mirror of
https://github.com/elysiajs/elysia
synced 2026-08-09 12:35:48 +00:00
Merge branch 'main' into next
This commit is contained in:
+5
-2
@@ -405,14 +405,17 @@ export const parseCookie = async (
|
||||
throw new Error('No secret is provided to cookie plugin')
|
||||
|
||||
if (isStringKey) {
|
||||
const temp = await unsignCookie(value as string, secrets)
|
||||
if (typeof value !== 'string') throw new InvalidCookieSignature(name)
|
||||
|
||||
const temp = await unsignCookie(value, secrets)
|
||||
if (temp === false) throw new InvalidCookieSignature(name)
|
||||
|
||||
value = temp
|
||||
} else {
|
||||
let decoded = false
|
||||
for (let i = 0; i < secrets.length; i++) {
|
||||
const temp = await unsignCookie(value as string, secrets[i])
|
||||
if (typeof value !== 'string') throw new InvalidCookieSignature(name)
|
||||
const temp = await unsignCookie(value, secrets[i])
|
||||
|
||||
if (temp !== false) {
|
||||
decoded = true
|
||||
|
||||
@@ -221,6 +221,7 @@ export const hasElysiaMeta = (meta: string, _schema: TAnySchema): boolean => {
|
||||
|
||||
if (schema.type === 'object') {
|
||||
const properties = schema.properties as Record<string, TAnySchema>
|
||||
if (!properties) return false
|
||||
|
||||
for (const key of Object.keys(properties)) {
|
||||
const property = properties[key]
|
||||
|
||||
+17
-3
@@ -1,5 +1,6 @@
|
||||
import type { Sucrose } from './sucrose'
|
||||
import type { TraceHandler } from './trace'
|
||||
import { timingSafeEqual } from 'crypto'
|
||||
|
||||
import type {
|
||||
LifeCycleStore,
|
||||
@@ -685,16 +686,29 @@ export const signCookie = async (val: string, secret: string | null) => {
|
||||
)
|
||||
}
|
||||
|
||||
const constantTimeEqual = (a: string, b: string) => {
|
||||
// Compare as UTF-8 bytes; timingSafeEqual requires equal length
|
||||
const ab = Buffer.from(a, 'utf8')
|
||||
const bb = Buffer.from(b, 'utf8')
|
||||
|
||||
if (ab.length !== bb.length) return false
|
||||
return timingSafeEqual(ab, bb)
|
||||
}
|
||||
|
||||
export const unsignCookie = async (input: string, secret: string | null) => {
|
||||
if (typeof input !== 'string')
|
||||
throw new TypeError('Signed cookie string must be provided.')
|
||||
|
||||
if (null === secret) throw new TypeError('Secret key must be provided.')
|
||||
if (secret === null)
|
||||
throw new TypeError('Secret key must be provided.')
|
||||
|
||||
const tentativeValue = input.slice(0, input.lastIndexOf('.'))
|
||||
const dot = input.lastIndexOf('.')
|
||||
if (dot <= 0) return false
|
||||
|
||||
const tentativeValue = input.slice(0, dot)
|
||||
const expectedInput = await signCookie(tentativeValue, secret)
|
||||
|
||||
return expectedInput === input ? tentativeValue : false
|
||||
return constantTimeEqual(expectedInput, input) ? tentativeValue : false
|
||||
}
|
||||
|
||||
export const insertStandaloneValidator = <const Name extends keyof InputSchema>(
|
||||
|
||||
Reference in New Issue
Block a user