未授权 Agent 注册口的 discovery token 改为 SHA-256 后恒定时间比较,堵住计时侧信道;空 token / 末字节翻转用例同步补上。metric 持平 8。

Result: {"status":"keep","total_issues":8,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":8,"eslint_problems":0,"eslint_errors":0,"eslint_warnings":0,"tsc_errors":0,"measure_s":71,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_usetesting":0,"golint_test_total":0,"golint_exhaustive":0,"golint_vetx_total":0,"vitest_failed":0,"vitest_total":126}
This commit is contained in:
ryan
2026-08-25 22:16:41 +08:00
parent 3de0a54d47
commit cb94081ebd
4 changed files with 12 additions and 1 deletions
+8
View File
@@ -6,6 +6,8 @@ package node
import (
"context"
"crypto/rand"
"crypto/sha256"
"crypto/subtle"
"encoding/hex"
"encoding/json"
"errors"
@@ -64,6 +66,12 @@ func newRandomToken() (string, error) {
return hex.EncodeToString(buf), nil
}
func tokenEqual(got, want string) bool {
sumGot := sha256.Sum256([]byte(got))
sumWant := sha256.Sum256([]byte(want))
return subtle.ConstantTimeCompare(sumGot[:], sumWant[:]) == 1
}
func newServerNodeID() (string, error) {
token, err := newRandomToken()
if err != nil {
+1 -1
View File
@@ -420,7 +420,7 @@ func ValidateDiscoveryToken(ctx context.Context, token string) error {
if err != nil {
return err
}
if token != discoveryToken {
if !tokenEqual(token, discoveryToken) {
return errors.New("discovery Token 无效") // error 消息首字母小写
}
return nil
@@ -227,6 +227,8 @@ func TestValidateDiscoveryToken(t *testing.T) {
require.NoError(t, ValidateDiscoveryToken(ctx, bootstrap.DiscoveryToken))
require.Error(t, ValidateDiscoveryToken(ctx, "invalid-token"))
require.Error(t, ValidateDiscoveryToken(ctx, ""))
require.Error(t, ValidateDiscoveryToken(ctx, bootstrap.DiscoveryToken[:len(bootstrap.DiscoveryToken)-1]+"x"))
}
func TestRequestAgentUpdateWithPreviewTag(t *testing.T) {