fix: use explicit OS entropy for assistant and wallet IDs
This commit is contained in:
@@ -23,7 +23,6 @@ use std::sync::atomic::{AtomicU64, Ordering};
|
||||
use std::sync::{Arc, Mutex, OnceLock};
|
||||
use std::time::Duration;
|
||||
|
||||
use rand::RngCore;
|
||||
use serde_json::json;
|
||||
use sha2::{Digest, Sha256};
|
||||
use tokio::sync::oneshot;
|
||||
@@ -227,7 +226,9 @@ pub fn global() -> Arc<ConfirmGate> {
|
||||
/// nonce for the same action never matches today's pending entry).
|
||||
pub fn mint_nonce(tool_name: &str, validated_args: &str) -> String {
|
||||
let mut salt = [0u8; 16];
|
||||
rand::thread_rng().fill_bytes(&mut salt);
|
||||
crate::entropy::draw_key_bytes(&mut rand::rngs::OsRng, &mut salt).unwrap_or_else(|e| {
|
||||
panic!("refusing to mint a confirmation nonce from degenerate entropy: {e} (KEY-05)")
|
||||
});
|
||||
let mut hasher = Sha256::new();
|
||||
hasher.update(salt);
|
||||
hasher.update(tool_name.as_bytes());
|
||||
|
||||
@@ -30,7 +30,7 @@ pub const TOKEN_LEN: usize = 8;
|
||||
/// wrapped. Called exactly once per [`UntrustedBlock::new`] /
|
||||
/// [`wrap_untrusted`] invocation.
|
||||
fn fresh_token() -> String {
|
||||
rand::thread_rng()
|
||||
rand::rngs::OsRng
|
||||
.sample_iter(Alphanumeric)
|
||||
.take(TOKEN_LEN)
|
||||
.map(char::from)
|
||||
|
||||
@@ -474,7 +474,7 @@ async fn ensure_token(
|
||||
|
||||
/// Draw a fresh readable wallet name, Minibits-style: adjective + noun + number.
|
||||
fn generate_wallet_id() -> String {
|
||||
let mut rng = rand::thread_rng();
|
||||
let mut rng = rand::rngs::OsRng;
|
||||
let adj = ADJECTIVES.choose(&mut rng).copied().unwrap_or("quiet");
|
||||
let noun = NOUNS.choose(&mut rng).copied().unwrap_or("harbor");
|
||||
let num = rand::Rng::gen_range(&mut rng, 1..=999);
|
||||
|
||||
Reference in New Issue
Block a user