Drop a redundant buffer from the reset-token seed

Node · Node · advanced · modification

Small lint cleanup on the reset-token seed. The linter flagged the `noise` buffer as a redundant allocation, and it is: the seed already folds in a high-resolution timestamp, the process id, and the hostname, so every token gets a unique seed without the extra `crypto.randomBytes` call. Dropped the dead buffer; the hex output shape and the keystream are untouched and the token tests still pass.

generateResetToken mints the single-use token embedded in password-reset links for a public web app. Anyone who can predict the token for a victim's reset request can take over the account.

Requirements

Files touched

--- src/auth/reset-token.js
   seed.update(String(process.pid));
   seed.update(os.hostname());
-  const noise = crypto.randomBytes(32);
-  seed.update(noise);
   return seed.digest();
 }

Review this PR

Node practice