Repository navigation
fix(security): hash reset codes and session tokens, coordinate reset transactionally (#54) - #56
Conversation
…transactionally (#54)
97c20ce to
810c7ac
Compare
…cated HMAC secret (#54)
Assessment: Yes — both issues are fixed in the latest PR #56The latest PR head is commit Partially migrated schemaStatus: Fixed
PostgreSQLUses independent
MySQLReads SQLiteReads Therefore, a schema containing only Missing individual hardened columnsStatus: Fixed The latest migration no longer gates all additions on the presence of This previous failure mode: Text
is now handled correctly. Supporting tests addedThe PR now includes tests for:
Relevant additions are in: Updated result
Conclusion: the previously identified partial-migration recovery issue is fixed in the latest commit. The remaining step is to confirm the latest CI run has completed successfully, particularly against the database driver intended for production. Assessment: Yes — both issues are fixed in the latest PR #56The latest PR head is commit aa42797ab0b0ca3b9160e59ef735b68466aa3abf. Partially migrated schema Status: Fixed HardenPasswordResetTokens.swift now reconciles each hardened column independently. PostgreSQL Uses independent ADD COLUMN IF NOT EXISTS clauses for: code_hash Reads information_schema.COLUMNS, then independently adds every missing column. SQLite Reads PRAGMA table_info(...), then independently adds every missing column. Therefore, a schema containing only code_hash, or any arbitrary subset of hardened columns, should now be completed safely. Missing individual hardened columns Status: Fixed The latest migration no longer gates all additions on the presence of code_hash. This previous failure mode: Text Supporting tests added The PR now includes tests for: recovery from a schema containing only code_hash; HardenPasswordResetTokens.swift Finding Current status |
Resolves P0 security findings: