied string as the second parameter, rather than the first.

eww, talk about an easy to misuse api.

I'll update the patch in a moment

Google suggests its for future compatability reasons ( I guess that's more reasonable. I still think that's a poor api design.


23:49 csteipp: deployed patch for T125290

Change 284237 merged by Chad:
[SECURITY] Use constant time comparison in validateAuthToken