Skip to content

Fix predictable conversation share hash - #417

Open
carfeii wants to merge 1 commit into
coaidev:mainfrom
carfeii:fix/predictable-share-hash
Open

carfeii wants to merge 1 commit into
coaidev:mainfrom
carfeii:fix/predictable-share-hash

Conversation

@carfeii

@carfeii carfeii commented Sep 15, 2026

Copy link
Copy Markdown

Fixes #416

Replaces the derived MD5 conversation-share hash (md5(user_id, conversation_id, refs)) with a cryptographically random 128-bit token (utils.GenerateRandomHash, via crypto/rand), since the old hash could be recomputed by anyone who knew or guessed a user's sequential user_id and a plausible conversation_id, letting them view that user's shared conversation without ever receiving the link.

ShareConversation now looks up an existing sharing row for a (user_id, conversation_id) pair via SELECT to decide whether to reuse its hash (updating refs) or mint a new random one, instead of relying on the old hash being reproducible to trigger ON DUPLICATE KEY UPDATE. The now-unused SharedHashForm type was removed.

Verified go build ./... succeeds with no regressions, and no other caller of ShareConversation/GetRef exists in the codebase.

The share link hash was md5(user_id, conversation_id, refs), fully
derivable from the sharer's sequential user id and conversation id
with no random component, letting anyone who guesses those ids
recompute a valid share hash and view another user's shared
conversation without ever receiving the link.

Generate a random 128-bit token instead, and reuse an existing share
row for a conversation by looking it up (user_id, conversation_id)
rather than relying on the hash itself being reproducible.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Conversation share links use a predictable, guessable hash instead of a random secret

1 participant