mirror of
https://github.com/suitenumerique/meet.git
synced 2026-08-06 17:07:46 +00:00
🔒️(frontend) room ids are generated with non-cryptographic rand
Room identifiers are created with `Math.random()`, which is predictable and not suitable for security-sensitive identifiers. Predictable room IDs increase the risk of room enumeration and unauthorized access attempts, especially when IDs are part of join URLs. Affected files: generateRoomId.ts Signed-off-by: tuanaiseo <221258316+tuanaiseo@users.noreply.github.com>
This commit is contained in:
committed by
aleb_the_flash
parent
cd7799997e
commit
fc260b2686
@@ -1,10 +1,20 @@
|
||||
// Google Meet uses only letters in a room identifier
|
||||
const ROOM_ID_ALLOWED_CHARACTERS = 'abcdefghijklmnopqrstuvwxyz'
|
||||
|
||||
const getRandomChar = () =>
|
||||
ROOM_ID_ALLOWED_CHARACTERS[
|
||||
Math.floor(Math.random() * ROOM_ID_ALLOWED_CHARACTERS.length)
|
||||
const getRandomChar = () => {
|
||||
const maxValue =
|
||||
Math.floor(0x100000000 / ROOM_ID_ALLOWED_CHARACTERS.length) *
|
||||
ROOM_ID_ALLOWED_CHARACTERS.length
|
||||
const randomValue = new Uint32Array(1)
|
||||
|
||||
do {
|
||||
crypto.getRandomValues(randomValue)
|
||||
} while (randomValue[0] >= maxValue)
|
||||
|
||||
return ROOM_ID_ALLOWED_CHARACTERS[
|
||||
randomValue[0] % ROOM_ID_ALLOWED_CHARACTERS.length
|
||||
]
|
||||
}
|
||||
|
||||
const generateSegment = (length: number): string =>
|
||||
Array.from(Array(length), getRandomChar).join('')
|
||||
|
||||
Reference in New Issue
Block a user