Skip to content

Safer ExternalPermutationWorkerFactory connections#10257

Open
niloc132 wants to merge 1 commit intogwtproject:mainfrom
niloc132:10256-safer-epwf-test
Open

Safer ExternalPermutationWorkerFactory connections#10257
niloc132 wants to merge 1 commit intogwtproject:mainfrom
niloc132:10256-safer-epwf-test

Conversation

@niloc132
Copy link
Member

Cookies are now sent/received as 32 ascii chars before any ObjectOutputStream data is sent, and the server validates before returning the socket. An invalid socket is closed and ignored, and the next valid socket will be used instead.

Also improved cookie randomness source.

Fixes #10256

Cookies are now sent/received as 32 ascii chars before any
ObjectOutputStream data is sent, and the server validates before
returning the socket. An invalid socket is closed and ignored, and the
next valid socket will be used instead.

Also improved cookie randomness source.

Fixes gwtproject#10256
@niloc132 niloc132 marked this pull request as ready for review February 12, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Investigate options to make ExternalPermutationWorkerFactory more safe

1 participant