seahaven-door-unlock-api/lambda/lockdown
Adam Moussa fe04a199de fix: use constant-time auth token comparison (INFRA-21) (#30)
Replace plain token !== secrets.authToken checks in the unlock and
lockdown handlers with crypto.timingSafeEqual, guarding for unequal
buffer lengths first (timingSafeEqual throws on different lengths).
Prevents timing side-channel leakage of the auth token. Handler
signatures, event shape, and return contract are unchanged.
2026-06-05 17:26:12 -04:00
..
lockdown-handler.ts fix: use constant-time auth token comparison (INFRA-21) (#30) 2026-06-05 17:26:12 -04:00