🛡️ Sentinel: [HIGH] Fix Event Loop Blocking DoS in Auth - #111
Conversation
…readpool Co-authored-by: benpiper <4343814+benpiper@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Severity: HIGH
Vulnerability: CPU-bound operations (like bcrypt hashing) were running directly in
asyncroute handlers.Impact: Because bcrypt operations are computationally intensive, doing them directly inside an
async deffunction blocks the FastAPI asyncio event loop. This leads to a severe performance degradation and opens the application up to Denial of Service (DoS) attacks, as it stops the server from handling concurrent requests during the hashing process.Fix: Offloaded the
bcryptoperations (hashpwandcheckpw) to a separate thread pool usingstarlette.concurrency.run_in_threadpooland wrapped them in newasyncfunctionsverify_passwordandget_password_hash. Updated usages inbackend/auth.pyandbackend/main.py.Verification: Verified changes by running the backend test suite (
pytest) and checking linting (ruff), making sure no regressions were introduced while the blocking DoS potential was eliminated.PR created automatically by Jules for task 1001470159459866222 started by @benpiper