Files
sexy/lib/auth/timing-safe-compare.ts
valknarandClaude Sonnet 5 1119c8eea0
CI / Static checks (push) Successful in 1m27s
CI / Build and push image (push) Skipped
Initial implementation of Bluetooth toy control app
Next.js app with a browser-side buttplug/buttplug-wasm control layer
(server never touches real-time device commands), SQLite storage via
Drizzle, single-secret auth, recordings/replay with device remapping,
a usage stats dashboard, Docker deployment, and Gitea CI.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W8WkFF5ppURBAB918593Eb
2026-08-25 07:51:38 +02:00

15 lines
585 B
TypeScript

import { timingSafeEqual } from "node:crypto";
/**
* Constant-time string comparison. `timingSafeEqual` throws on mismatched
* buffer lengths, which would itself leak length via which branch throws -
* so a length mismatch is treated as a plain (also constant-time-irrelevant,
* since it never reaches the byte comparison) false rather than propagating.
*/
export function timingSafeStringEqual(a: string, b: string): boolean {
const bufA = Buffer.from(a);
const bufB = Buffer.from(b);
if (bufA.length !== bufB.length) return false;
return timingSafeEqual(bufA, bufB);
}