fix(user): equalise login timing for unknown emails #32
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!32
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/login-timing-oracle"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stacked on #29 (
fix/login-lockout).An unknown email returned before any bcrypt compare ran, so timing distinguished registered addresses from unknown ones (~100x) on the anonymous Login surface, despite the uniform response body.
The not-found and closed-account paths now burn the same bcrypt cost against a fixed cost-10 dummy hash before refusing. The lock/gap refusals keep their deliberate no-compare design from #29 (they reveal lock state only to someone who already proved the account exists by triggering misses). A test pins the dummy hash as valid bcrypt at
bcrypt.DefaultCost— a malformed literal would silently reopen the oracle.Fixes #15
🤖 Generated with Claude Code
94c8c7a826e66b37aa10