Skip to content

auth: deflake constant-time login test - #422

Merged
espadonne merged 2 commits into
trunkfrom
fix/login-timing-test-flake
Sep 2, 2026
Merged

espadonne merged 2 commits into
trunkfrom
fix/login-timing-test-flake

Conversation

@espadonne

Copy link
Copy Markdown
Contributor

TestLogin_ConstantTime compared mean request latency of an existing-user vs missing-user login with a 5x bound. The existing-user path also does throttle/audit DB writes, so under parallel CI load against the shared Postgres it failed (existing=66ms, missing=11ms) on an unrelated PR (#421).

The property that matters is that the missing-user branch still pays for an argon2 verify. The test now measures that cost directly and asserts the missing-user median is at least half of it, keeping only a loose 10x divergence bound on medians.

  • auth: make constant-time login test measure hash cost instead of request ratio

Test targets:

  • CI Integration step: internal/web/handlers/auth green

@espadonne
espadonne merged commit 5bbad0b into trunk Sep 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants