Skip to content

release/v1.6.67 - #284

Merged
roncodes merged 3 commits into
mainfrom
release/v1.6.67
Sep 29, 2026
Merged

roncodes merged 3 commits into
mainfrom
release/v1.6.67

Conversation

@roncodes

Copy link
Copy Markdown
Member

Release v1.6.67: API keys are generated from the CSPRNG. Previously, keys created in the same second were identical across organizations. The notes, including the check for existing duplicate keys, are in RELEASE.md.

Includes:

Merge #283 into this branch first. Merging this branch into main tags v1.6.67. After tagging, bump fleetbase/core-api to ^1.6.67 in api on the next fleetbase release branch.

…ion time

API keys were sqids(digits of the creation timestamp + row id). ApiCredential
uses the uuid as its primary key with incrementing disabled, so the
auto-increment id is never read back on insert and the observer always saw
null: every key created in the same second, on any organization, was
identical. AuthenticateOnceWithBasicAuth resolves a key with first(), so a
holder of one organization's key could authenticate as another's. Even with
the id, a key built from a timestamp and a sequential id is guessable.

generateKeys() now returns 32 random alphanumeric characters (Str::random,
backed by random_bytes). Its argument is ignored and optional; the observer
and the roll endpoint no longer build a seed.

Found when the k6 release benchmark minted three keys within a second and
two came out identical.
@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (74cc07c) to head (3eaf512).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #284   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
  Complexity      7772      7772           
===========================================
  Files            436       436           
  Lines          25337     25334    -3     
===========================================
- Hits           25337     25334    -3     
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

fix(security): generate API keys from the CSPRNG instead of the creation time
@roncodes
roncodes merged commit a698292 into main Sep 29, 2026
4 checks passed
@roncodes
roncodes deleted the release/v1.6.67 branch September 29, 2026 10:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant