From 27bececfc9e86210c181ac506646b6fcacf3e269 Mon Sep 17 00:00:00 2001 From: Babak Naderi Date: Thu, 8 Oct 2026 15:25:49 +0200 Subject: [PATCH 1/2] Use secure randomness for browser identifiers Replace Math.random-based session and local worker identifiers with 128-bit values generated by the Web Crypto API. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- hitapp_server/api/res/frame_template.html.template | 2 +- src/template/ACRHR_template.html | 2 +- src/template/ACR_template.html | 2 +- src/template/DCR_template.html | 2 +- src/template/avatar_template.html | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/hitapp_server/api/res/frame_template.html.template b/hitapp_server/api/res/frame_template.html.template index dbb3b94..77263af 100644 --- a/hitapp_server/api/res/frame_template.html.template +++ b/hitapp_server/api/res/frame_template.html.template @@ -44,7 +44,7 @@ function getLocalWorkerID(){ c_name = "w_id"; local_worker_id = readCookie(c_name); if (!local_worker_id){ - let id = Math.random().toString(36).substring(3) + Math.random().toString(36).substring(3); + let id = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); // for a month createCookie(c_name,"loc"+id,1440*7*4) local_worker_id = readCookie(c_name); diff --git a/src/template/ACRHR_template.html b/src/template/ACRHR_template.html index faaece6..13dbcdb 100644 --- a/src/template/ACRHR_template.html +++ b/src/template/ACRHR_template.html @@ -218,7 +218,7 @@ **/ function initializeActivePageMonitoring(){ - sessionId = Math.random().toString(36).substr(2, 9); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/ACR_template.html b/src/template/ACR_template.html index 059230b..55cec45 100644 --- a/src/template/ACR_template.html +++ b/src/template/ACR_template.html @@ -222,7 +222,7 @@ // not more than 2min loading time is acceptable despite the internet speed test and file size page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Math.random().toString(36).substr(2, 9); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/DCR_template.html b/src/template/DCR_template.html index 5bad471..9f71c0c 100644 --- a/src/template/DCR_template.html +++ b/src/template/DCR_template.html @@ -272,7 +272,7 @@ page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Math.random().toString(36).substr(2, 9); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/avatar_template.html b/src/template/avatar_template.html index ad93b5e..8263d13 100644 --- a/src/template/avatar_template.html +++ b/src/template/avatar_template.html @@ -234,7 +234,7 @@ // not more than 2min loading time is acceptable despite the internet speed test and file size page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Math.random().toString(36).substr(2, 9); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); From efbe08c69963da0e9afb40d946b30452977b1e39 Mon Sep 17 00:00:00 2001 From: Babak Naderi Date: Thu, 8 Oct 2026 15:29:36 +0200 Subject: [PATCH 2/2] Preserve session identifier length Keep secure session identifiers at the original nine-character length and limit the CodeQL fix to the affected session ID pattern. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- hitapp_server/api/res/frame_template.html.template | 2 +- src/template/ACRHR_template.html | 2 +- src/template/ACR_template.html | 2 +- src/template/DCR_template.html | 2 +- src/template/avatar_template.html | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/hitapp_server/api/res/frame_template.html.template b/hitapp_server/api/res/frame_template.html.template index 77263af..dbb3b94 100644 --- a/hitapp_server/api/res/frame_template.html.template +++ b/hitapp_server/api/res/frame_template.html.template @@ -44,7 +44,7 @@ function getLocalWorkerID(){ c_name = "w_id"; local_worker_id = readCookie(c_name); if (!local_worker_id){ - let id = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); + let id = Math.random().toString(36).substring(3) + Math.random().toString(36).substring(3); // for a month createCookie(c_name,"loc"+id,1440*7*4) local_worker_id = readCookie(c_name); diff --git a/src/template/ACRHR_template.html b/src/template/ACRHR_template.html index 13dbcdb..921b17b 100644 --- a/src/template/ACRHR_template.html +++ b/src/template/ACRHR_template.html @@ -218,7 +218,7 @@ **/ function initializeActivePageMonitoring(){ - sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(5)), byte => byte.toString(16).padStart(2, "0")).join("").slice(0, 9); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/ACR_template.html b/src/template/ACR_template.html index 55cec45..0a70408 100644 --- a/src/template/ACR_template.html +++ b/src/template/ACR_template.html @@ -222,7 +222,7 @@ // not more than 2min loading time is acceptable despite the internet speed test and file size page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(5)), byte => byte.toString(16).padStart(2, "0")).join("").slice(0, 9); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/DCR_template.html b/src/template/DCR_template.html index 9f71c0c..758fe08 100644 --- a/src/template/DCR_template.html +++ b/src/template/DCR_template.html @@ -272,7 +272,7 @@ page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(5)), byte => byte.toString(16).padStart(2, "0")).join("").slice(0, 9); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70); diff --git a/src/template/avatar_template.html b/src/template/avatar_template.html index 8263d13..3e0f1dc 100644 --- a/src/template/avatar_template.html +++ b/src/template/avatar_template.html @@ -234,7 +234,7 @@ // not more than 2min loading time is acceptable despite the internet speed test and file size page_loading_timer = setTimeout(show_message_too_long_loading, 120*1000); - sessionId = Array.from(crypto.getRandomValues(new Uint8Array(16)), byte => byte.toString(16).padStart(2, "0")).join(""); + sessionId = Array.from(crypto.getRandomValues(new Uint8Array(5)), byte => byte.toString(16).padStart(2, "0")).join("").slice(0, 9); sessionIdVariableName = config.qualificationCookieName +"_sid"; createCookie(sessionIdVariableName,sessionId,70);