fix(user): equalise login timing for unknown emails #32

Merged
nalum merged 1 commit from fix/login-timing-oracle into main 2026-08-13 11:40:10 +00:00
Owner

Stacked on #29 (fix/login-lockout).

An unknown email returned before any bcrypt compare ran, so timing distinguished registered addresses from unknown ones (~100x) on the anonymous Login surface, despite the uniform response body.

The not-found and closed-account paths now burn the same bcrypt cost against a fixed cost-10 dummy hash before refusing. The lock/gap refusals keep their deliberate no-compare design from #29 (they reveal lock state only to someone who already proved the account exists by triggering misses). A test pins the dummy hash as valid bcrypt at bcrypt.DefaultCost — a malformed literal would silently reopen the oracle.

Fixes #15

🤖 Generated with Claude Code

Stacked on #29 (`fix/login-lockout`). An unknown email returned before any bcrypt compare ran, so timing distinguished registered addresses from unknown ones (~100x) on the anonymous Login surface, despite the uniform response body. The not-found and closed-account paths now burn the same bcrypt cost against a fixed cost-10 dummy hash before refusing. The lock/gap refusals keep their deliberate no-compare design from #29 (they reveal lock state only to someone who already proved the account exists by triggering misses). A test pins the dummy hash as valid bcrypt at `bcrypt.DefaultCost` — a malformed literal would silently reopen the oracle. Fixes #15 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(user): equalise login timing for unknown emails
All checks were successful
check / web (push) Successful in 1m32s
check / go (push) Successful in 1m49s
94c8c7a826
An unknown email returned before the bcrypt compare ran, so timing
distinguished registered addresses from unknown ones on the anonymous
Login surface (~100x faster). The miss path now burns the same bcrypt
cost against a fixed dummy hash before refusing, closing the
enumeration oracle while keeping the uniform response body.

Fixes #15
nalum force-pushed fix/login-timing-oracle from 94c8c7a826
All checks were successful
check / web (push) Successful in 1m32s
check / go (push) Successful in 1m49s
to e66b37aa10
Some checks failed
tag / tag (push) Has been cancelled
check / go (push) Successful in 1m49s
check / web (push) Successful in 1m26s
2026-08-13 11:33:33 +00:00
Compare
nalum changed target branch from fix/login-lockout to main 2026-08-13 11:33:55 +00:00
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:34:07 +00:00
nalum merged commit e66b37aa10 into main 2026-08-13 11:40:10 +00:00
nalum deleted branch fix/login-timing-oracle 2026-08-13 11:40:10 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!32
No description provided.