mirror of
https://github.com/versity/versitygw.git
synced 2026-09-22 16:04:15 +00:00
AWS SigV4 signatures are attacker-controlled inputs compared against server-computed HMAC values. Ordinary string comparison exits at the first differing byte, which can expose the length of the matching prefix through response timing and, in principle, enable signature forgery for a fixed request after many probes. Use the shared sigv4auth.SecureCompare helper for browser POST-policy signatures and streaming chunk and trailer signatures. The helper preserves the existing accept/reject behavior, including rejecting malformed or different-length signatures, while using crypto/subtle.ConstantTimeCompare for equal-length values.