grafana/k6

webcrypto: Throw exception on `saltLength: 0` for RSA PSS sign/verify

Open

#4265 aperta il 30 ott 2024

Vedi su GitHub
 (14 commenti) (0 reazioni) (1 assegnatario)Go (1537 fork)batch import
area: webcryptogood first issuehelp wanted

Metriche repository

Star
 (30.564 star)
Metriche merge PR
 (Merge medio 11g 15h) (47 PR mergiate in 30 g)

Descrizione

What?

While implementing support of RSA grafana/xk6-webcrypto#85 we've found that standard Golang's SDK doesn't provide support of the saltLength: 0, instead it always tries to generate salt with the maximum length.

This led us for the patch to WebPlatfrom tests: https://github.com/grafana/xk6-webcrypto/blob/main/webcrypto/tests/wpt-patches/WebCryptoAPI__sign_verify__rsa.js.patch

Since some use cases could actually try to use the lengths of salt 0 we need to issue a log warning user that the actual behavior of our implementation is different.

edit(@mstoykov): After some discussion the idea is currently to throw an exception instead of just log a warning.

Why?

It improves UX and makes implementation predictable.

Guida contributor