NAME

Langertha::Skeid::Secret - Constant-time comparison for keys, tokens and signatures

VERSION

version 0.003

SYNOPSIS

use Langertha::Skeid::Secret;
Langertha::Skeid::Secret->equal($presented_token, $admin_api_key) or return deny();

DESCRIPTION

Every place Skeid checks a presented secret -- the admin API key, the registry read key, a registry snapshot signature -- compares through "equal", never with eq/ne, so a caller cannot recover the secret one character at a time from response timing.

equal

my $ok = Langertha::Skeid::Secret->equal($given, $want);

True (1) when both strings are equal, else 0. It compares the SHA-256 digests of both strings byte by byte without short-circuiting, so the time depends neither on where they first differ nor on either string's length. undef compares as the empty string; callers that must reject an empty or missing secret check that before calling.

SEE ALSO

Langertha::Skeid::Proxy (admin and registry bearer checks), "verify" in Langertha::Skeid::Registry

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/langertha-skeid/issues.

IRC

Join #langertha on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.