Merge branch 'main' into next

This commit is contained in:
saltyaom
2026-01-03 21:19:44 +07:00
3 changed files with 23 additions and 5 deletions
+5 -2
View File
@@ -405,14 +405,17 @@ export const parseCookie = async (
throw new Error('No secret is provided to cookie plugin')
if (isStringKey) {
const temp = await unsignCookie(value as string, secrets)
if (typeof value !== 'string') throw new InvalidCookieSignature(name)
const temp = await unsignCookie(value, secrets)
if (temp === false) throw new InvalidCookieSignature(name)
value = temp
} else {
let decoded = false
for (let i = 0; i < secrets.length; i++) {
const temp = await unsignCookie(value as string, secrets[i])
if (typeof value !== 'string') throw new InvalidCookieSignature(name)
const temp = await unsignCookie(value, secrets[i])
if (temp !== false) {
decoded = true
+1
View File
@@ -221,6 +221,7 @@ export const hasElysiaMeta = (meta: string, _schema: TAnySchema): boolean => {
if (schema.type === 'object') {
const properties = schema.properties as Record<string, TAnySchema>
if (!properties) return false
for (const key of Object.keys(properties)) {
const property = properties[key]
+17 -3
View File
@@ -1,5 +1,6 @@
import type { Sucrose } from './sucrose'
import type { TraceHandler } from './trace'
import { timingSafeEqual } from 'crypto'
import type {
LifeCycleStore,
@@ -685,16 +686,29 @@ export const signCookie = async (val: string, secret: string | null) => {
)
}
const constantTimeEqual = (a: string, b: string) => {
// Compare as UTF-8 bytes; timingSafeEqual requires equal length
const ab = Buffer.from(a, 'utf8')
const bb = Buffer.from(b, 'utf8')
if (ab.length !== bb.length) return false
return timingSafeEqual(ab, bb)
}
export const unsignCookie = async (input: string, secret: string | null) => {
if (typeof input !== 'string')
throw new TypeError('Signed cookie string must be provided.')
if (null === secret) throw new TypeError('Secret key must be provided.')
if (secret === null)
throw new TypeError('Secret key must be provided.')
const tentativeValue = input.slice(0, input.lastIndexOf('.'))
const dot = input.lastIndexOf('.')
if (dot <= 0) return false
const tentativeValue = input.slice(0, dot)
const expectedInput = await signCookie(tentativeValue, secret)
return expectedInput === input ? tentativeValue : false
return constantTimeEqual(expectedInput, input) ? tentativeValue : false
}
export const insertStandaloneValidator = <const Name extends keyof InputSchema>(