Skip to content

fix: reduce timing-based user enumeration - #1382

Open
michalsn wants to merge 2 commits into
codeigniter4:developfrom
michalsn:fix/harden-auth-timing
Open

michalsn wants to merge 2 commits into
codeigniter4:developfrom
michalsn:fix/harden-auth-timing

Conversation

@michalsn

@michalsn michalsn commented Oct 2, 2026

Copy link
Copy Markdown
Member

Description
The OWASP Authentication Cheat Sheet recommends generic authentication errors and warns that early returns can reveal whether an account exists through response time. These changes address both discrepancies without claiming constant time for the entire request.

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@michalsn michalsn added the bug Something isn't working label Oct 2, 2026
@@ -142,7 +142,16 @@ public function check(array $credentials): Result
}

// Extract UserToken and HMACSHA256 Signature from Authorization token

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you please move the existing comment:

// Extract UserToken and HMACSHA256 Signature from Authorization token
[$userToken, $signature] = $authTokens;

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants