davsclaus opened a new pull request, #27504:
URL: https://github.com/apache/camel/pull/27504

   Follow-up to 
[CAMEL-24440](https://issues.apache.org/jira/browse/CAMEL-24440) (#26725), from 
the review note on the 4.22.x backport #27490.
   
   #26725 made a bad-padding message and a bad-MAC message report the same 
`Message authentication failed`. The two paths still did different work at the 
end, though. The bad-MAC path finalizes the HMAC and runs the constant-time 
compare, while the bad-padding path threw straight from the `catch` block.
   
   The padding-failure path now calls `HMACAccumulator.validate(true)`. It 
finalizes and compares the MAC in the same way, then always fails with the same 
message. Both failures now take the same final step.
   
   `CipherInputStream` only checks the padding at `doFinal` when the stream 
reaches EOF. So both paths have already read and run the whole message through 
the HMAC before this point, and the finalization and compare were the step that 
differed.
   
   - No change to the data format or to the error message. `validate()` keeps 
its behaviour, and the new overload is package-private.
   - Added 
`HMACAccumulatorTest.testValidateAfterCipherFailureStillComputesMacAndFails`. 
`camel-crypto` runs 87 tests with 0 failures.
   
   _Claude Code on behalf of davsclaus_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to