Problem/Motivation

The MyrestTokenAuthProvider uses md5() for token verification, which is insecure and susceptible to various attacks.

Proposed resolution

  • Replace md5() with a more secure hashing algorithm (e.g., SHA-256 via hash_hmac).
  • Use hash_equals() for timing-attack-safe comparisons.
  • Consider using Drupal's password service for managing these tokens.

Remaining tasks

Update the authentication provider logic and verify token validation.

User interface changes

None.

API changes

Internal token verification logic change.

Issue fork myrest-3594453

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

sergeydruua created an issue. See original summary.

sergeydruua’s picture

Status: Active » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

sergeydruua’s picture

Status: Fixed » Closed (fixed)