• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

mattupstate / flask-security / 874
28%

Build:
DEFAULT BRANCH: develop
Ran 06 Oct 2017 11:02AM UTC
Jobs 6
Files 20
Run time 6min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
874

push

travis-ci

Jiri Kuncar
Fix timing attack on login form

As detailed in #357 the time it takes to process a login request is
considerably less if the user specified doesn't exist than if the
password is incorrect. This can be used as a user enumeration attack,
even if the login error messages were customized to avoid this.

I fixed it by increasing the response time of a non-existing user
request by hashing the given password anyway (if using good
password hashing algorithm this is what takes a relatively
large amount of time and makes the attack possibly).

closes #357

3 of 3 new or added lines in 1 file covered. (100.0%)

1360 of 1448 relevant lines covered (93.92%)

5.63 hits per line

Jobs
ID Job ID Ran Files Coverage
1 874.1 (REQUIREMENTS=lowest) 06 Oct 2017 11:02AM UTC 0
93.92
Travis Job 874.1
2 874.2 (REQUIREMENTS=release) 06 Oct 2017 11:03AM UTC 0
93.65
Travis Job 874.2
3 874.3 (REQUIREMENTS=lowest) 06 Oct 2017 11:07AM UTC 0
93.92
Travis Job 874.3
4 874.4 (REQUIREMENTS=release) 06 Oct 2017 11:08AM UTC 0
93.65
Travis Job 874.4
5 874.5 (REQUIREMENTS=lowest) 06 Oct 2017 11:08AM UTC 0
93.92
Travis Job 874.5
6 874.6 (REQUIREMENTS=release) 06 Oct 2017 11:09AM UTC 0
93.65
Travis Job 874.6
Source Files on build 874
Detailed source file information is not available for this build.
  • Back to Repo
  • Travis Build #874
  • 59c0fb7b on github
  • Prev Build on develop (#873)
  • Next Build on develop (#875)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc