99designs / http-signatures-php

Sign and verify PSR-7 HTTP messages in PHP.
MIT License
44 stars 32 forks source link

[2.x backport] Avoid timing side-channels in signature validation #30

Closed afk11 closed 7 years ago

afk11 commented 7 years ago

See https://github.com/99designs/http-signatures-php/pull/28

joho commented 7 years ago

Great, thanks. We'll get this released today. Very much appreciated.

rbone commented 7 years ago

I've just created a new release for this as 2.0.5. Thanks again @afk11.