Skip to content

Latest commit

 

History

History
31 lines (18 loc) · 915 Bytes

readme.md

File metadata and controls

31 lines (18 loc) · 915 Bytes

Crypto Timing-Safe Equals

An isomorphic timing-safe equality function for strings and Uint8Arrays.

This is a port of @ircmaxell's function for PHP, published here.

If you want to avoid leaking the length of your secret, you should always pass that as the first argument to the function.

Install

npm install --save crypto-timing-safe-equals

Usage

import timingSafeEquals from 'crypto-timing-safe-equals';

// Check if two strings are equal, in a timing-safe manner

timingSafeEquals ( 'secret', 'attempt' ); // => false

// Check if two Uint8Arrays are equal, in a timing-safe manner

timingSafeEquals ( new Uint8Array ([ 102, 111, 111 ]), new Uint8Array ([ 98, 97, 114 ]) ); // => false

License

MIT © Fabio Spampinato