Skip to content

security: timing-safe HMAC and CORS wildcard fix - #617

Open
wahh3b-lgtm wants to merge 3 commits into
PasarGuard:devfrom
wahh3b-lgtm:pr-1-security-v2
Open

wahh3b-lgtm wants to merge 3 commits into
PasarGuard:devfrom
wahh3b-lgtm:pr-1-security-v2

Conversation

@wahh3b-lgtm

@wahh3b-lgtm wahh3b-lgtm commented Jun 15, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  • JWT timing-safe verification (app/utils/jwt.py): Replaced in membership check with hmac.compare_digest using bitwise OR to ensure both comparisons always execute, preventing timing side-channels
  • CORS wildcard fix (app/middlewares/__init__.py): When allow_credentials=True, any wildcard origin (*) in the allowed origins list now disables credentials with a warning
  • Python 2 syntax fix (app/utils/jwt.py): Fixed except TypeError, ValueError: to except (TypeError, ValueError):

What was removed (per project owner feedback)

  • Rate limiting: Should be handled at infrastructure level (nginx, cloudflare, haproxy)
  • TTL on get_secret_key: The JWT secret key is permanent and doesn't need a TTL
  • invalidate_secret_key_cache: Unused function removed

Files Changed

  • app/utils/jwt.py
  • app/middlewares/__init__.py

Verification

  • Ruff lint + format pass
  • 13/13 tests pass

Summary by CodeRabbit

  • Bug Fixes
    • Cross-origin requests now include credential permission only when allowed origins are explicitly configured. When the wildcard origin is used, credential permission is omitted.
    • Legacy subscription tokens are accepted when their signatures match either supported format. Tokens with altered signatures, including non-ASCII characters, are rejected.

- Use hmac.compare_digest with bitwise OR for constant-time JWT signature verification
- Reject wildcard CORS origins when allow_credentials=True
- Fix Python 2 exception syntax (except TypeError, ValueError -> except (TypeError, ValueError))
@coderabbitai

coderabbitai Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 03059053-52b6-4a7d-b3a6-5cfa249491be

📥 Commits

Reviewing files that changed from the base of the PR and between 2c474eb and c8a87c9.


📒 Files selected for processing (3)
  • app/middlewares/__init__.py
  • app/utils/jwt.py
  • tests/test_security_hardening.py

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 4 remain after this review.



Walkthrough

The pull request changes legacy subscription-token signature validation to use constant-time comparisons. It also disables CORS credentials when the allowed origins include *. Tests cover both changes.

Changes

Legacy token validation

Layer / File(s) Summary
Legacy signature validation and tests
app/utils/jwt.py, tests/test_security_hardening.py
Legacy signature validation uses constant-time comparisons against two supported encodings. Tests cover valid and altered signatures.

CORS credential handling

Layer / File(s) Summary
CORS origin configuration and tests
app/middlewares/__init__.py, tests/test_security_hardening.py
CORS setup disables credentials for wildcard origins and enables them for explicit origins. Tests check the credentials and allow-origin headers.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: m03ed

Merge Risk: ⚪ Minimal · up to c8a87

The change hardens legacy token signature comparison and stops sending CORS credentials for wildcard origins. No actionable merge-blocking risk is evident.

Pre-merge checks | Passed 4 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes both main changes: timing-safe HMAC validation and the CORS wildcard credential fix.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks each token’s mark,
And guards the origins after dark.
Two signatures meet a careful test,
While wildcard stars receive no crest.
The burrow’s headers settle right,
Then carrots crunch beneath moonlight.

Comment @coderabbitai help to get the list of available commands.

dev restructured app/utils/jwt.py (new HMAC token format, Python 3.14
except syntax), so take dev's version here; the constant-time compare is
re-applied to the legacy branch in the next commit.
…e legacy signatures in constant time

ALLOWED_ORIGINS defaults to "*". With allow_credentials on, Starlette
then echoes every cross-origin request's Origin back together with
Access-Control-Allow-Credentials, so any site could make credentialed
requests and read the responses. Credentials are now only allowed when
the origins are listed explicitly. The panel authenticates with bearer
tokens, so the dashboard is unaffected; there is no startup warning,
since the wildcard is the default.

The legacy subscription token branch still matched its signature with
`in`. It now uses hmac.compare_digest on bytes for both encodings (str
input must be ASCII, and the signature comes from the URL).
@T3ST3ST3R0N

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants