Compare commits

..

2 Commits
4.1.1 ... 4.1.2

Author SHA1 Message Date
Alex Bilbie
19b64c2e65 Merge pull request #290 from sarciszewski/patch-1
Remove side-effects in hash_equals()
2015-01-01 12:52:03 +00:00
Scott Arciszewski
612775466c Remove side-effects in hash_equals()
This is functionally identical, but without the side-effect of defining a function in the current namespace.

Also, it uses absolute function reference (`\hash_equals` instead of `hash_equals`) because if someone defined `League\OAuth2\Server\TokenType\hash_equals()` elsewhere, it would try that first.

Kudos for using `hash_equals()` in your original design for this feature. Many OAuth2 implementations neglect this nuance :)
2015-01-01 01:34:22 -05:00

View File

@@ -128,9 +128,9 @@ class MAC extends AbstractTokenType implements TokenTypeInterface
*/ */
private function hash_equals($knownString, $userString) private function hash_equals($knownString, $userString)
{ {
if (!function_exists('hash_equals')) { if (function_exists('\hash_equals')) {
function hash_equals($knownString, $userString) return \hash_equals($knownString, $userString);
{ }
if (strlen($knownString) !== strlen($userString)) { if (strlen($knownString) !== strlen($userString)) {
return false; return false;
} }
@@ -142,8 +142,4 @@ class MAC extends AbstractTokenType implements TokenTypeInterface
// They are only identical strings if $result is exactly 0... // They are only identical strings if $result is exactly 0...
return 0 === $result; return 0 === $result;
} }
}
return hash_equals($knownString, $userString);
}
} }