Module: Hanami::Tachiban
- Defined in:
- lib/tachiban.rb
Constant Summary collapse
- DUMMY_HASH =
To close the account enumeration vulnerability via response timing, a dummy hash is computed once when Tachiban loads. When no user is found, the provided password is verified against that dummy hash instead of returning immediately. Both the existing-account and missing-account paths then perform one Argon2 verification, so the response time no longer tells an attacker whether an account exists.
The dummy hash is precomputed rather than generated per request on purpose: Argon2 hash creation is more expensive than verification, so generating one per miss would make the missing-account path measurably slower and reopen the leak in the other direction. Argon2::Password.create(SecureRandom.hex(32)).freeze