All changes are localized to RemoteWebServer plus two small helpers; the Phase 0 characterization tests confirm routing, JSON/Prometheus shape, and credential pass/fail semantics are otherwise unchanged. - Password hashing: new PasswordHasher uses PBKDF2-HMAC-SHA256 with a per-credential random salt (self-describing pbkdf2$iters$salt$hash). Verify() still accepts the legacy unsalted SHA-256 hex hash and a successful legacy auth transparently upgrades the stored hash, persisted by the view model on save/shutdown. Property renamed PasswordSHA256 -> PasswordHash. - Constant-time comparison: CredentialComparer.FixedTimeEquals for the user name and password hash; both are evaluated fully (no && short-circuit). - No information disclosure: POST failures return a generic message instead of ex.ToString(); detail is logged server-side only. - Bind intent respected: ResolveListenerIp no longer mutates ListenerIp or silently falls back to all-interfaces for a specific configured address (auto/'?'/wildcards still bind all). A bad address now fails Start(). - CORS: removed the Access-Control-Allow-Origin '*' wildcard; common response headers centralized in WriteCommonHeaders. - Prometheus: label values are escaped (EscapePrometheusLabel). 185 tests pass (was 167). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
28 lines
905 B
C#
28 lines
905 B
C#
// This Source Code Form is subject to the terms of the Mozilla Public License, v. 2.0.
|
|
// If a copy of the MPL was not distributed with this file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
// Copyright (C) LibreHardwareMonitor and Contributors.
|
|
|
|
using LibreHardwareMonitor.Windows.WinUI.Services;
|
|
using Xunit;
|
|
|
|
namespace LibreHardwareMonitor.Windows.WinUI.Tests.Services;
|
|
|
|
public class CredentialComparerTests
|
|
{
|
|
[Fact]
|
|
public void FixedTimeEquals_EqualStrings_ReturnsTrue()
|
|
{
|
|
Assert.True(CredentialComparer.FixedTimeEquals("admin", "admin"));
|
|
}
|
|
|
|
[Theory]
|
|
[InlineData("admin", "Admin")]
|
|
[InlineData("admin", "root")]
|
|
[InlineData("admin", "administrator")]
|
|
[InlineData("", "x")]
|
|
public void FixedTimeEquals_DifferentStrings_ReturnsFalse(string left, string right)
|
|
{
|
|
Assert.False(CredentialComparer.FixedTimeEquals(left, right));
|
|
}
|
|
}
|