Next.js app with a browser-side buttplug/buttplug-wasm control layer (server never touches real-time device commands), SQLite storage via Drizzle, single-secret auth, recordings/replay with device remapping, a usage stats dashboard, Docker deployment, and Gitea CI. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W8WkFF5ppURBAB918593Eb
15 lines
585 B
TypeScript
15 lines
585 B
TypeScript
import { timingSafeEqual } from "node:crypto";
|
|
|
|
/**
|
|
* Constant-time string comparison. `timingSafeEqual` throws on mismatched
|
|
* buffer lengths, which would itself leak length via which branch throws -
|
|
* so a length mismatch is treated as a plain (also constant-time-irrelevant,
|
|
* since it never reaches the byte comparison) false rather than propagating.
|
|
*/
|
|
export function timingSafeStringEqual(a: string, b: string): boolean {
|
|
const bufA = Buffer.from(a);
|
|
const bufB = Buffer.from(b);
|
|
if (bufA.length !== bufB.length) return false;
|
|
return timingSafeEqual(bufA, bufB);
|
|
}
|