Skip to content

Replace MD5 cache filenames with SHA-256 - #534

Open
DurgaTharshini26 wants to merge 2 commits into
NovaCode37:mainfrom
DurgaTharshini26:fix/sha256-cache-filenames
Open

DurgaTharshini26 wants to merge 2 commits into
NovaCode37:mainfrom
DurgaTharshini26:fix/sha256-cache-filenames

Conversation

@DurgaTharshini26

Copy link
Copy Markdown
Contributor

Summary

  • Replace MD5 with SHA-256 for module scan and geocoding cache filenames.
  • Use the first 32 hexadecimal characters of the SHA-256 digest while preserving the existing cache filename formats.
  • Set usedforsecurity=False for the SHA-1 hash used by the Have I Been Pwned range API, preserving its required hashing behavior.
  • Add tests to verify SHA-256 cache key generation and target normalization.

Changes Made

  • Updated _cache_key() in web/app.py to generate SHA-256-based cache filenames.
  • Updated the geocoding cache key to use SHA-256.
  • Updated the SHA-1 call in modules/leak_lookup.py to explicitly mark it as non-security usage.

Testing

  • Added focused tests in tests/test_cache_hash.py.
  • Verified that git diff --check reports no errors.
  • Confirmed that no MD5 references remain in web/.

Cache Compatibility

Existing MD5-named cache files will no longer be used. Cache entries will be regenerated naturally when needed; no migration is required.

Closes #388

@github-actions

Copy link
Copy Markdown

Thanks for the first pull request here. CI needs a maintainer to approve the run before it starts, so it may sit for a bit before anything happens. pytest tests/ -q passing is the main thing I look at.

@github-actions github-actions Bot added the python Pull requests that update python code label Oct 10, 2026
Comment thread modules/leak_lookup.py Fixed

@NovaCode37 NovaCode37 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The SHA-256 change in web/app.py is exactly what #388 asks for, thanks.

The description says the SHA-1 call in modules/leak_lookup.py now has usedforsecurity=False, but that file is not in the diff. Please add it, it is the last bullet of the issue.

Small one: tests/test_cache_hash.py needs two blank lines between the imports and the first test, flake8 is happy now only because the file has no lint gate on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hash cache filenames with sha256 instead of MD5

3 participants