Summary
KeyRotationService.generateConfirmationToken builds its nonce with Math.random().toString(36), and generateIdempotencyKey in idempotency.ts also relies on Math.random, despite comments about cryptographic security.
Why this matters
Math.random is predictable; if these values are ever used for anti-replay or dedup across users, collisions and guessing become possible.
Scope
Use crypto.getRandomValues (or crypto.randomUUID) for nonces and idempotency keys with a fallback only in non-browser tests. Update comments to match reality.
Relevant code in CalloraOrg/Callora-Frontend:
src/services/KeyRotationService.ts
src/services/idempotency.ts
Priority
High
Acceptance criteria
- No Math.random call remains in KeyRotationService or idempotency
- Nonces are at least 128 bits
- Existing tests pass with crypto mocked where needed
- Comments no longer overstate security
Validation
npm test -- --run src/services/KeyRotationService.test.ts src/services/idempotency.test.ts src/services/KeyRotation.adversarial.test.ts
Non-goals
- Typo-only, formatting-only, or cosmetic changes.
- Unrelated refactors, dependency upgrades, or broad rewrites.
- Removing safeguards or weakening validation to make tests pass.
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.
Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code
Summary
KeyRotationService.generateConfirmationToken builds its nonce with Math.random().toString(36), and generateIdempotencyKey in idempotency.ts also relies on Math.random, despite comments about cryptographic security.
Why this matters
Math.random is predictable; if these values are ever used for anti-replay or dedup across users, collisions and guessing become possible.
Scope
Use crypto.getRandomValues (or crypto.randomUUID) for nonces and idempotency keys with a fallback only in non-browser tests. Update comments to match reality.
Relevant code in CalloraOrg/Callora-Frontend:
src/services/KeyRotationService.tssrc/services/idempotency.tsPriority
High
Acceptance criteria
Validation
npm test -- --run src/services/KeyRotationService.test.ts src/services/idempotency.test.ts src/services/KeyRotation.adversarial.test.ts
Non-goals
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include
Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code