NAME
Langertha::Skeid::Secret - Constant-time comparison for keys, tokens and signatures
VERSION
version 0.003
SYNOPSIS
use Langertha::Skeid::Secret;
Langertha::Skeid::Secret->equal($presented_token, $admin_api_key) or return deny();
DESCRIPTION
Every place Skeid checks a presented secret -- the admin API key, the registry read key, a registry snapshot signature -- compares through "equal", never with eq/ne, so a caller cannot recover the secret one character at a time from response timing.
equal
my $ok = Langertha::Skeid::Secret->equal($given, $want);
True (1) when both strings are equal, else 0. It compares the SHA-256 digests of both strings byte by byte without short-circuiting, so the time depends neither on where they first differ nor on either string's length. undef compares as the empty string; callers that must reject an empty or missing secret check that before calling.
SEE ALSO
Langertha::Skeid::Proxy (admin and registry bearer checks), "verify" in Langertha::Skeid::Registry
SUPPORT
Issues
Please report bugs and feature requests on GitHub at https://github.com/Getty/langertha-skeid/issues.
IRC
Join #langertha on irc.perl.org or message Getty directly.
CONTRIBUTING
Contributions are welcome! Please fork the repository and submit a pull request.
AUTHOR
Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/
COPYRIGHT AND LICENSE
This software is copyright (c) 2026 by Torsten Raudssus.
This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.