[grade=A] DC-085: Replace Math.random() with crypto for security-sensitive IDs
CI / Test & Lint (push) Canceled after 0s
CI / Security audit (push) Canceled after 0s

- port-lock-manager.js: lockId uses crypto.randomBytes(8) instead of Math.random()
- openclaw.js: generateToken() uses crypto.randomBytes(24).toString('base64url') — 192 bits entropy
- Sampling uses (health-checker 5%, resource-monitor 10%) intentionally left as Math.random

Codex grade: A (21,294 tokens). All 1539 tests pass.
This commit is contained in:
Hermes
2026-08-12 04:45:19 -07:00
parent cdf9e8d3ef
commit a1d7208686
2 changed files with 4 additions and 7 deletions
+2 -6
View File
@@ -1,5 +1,6 @@
const express = require('express');
const http = require('http');
const crypto = require('crypto');
const { ok, errorResponse, notFound, conflict } = require('../src/utils/responses');
/**
@@ -263,10 +264,5 @@ module.exports = function openClawRoutes(ctx) {
// ── token generator ──────────────────────────────────────────────────────────
function generateToken() {
const chars = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';
let result = '';
for (let i = 0; i < 32; i++) {
result += chars.charAt(Math.floor(Math.random() * chars.length));
}
return result;
return crypto.randomBytes(24).toString('base64url');
}