Skip to content

fix(security): timing-safe seed secret comparison + fix SAMPLE_DATA attestation shape - #2053

Open
neverm1ndthat wants to merge 1 commit into
Commitlabs-Org:masterfrom
neverm1ndthat:fix/1940-seed-security
Open

neverm1ndthat wants to merge 1 commit into
Commitlabs-Org:masterfrom
neverm1ndthat:fix/1940-seed-security

Conversation

@neverm1ndthat

Copy link
Copy Markdown

Fixes #1940

Changes

  1. Security fix: isSeedSecretValid() now uses Node's imingSafeEqual instead of plain === comparison, preventing timing side-channel attacks on the seed secret. Follows the same pattern already used in csrf.ts's safeEqualToken helper.

  2. Type shape fix: Removed the non-existent �ddress field from SAMPLE_DATA.attestations[0]. The Attestation interface only defines id, commitmentId, kind, status, �erdict, observedAt, imestamp, severity, and a few optional fields.

  3. Compile-time safety: Added satisfies MockData assertion on SAMPLE_DATA so future shape mismatches are caught at compile time instead of silently passing.

…ttestation shape

Issue Commitlabs-Org#1940:
(1) Replace plain === secret comparison with Node's timingSafeEqual
(2) Remove non-existent address field from SAMPLE_DATA attestations
(3) Add satisfies MockData assertion so shape mismatches are caught at compile time
@vercel

vercel Bot commented Oct 6, 2026

Copy link
Copy Markdown

@neverm1ndthat is attempting to deploy a commit to the 1nonly's projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Non-timing-safe secret comparison and mistyped sample data in src/lib/backend/seed.ts

1 participant