Skip to content

Fix/codeql secure random - #53

Merged
Babak (babaknaderi) merged 2 commits into
mainfrom
fix/codeql-secure-random
Oct 8, 2026
Merged

Babak (babaknaderi) merged 2 commits into
mainfrom
fix/codeql-secure-random

Conversation

@babaknaderi

Copy link
Copy Markdown
Collaborator

No description provided.

Babak (babaknaderi) and others added 2 commits October 8, 2026 15:25
Replace Math.random-based session and local worker identifiers with 128-bit values generated by the Web Crypto API.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep secure session identifiers at the original nine-character length and limit the CodeQL fix to the affected session ID pattern.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused changes correctly replace predictable randomness consistently without altering session-monitoring behavior.

0 open findings

What changed in this PR

Replaces predictable session identifiers with cryptographically secure browser-generated values across all study templates.

Changes:

  • Uses crypto.getRandomValues() for session ID generation.
  • Preserves the existing nine-character session ID format.
File Description
src/​template/​DCR_template.html Secures DCR session IDs.
src/​template/​avatar_template.html Secures avatar session IDs.
src/​template/​ACRHR_template.html Secures ACR-HR session IDs.
src/​template/​ACR_template.html Secures ACR session IDs.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@babaknaderi
Babak (babaknaderi) merged commit f5fdbc2 into main Oct 8, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants