util: check RNG error before slicing url-safe random string

A crypto/rand failure sliced empty output and panicked.
This commit is contained in:
Kristoffer Dalby
2026-06-05 14:59:10 +00:00
committed by Kristoffer Dalby
parent ba54349176
commit 84c99023e5
2 changed files with 35 additions and 2 deletions
+24
View File
@@ -0,0 +1,24 @@
package util
import (
"bytes"
"testing"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
// TestEncodeRandomURLSafeChecksErrorFirst ensures the URL-safe random string
// encoder returns ("", err) on an RNG failure instead of slicing the empty
// base64 of nil bytes and panicking.
func TestEncodeRandomURLSafeChecksErrorFirst(t *testing.T) {
require.NotPanics(t, func() {
s, err := encodeRandomURLSafe(nil, 32, assert.AnError)
assert.Empty(t, s)
require.Error(t, err)
})
s, err := encodeRandomURLSafe(bytes.Repeat([]byte{0x1}, 32), 32, nil)
require.NoError(t, err)
assert.Len(t, s, 32)
}