Skip to content

fix(security): resolve CodeQL hard-coded-crypto alerts in portal auth - #108

Merged
chinkan merged 1 commit into
mainfrom
security/fix-portal-auth-codeql
Sep 29, 2026
Merged

chinkan merged 1 commit into
mainfrom
security/fix-portal-auth-codeql

Conversation

@chinkan

@chinkan chinkan commented Sep 29, 2026

Copy link
Copy Markdown
Owner

What

Resolves CodeQL rust/hard-coded-cryptographic-value alerts #22 and #23 in src/portal/auth.rs.

Root cause

signing_secret() materialised the 32-byte HMAC signing key from a zero-initialised [0u8; 32] buffer on both paths:

Line Path Old code
136 read portal_secret.key let mut buf = [0u8; 32]; hex_decode_32(..., &mut buf)
143 create key let mut buf = [0u8; 32]; fill_bytes(&mut rng, &mut buf)

The constant value flows into Hmac::<Sha256>::new_from_slice(...) (auth.rs:240 / :255), so CodeQL flags it as a hard-coded key. The values were always overwritten first — this is a false positive in practice, but the pattern is what the rule is designed to catch, and it is trivially avoidable.

Fix (same proven pattern as PR #100)

  • hex_decode_32(raw) -> Option<[u8; 32]> now parses into a fresh Vec<u8> then <[u8;32]>::try_from(...) — the key is never materialised from a constant-initialised buffer.
  • the create path draws the key directly from the OS CSPRNG with rand::rng().random().

Behaviour is identical: same 32-byte key, same on-disk hex format, same corrupt-file rejection, cookies still stable across restarts.

Verification

Check Result
cargo fmt clean
cargo clippy --all-targets -- -D warnings clean
cargo test 792 passed / 0 failed
portal::auth unit tests 6/6 (incl. hex_decode_32_roundtrip, cookie_sign_verify_roundtrip_and_tamper)
tests/portal_api.rs 62/62 (incl. cookie_survives_new_state_same_home)

CodeQL will re-scan this PR ref; expected rust findings drop from 5 → 3 (the 3 test-only alerts remain and are dismissed separately).

Related

Resolves rust/hard-coded-cryptographic-value alerts #22 and #23.
The signing key was materialised from a zero-initialised [0u8; 32]
buffer (read path via hex_decode_32, create path via fill_bytes),
which CodeQL flags because the constant value flows into the
Hmac<Sha256> key at auth.rs:240/255.

Apply the proven PR #100 pattern:
- hex_decode_32 now returns Option<[u8;32]> built from a fresh Vec,
  then try_from (no constant-initialised buffer).
- the create path draws the key directly with rand::rng().random().

Behaviour is identical: same 32-byte key, same on-disk hex format,
same corrupt-file rejection, cookies still stable across restarts.
@chinkan
chinkan merged commit 6e24388 into main Sep 29, 2026
14 checks passed
@chinkan
chinkan deleted the security/fix-portal-auth-codeql branch September 29, 2026 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant