Skip to main content

secure_token_eq

Function secure_token_eq 

Source
pub fn secure_token_eq(a: &str, b: &str) -> bool
Expand description

Secure constant-time token comparison.

To completely eliminate timing side-channels (including length-leakage attacks), both inputs are hashed using SHA-256 into fixed 32-byte digests, and the digests are compared in constant time using subtle::ConstantTimeEq.