Page MenuHomePhabricator

Use better secrets in generating account tokens
ClosedPublic

Authored by epriestley on Apr 10 2014, 5:32 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Jan 26, 5:41 AM
Unknown Object (File)
Sat, Jan 25, 2:24 AM
Unknown Object (File)
Dec 18 2024, 7:40 AM
Unknown Object (File)
Dec 12 2024, 10:51 PM
Unknown Object (File)
Dec 9 2024, 2:09 AM
Unknown Object (File)
Dec 5 2024, 6:02 PM
Unknown Object (File)
Dec 3 2024, 10:39 PM
Unknown Object (File)
Nov 29 2024, 2:43 AM
Subscribers

Details

Reviewers
btrahan
Commits
Restricted Diffusion Commit
rPab7d89edc8ad: Use better secrets in generating account tokens
Summary

When we generate account tokens for CSRF keys and email verification, one of the inputs we use is the user's password hash. Users won't always have a password hash, so this is a weak input to key generation. This also couples CSRF weirdly with auth concerns.

Instead, give users a dedicated secret for use in token generation which is used only for this purpose.

Test Plan
  • Ran upgrade scripts.
  • Verified all users got new secrets.
  • Created a new user.
  • Verified they got a secret.
  • Submitted CSRF'd forms, they worked.
  • Adjusted the CSRF token and submitted CSRF'd forms, verified they don't work.

Diff Detail

Repository
rP Phabricator
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

epriestley retitled this revision from to Use better secrets in generating account tokens.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Apr 10 2014, 6:29 PM
epriestley updated this revision to Diff 20747.

Closed by commit rPab7d89edc8ad (authored by @epriestley).