Timing attack on signature comparison
Review this Node.js webhook signature check.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 25 min
Mark a line and say what kind of problem it is.0 findings
1function verifyWebhook(req) {
2 const sig = req.headers['x-signature'];
3 const expected = crypto
4 .createHmac('sha256', SECRET)
5 .update(req.rawBody)
6 .digest('hex');
7 if (sig === expected) {
8 return true;
9 }
10 return false;
11}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.