HomePhabricator

Add hash_equals() fallback and use it
b9e1d5f5c066Unpublished

Authored by PleaseStand.

Unpublished Commit · Learn More

Repository Importing: This repository is still importing.

Description

Add hash_equals() fallback and use it

Two classes (User and SpecialRunJobs) currently contain string
equality checks that purport to be timing-attack resistant.

Reduce code duplication by adding and using a fallback for the
hash_equals() function from PHP 5.6 (currently in beta), in a way
addressing the comment "@todo: make a common method for this".

Change-Id: Iece006ec0216edb3fc5fbef7cc6ec00a6d182775

Details