* @brief Constant-time byte-wise equality check that does not short-circuit. */
| 35 | * @brief Constant-time byte-wise equality check that does not short-circuit. |
| 36 | */ |
| 37 | static bool constantTimeEquals(const QByteArray& a, const QByteArray& b) |
| 38 | { |
| 39 | if (a.size() != b.size()) |
| 40 | return false; |
| 41 | |
| 42 | unsigned char diff = 0; |
| 43 | const int n = a.size(); |
| 44 | for (int i = 0; i < n; ++i) |
| 45 | diff |= static_cast<unsigned char>(a[i]) ^ static_cast<unsigned char>(b[i]); |
| 46 | |
| 47 | return diff == 0; |
| 48 | } |
| 49 | |
| 50 | /** |
| 51 | * @brief Generates kSaltLen bytes of cryptographically strong randomness. |
no test coverage detected