c2e25edbf8c48361a71398664ec0c279d5fc58f5
braney
Sat Sep 19 18:11:31 2026 -0700
hmacTest: pin the signature hgLogin puts on a pending social identity
hgLogin signs a pending social identity with hmacMd5(login.cookieSalt, fields)
and hands the signature to the browser in the account chooser, so a forgeable
signature lets an attacker choose whose account the chooser links to. Nothing
about the page looks different either way.
Before #37984 that signature was a plain MD5 of the salt concatenated in front
of the same fields, and a hash of a secret followed by attacker-chosen text is
the wrong shape for the job. boundaryMoves() is the case that says so: with
concatenation, hmacMd5("a", "bc") and hmacMd5("ab", "c") hash the same bytes
and sign the same, while HMAC keeps them apart.
Known answers are RFC 2202 test case 2 for MD5 and SHA1, cross-checked here
with the openssl command line. Only the string-keyed vectors from the RFC can
be used, since this interface takes key and data as C strings.
Watched to fail and then pass: putting hmacMd5 back to the concatenation shape
turns the known answer red and makes the two boundary cases identical, both of
which the test catches. Recorded as sandbox-ab in utils/testRegistry.
refs #37984, refs #38391
diff --git src/lib/tests/makefile src/lib/tests/makefile
index 20bbd0ecd38..6af34921040 100644
--- src/lib/tests/makefile
+++ src/lib/tests/makefile
@@ -1,39 +1,47 @@
kentSrc = ../..
include ../../inc/common.mk
MYLIBDIR = ../../lib/${MACHTYPE}
MYLIBS = ${MYLIBDIR}/jkweb.a
BIN_DIR = bin/${MACHTYPE}
pipelineTester = ${BIN_DIR}/pipelineTester
test: errCatchTest htmlPageTest htmlExpandUrlTest htmlSanitizeTest pipelineTests dyStringTest \
mimeTests base64Tests quotedPTests safeTest hashTest fetchUrlTest gff3Test \
tabixTest vcfTest hacTreeTest mmHashTest testSumDoubles jsonQueryTest \
- dnaCodonTest pathSimplifyTest faSpeedReadTest cgiParseTest cgiCookieTest
+ dnaCodonTest pathSimplifyTest faSpeedReadTest cgiParseTest cgiCookieTest \
+ hmacTest
rm -r output fetchUrlTest testSumDoubles
@echo tested all
mkdirs:
${MKDIR} output ${BIN_DIR}
testSumDoubles: testSumDoubles.o ${MYLIBS}
@${MKDIR} $(dir $@)
${CC} ${COPT} -o ./testSumDoubles testSumDoubles.o ${MYLIBS} ${L}
+hmacTest: hmacTest.o ${MYLIBS} mkdirs
+ @${MKDIR} $(dir $@)
+ ${CC} ${COPT} -o ${BIN_DIR}/hmacTest hmacTest.o ${MYLIBS} ${L}
+ ${STRIP} ${BIN_DIR}/hmacTest${EXE}
+ ${BIN_DIR}/hmacTest > output/hmacTest
+ diff expected/hmacTest output/hmacTest
+
pathSimplifyTest: pathSimplifyTest.o ${MYLIBS} mkdirs
@${MKDIR} $(dir $@)
${CC} ${COPT} -o ${BIN_DIR}/pathSimplifyTest pathSimplifyTest.o ${MYLIBS} ${L}
${STRIP} ${BIN_DIR}/pathSimplifyTest${EXE}
${BIN_DIR}/pathSimplifyTest > output/pathSimplifyTest
diff expected/pathSimplifyTest output/pathSimplifyTest
faSpeedReadTest: faSpeedReadTest.o ${MYLIBS} mkdirs
@${MKDIR} $(dir $@)
${CC} ${COPT} -o ${BIN_DIR}/faSpeedReadTest faSpeedReadTest.o ${MYLIBS} ${L}
${STRIP} ${BIN_DIR}/faSpeedReadTest${EXE}
${BIN_DIR}/faSpeedReadTest > output/faSpeedReadTest
diff expected/faSpeedReadTest output/faSpeedReadTest
dnaCodonTest: dnaCodonTest.o ${MYLIBS} mkdirs