mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-02 12:45:31 +02:00
* fix(encryption): return an error instead of panicking on a short GCM ciphertext gcmCipher.Decrypt slices ciphertext[:nonceSize] without first checking the length, so a ciphertext shorter than the 12-byte GCM nonce triggers a slice-bounds-out-of-range panic instead of returning an error. The sibling cfbCipher.Decrypt already guards its IV length and returns a descriptive error; mirror that guard for GCM so decrypting a malformed (e.g. truncated) cookie fails cleanly. Adds a test covering both ciphers. Signed-off-by: Madan Kumar <winklemad@outlook.com> * docs(changelog): add entry for the GCM short-ciphertext fix Signed-off-by: Madan Kumar <winklemad@outlook.com> --------- Signed-off-by: Madan Kumar <winklemad@outlook.com>