Skip to content

Commit 0930414

Browse files
paragonie-securitynbaars
authored andcommitted
Use MessageDigest.isEqual() instead of Array.equals()
1 parent 8038a1d commit 0930414

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

version1/src/main/java/org/paseto4j/version1/PasetoLocal.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -116,7 +116,7 @@ static String decrypt(SecretKey key, String token, String footer) {
116116

117117
//1
118118
if (!isNullOrEmpty(footer)) {
119-
verify(Arrays.equals(getUrlDecoder().decode(tokenParts[3]), footer.getBytes(UTF_8)), "footer does not match");
119+
verify(MessageDigest.isEqual(getUrlDecoder().decode(tokenParts[3]), footer.getBytes(UTF_8)), "footer does not match");
120120
}
121121

122122
//2

0 commit comments

Comments
 (0)