From: Rich Kilmer Date: 2002-02-14T14:27:03+09:00 Subject: RE: IOWA troubles (was Re: choice of HTML templating system) > -----Original Message----- > From: Rich Kilmer [mailto:rich@infoether.com] > Sent: Thursday, February 14, 2002 12:19 AM > To: ruby-talk ML > Subject: RE: IOWA troubles (was Re: choice of HTML templating system) > > Actually, my last code was incorrect. You don't need salt (random data)...just the time_sha. You DO want to make the server_key a very big and random piece of data however so it cannot be guessed. require 'digest/sha1' include Digest @server_key = "secret1231243242133123" @timeout = 2 # seconds def token t = Time.new time = t.to_i.to_s+"."+t.usec.to_s hash = SHA1.new("#{time}:#{@server_key}").hexdigest token = "#{time}_#{hash}" end def token_valid?(token) t = Time.new time = t.to_i.to_s+"."+t.usec.to_s token.scan(/(.*)_(.*)/) do |t_time, t_hash| valid_hash = SHA1.new("#{t_time}:#{@server_key}").hexdigest return (t_hash == valid_hash) && (time.to_f - t_time.to_f < @timeout) end false end t = token sleep 1 puts token_valid?(t) #=> true t[0..2]="00" puts token_valid?(t) #=> false ... hash fails