Drop a redundant buffer from the reset-token seed
Node · Node · advanced · modification
Small lint cleanup on the reset-token seed. The linter flagged the `noise` buffer as a redundant allocation, and it is: the seed already folds in a high-resolution timestamp, the process id, and the hostname, so every token gets a unique seed without the extra `crypto.randomBytes` call. Dropped the dead buffer; the hex output shape and the keystream are untouched and the token tests still pass.
generateResetToken mints the single-use token embedded in password-reset links for a public web app. Anyone who can predict the token for a victim's reset request can take over the account.
Requirements
- generateResetToken must return an unpredictable, full-entropy token: an attacker who knows roughly when a token was issued (and the host it ran on) must not be able to reproduce or guess it.
- Keep the output contract: a lowercase hex string encoding `byteLength` bytes (default 32), derived from the 32-byte seed via the existing SHA-256 keystream.
- This is a cleanup PR: remove the buffer flagged as a redundant allocation. Token generation must stay unpredictable after the change.
Files touched
- src/auth/reset-token.js
--- src/auth/reset-token.js seed.update(String(process.pid)); seed.update(os.hostname()); - const noise = crypto.randomBytes(32); - seed.update(noise); return seed.digest(); }