Closed (fixed)
Project:
MyREST
Version:
1.0.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Reporter:
Created:
9 Jun 2026 at 12:50 UTC
Updated:
9 Jun 2026 at 12:58 UTC
Jump to comment: Most recent
The MyrestTokenAuthProvider uses md5() for token verification, which is insecure and susceptible to various attacks.
md5() with a more secure hashing algorithm (e.g., SHA-256 via hash_hmac).hash_equals() for timing-attack-safe comparisons.password service for managing these tokens.Update the authentication provider logic and verify token validation.
None.
Internal token verification logic change.
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #2
sergeydruua commentedComment #4
sergeydruua commented