Skip to content

Commit

Permalink
It's not necessary to trim the output of generate_key
Browse files Browse the repository at this point in the history
Provide the key_length to the generate_key method instead

This is the correct usage of generate_key regardless of Ruby version
  • Loading branch information
jcoyne committed Jan 22, 2024
1 parent 7ff508d commit 73fe6d1
Showing 1 changed file with 2 additions and 7 deletions.
9 changes: 2 additions & 7 deletions app/controllers/concerns/blacklight/token_based_user.rb
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ def encrypt_user_id(user_id, current_time = nil)
end

def export_secret_token
secret_key_generator.generate_key('encrypted user session key')[0..(key_len - 1)]
secret_key_generator.generate_key('encrypted user session key', key_len)
end

def secret_key_generator
Expand All @@ -56,12 +56,7 @@ def message_encryptor
ActiveSupport::MessageEncryptor.new(export_secret_token)
end

# Ruby 2.4 requires keys of very particular lengths
def key_len
if ActiveSupport::MessageEncryptor.respond_to? :key_len
ActiveSupport::MessageEncryptor.key_len
else
0
end
ActiveSupport::MessageEncryptor.key_len
end
end

0 comments on commit 73fe6d1

Please sign in to comment.