SECURITY: API: Use constant-time comparison for watchlist token
authorBrad Jorsch <bjorsch@wikimedia.org>
Fri, 27 Mar 2015 15:49:58 +0000 (11:49 -0400)
committerChad Horohoe <chadh@wikimedia.org>
Tue, 11 Aug 2015 14:16:57 +0000 (07:16 -0700)
commit00f3e29bfcb80361b588357da0aaea4bce63d198
treed69210eab274dfb62930a26ab7b9fa5c77c03450
parent9aa013b09eaa400dec060e4632a89887c003badd
SECURITY: API: Use constant-time comparison for watchlist token

Avoids a theoretical timing attack.

Bug: T94116
Change-Id: Ia4a2b13bd5d3cd256c6b2deada224148dc2888a6
includes/api/ApiBase.php