3 ms·
Not very too level. I had to take that into consideration at some parts. For example, the static username_password provider calls a hasher defined in Caddy whic
by m_sahaf 5y ago
Not very too level. I had to take that into consideration at some parts. For example, the static username_password provider calls a hasher defined in Caddy which uses `subtle.ConstantTimeCompare` function used. At other places, I don't return early (when possible) on auth failures to avoid timing attacks. That said, I'd love to know if there are places where I fell short.