mirror of
https://github.com/opencloud-eu/opencloud.git
synced 2026-07-20 12:34:30 -04:00
generate cryptographically secure state token
This commit is contained in:
7
changelog/unreleased/generate-secure-state.md
Normal file
7
changelog/unreleased/generate-secure-state.md
Normal file
@@ -0,0 +1,7 @@
|
||||
Change: generate cryptographically secure state token
|
||||
|
||||
Replaced Math.random with a cryptographically secure way to generate the oidc state token using the javascript crypto api.
|
||||
|
||||
https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getRandomValues
|
||||
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Math/random
|
||||
https://github.com/owncloud/ocis/pull/1203
|
||||
@@ -1,5 +1,9 @@
|
||||
export function withClientRequestState(obj) {
|
||||
obj.state = Math.random().toString(36).substring(7);
|
||||
// Generate a 16 byte random token
|
||||
const values = new Uint8Array(16);
|
||||
crypto.getRandomValues(values);
|
||||
// Convert the 16 byte to a hex string and assign to the state attribute
|
||||
obj.state = Array.prototype.map.call(values, x => x.toString(16)).join('');
|
||||
|
||||
return obj;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user