From 52c4f646559bd88d626e3f014374937550af2e92 Mon Sep 17 00:00:00 2001 From: Joel Biddle Date: Tue, 22 Aug 2023 23:36:24 +1000 Subject: [PATCH] Removed log and fixed comments --- .../utilities/checks/checkIsPasswordBreached.ts | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/frontend/src/components/utilities/checks/checkIsPasswordBreached.ts b/frontend/src/components/utilities/checks/checkIsPasswordBreached.ts index fba537977..56b70c5c1 100644 --- a/frontend/src/components/utilities/checks/checkIsPasswordBreached.ts +++ b/frontend/src/components/utilities/checks/checkIsPasswordBreached.ts @@ -4,9 +4,9 @@ import crypto from "crypto"; // added types from @types/node export const checkIsPasswordBreached = async (password: string) => { // see API details here: https://haveibeenpwned.com/API/v3#SearchingPwnedPasswordsByRange // in short, the pending password is hashed (SHA-1), the first 5 chars are sliced and compared against a ranged hash table - // if there is a match, that password has been involved in a password breach and should not be accepted + // if there is a match, that password has been involved in a password breach and should NOT be accepted - // the database consists of ~700 mln breached passwords and is continuously updated + // the database consists of ~700 mln breached passwords and is continuously updated, including with law enforcement ingestion // https://www.troyhunt.com/open-source-pwned-passwords-with-fbi-feed-and-225m-new-nca-passwords-is-now-live/ const dataBreachCheckAPIBaseURL = "https://api.pwnedpasswords.com/range/"; // added to CSP @@ -21,16 +21,16 @@ export const checkIsPasswordBreached = async (password: string) => { .join("") .toUpperCase(); - const hashedPwdToSend = hashedPwd.slice(0, 5); // ONLY the first five SHA-1 hash chars are sent over HTTPS (the whole string can be sent but that's not very secure due to SHA-1 flaws) + // ONLY the first five SHA-1 hash chars need to be sent (must be over HTTPS) + const hashedPwdToSend = hashedPwd.slice(0, 5); const response = await axios.get(`${dataBreachCheckAPIBaseURL}${hashedPwdToSend}`); const responseData = response.data.toUpperCase(); - const isBreachedPassword = responseData.includes(hashedPwd.slice(5, 40)); // compare against the API's ranged db's hash table - - console.log("isBreachedPassword:", isBreachedPassword); // remove log later - // Clear the hashed password from memory + // compare against the API's ranged db's hash table + const isBreachedPassword = responseData.includes(hashedPwd.slice(5, 40)); + // Clear the hashed password from memory as a precaution const zeroBuffer = new Uint8Array(encodedPwd.length); encodedPwd.set(zeroBuffer); @@ -39,7 +39,7 @@ export const checkIsPasswordBreached = async (password: string) => { if (axios.isAxiosError(err) && err.response && err.response.status === 429) { console.error("Received a 429 response from the Pwnd Passwords API"); // Handle the 429 error here (not 100% sure what the rate limits are for the password API but looks like <10 calls/min) - // an error here should not cause the setting/resetting/changing password to fail (unless desired) + // an error here should probably not cause the setting/resetting/changing password to fail (unless desired) } else { console.error(err); }