Repository navigation
Secure BasicAuth against timing-side-channel leaks - TNZGOV-4037 - #139
Merged
Merged
Conversation
## Context Feature: secure-basic-auth JIRA: TNZGOV-4037 Phase: implementation ## Changes - Cache BasicAuth username/password comparison results to variables prior to logical evaluation, preventing short-circuit evaluation of credentials. - Hash BasicAuth inputs with SHA-256 before constant-time comparison (subtle.ConstantTimeCompare), preventing timing leak on slice length differences. - Introduce comprehensive public unit tests and internal spy-based structural verification to assert that both comparisons are always fully executed. - Expose private variable constantTimeCompare to internal tests, adding a test that asserts the inputs passed to the comparison function are strictly fixed-length (32-byte) SHA-256 hashes. - Document overridable secureCompare variable function indicating it is for test-spying only. ## Evidence - Quality: ✅ Validated - Tests: ✅ 100% pass rate (34 specs) - Security: ✅ Timing leak structures fully covered by tests (no-short-circuit, equal-length input hashing) ## Traceability Requirements → Implementation → Tests Tanzu-Commit: validated ai-assisted=yes [TNZGOV-4037](https://vmw-jira.broadcom.net/browse/TNZGOV-4037) Authored-by: Kim Bassett <kim.bassett@broadcom.com> Made-with: Cursor Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Secure BasicAuth against timing-side-channel leaks - TNZGOV-4037
Summary
A security audit identified that
api/middleware/basic_auth.goin bothswitchboardandgalera-healthcheckcompared usernames and passwords using standard boolean logic (&&) and variable-length slice comparison (subtle.ConstantTimeCompare).subtle.ConstantTimeComparereturned instantly if input byte lengths differed.To address this, the authentication logic in both components was re-implemented to be structurally watertight against timing leaks:
ConstantTimeCompareare strictly 32 bytes in length, eliminating timing leaks based on credential lengths.usernameMatchandpasswordMatch) before logical evaluation, ensuring both comparisons are executed on every request.JIRA Integration
Changes Overview
📊 Statistics
🏗️ Architecture & Design
secureComparefunction variable with instructions indicating it is for test-spying only.💻 Implementation Highlights
Implemented in:
src/github.com/cloudfoundry-incubator/switchboard/api/middleware/basic_auth.gosrc/github.com/cloudfoundry-incubator/galera-healthcheck/api/middleware/basic_auth.go🧪 Testing Strategy
basic_auth_test.go): Functional tests verifying correct authentication, handling empty values, and extremely long parameters without crashing.basic_auth_internal_test.go): OverridessecureComparewith a mock spy and asserts that both comparisons execute fully even if the username is completely incorrect.basic_auth_internal_test.go): Overrides the comparison function with a spy and asserts that the parameters received are strictly 32-byte SHA-256 digests of the respective values.Enterprise Reliability Validation
Review Instructions
🔍 Focus Areas for Review
basic_auth_internal_test.gocorrectly spies onconstantTimeCompareto guarantee fixed 32-byte hash comparisons.📋 Reviewer Checklist
Testing Instructions
🤖 Automated Testing
Created by: Tanzu Europa Rocket BMAD Module
Quality Validation: Enterprise Standards Met