Repository navigation
Runtime-deprecate calling digest() on HMAC more than once #62838
Description
Activity
- addedsecurityIssues and PRs related to security.Issues and PRs related to security.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on Apr 20, 2026 Given the lack of usefulness of the second digest() call's return (and in so the likelyhood of it being depended on), shouldn't we treat this as a bug fix?The behaviour looks entirely deliberate
node/lib/internal/crypto/hash.js
Lines 185 to 190 in c3dd52a
if (state[kFinalized]) { const buf = Buffer.from(''); if (outputEncoding && outputEncoding !== 'buffer') return buf.toString(outputEncoding); return buf; } but looking at the blame its introduction traces back to #15231 by @jasnell, its parent was just throwing the same as
HashLine 121 in 8fa5fcc
Hmac.prototype.update = Hash.prototype.update; Oh, we reaching way back. I don't remember what the reasoning here was. I'm +1 on deprecation of the inconsistent behavior
Yeah, +1 deprecate it.
Reacted by Nikita Skovoroda@panva this was also auto-detected by the scanner behind @deepview-autofix btw.
But this in fact looks intentional so I would recommend removing this in a major as a safeguard, following a deprecation cycle.
Upd: github glitched, I replied to #62838 (comment), all the other comments (end the edit on that one) just loaded. I agree with those.
Enough time to land a semver-major
PRs that contain breaking changes and should be released in the next major version. runtime-deprecation for v27.x and then soonest with v28.x EOL the deprecation.Reacted by Nikita Skovoroda- addedgood first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.
on Apr 28, 2026 Hi! I'd love to contribute. Could you assign this issue to me?
Hi! I’d like to work on this issue. I’m preparing a PR for it.
- added a commit that references this issue
on May 6, 2026 @Anshikakalpana Left review suggestions for the CI failure.
expectWarning is keyed by warning name, so the inline
DEP0181block at the bottom of test-crypto-hmac.js overwrites the new DEP0206 registration. Merging them at the top resolves it.Fetching comments for issue #62838...
- removedgood first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.
on Jun 8, 2026 - added a commit that references this issue
on Jun 15, 2026 - added a commit that references this issue
on Jun 15, 2026 - added a commit that references this issue
on Jun 18, 2026 - added a commit that references this issue
on Aug 12, 2026
(Upd: detected by the scanner behind @deepview-autofix)
Hash behavior is reasonable:
But HMAC, on the other hand, returns empty buffers on further
.digest()calls, likely for compat reasons:This is a footgun with potential security risks, and should be first runtime-deprecated, then removed if no breakage is detected.