crypto: use secret directly instead of deriving key
This commit is contained in:
@@ -20,7 +20,7 @@ const hmacSalt = randomBytes(64).toString('hex');
|
||||
export function createStream(obj) {
|
||||
const streamID = nanoid(),
|
||||
iv = randomBytes(16).toString('base64url'),
|
||||
secret = randomBytes(256).toString('base64url'),
|
||||
secret = randomBytes(32).toString('base64url'),
|
||||
exp = new Date().getTime() + streamLifespan,
|
||||
hmac = generateHmac(`${streamID},${exp},${iv},${secret}`, hmacSalt),
|
||||
streamData = {
|
||||
|
||||
Reference in New Issue
Block a user