Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

crypto: fix webcrypto HMAC "get key length" in deriveKey and generateKey #44917

Merged
merged 1 commit into from
Oct 12, 2022

Conversation

panva
Copy link
Member

@panva panva commented Oct 7, 2022

#42542 unfortunately used the hash's output size instead of block size. This also fixes the same problem for HMAC generateKey when length is missing.

Screenshot 2022-10-08 at 1 07 33

Screenshot 2022-10-08 at 1 07 02

Refs: denoland/deno#16180 (comment)
Refs: cloudflare/workerd#68 (comment)

@panva panva added crypto Issues and PRs related to the crypto subsystem. experimental Issues and PRs related to experimental features. webcrypto labels Oct 7, 2022
@panva panva requested review from jasnell and tniessen October 7, 2022 23:15
@nodejs-github-bot
Copy link
Collaborator

Review requested:

  • @nodejs/crypto

@nodejs-github-bot nodejs-github-bot added the needs-ci PRs that need a full CI run. label Oct 7, 2022
@panva panva added the request-ci Add this label to start a Jenkins CI on a PR. label Oct 7, 2022
@github-actions github-actions bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Oct 7, 2022
@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot
Copy link
Collaborator

@panva panva force-pushed the fix-webcrypto-get-key-length branch from f979ef3 to 7f2258f Compare October 10, 2022 07:46
@panva panva added the request-ci Add this label to start a Jenkins CI on a PR. label Oct 10, 2022
@github-actions github-actions bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Oct 10, 2022
@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot
Copy link
Collaborator

@panva panva added the author ready PRs that have at least one approval, no pending requests for changes, and a CI started. label Oct 10, 2022
@panva panva force-pushed the fix-webcrypto-get-key-length branch from 7f2258f to 472ae3a Compare October 12, 2022 10:55
@panva panva added the request-ci Add this label to start a Jenkins CI on a PR. label Oct 12, 2022
@github-actions github-actions bot removed the request-ci Add this label to start a Jenkins CI on a PR. label Oct 12, 2022
@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot
Copy link
Collaborator

@nodejs-github-bot
Copy link
Collaborator

@panva panva added the commit-queue Add this label to land a pull request using GitHub Actions. label Oct 12, 2022
@nodejs-github-bot nodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label Oct 12, 2022
@nodejs-github-bot nodejs-github-bot merged commit 214354f into nodejs:main Oct 12, 2022
@nodejs-github-bot
Copy link
Collaborator

Landed in 214354f

@panva panva deleted the fix-webcrypto-get-key-length branch October 13, 2022 09:12
danielleadams pushed a commit that referenced this pull request Dec 30, 2022
PR-URL: #44917
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
danielleadams pushed a commit that referenced this pull request Jan 3, 2023
PR-URL: #44917
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
panva added a commit to panva/node that referenced this pull request Mar 31, 2023
PR-URL: nodejs#44917
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Backport-PR-URL: nodejs#47336
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
author ready PRs that have at least one approval, no pending requests for changes, and a CI started. crypto Issues and PRs related to the crypto subsystem. experimental Issues and PRs related to experimental features. needs-ci PRs that need a full CI run. webcrypto
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants