fix: insecure randomness

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
Levente Orban
2025-10-28 07:46:02 +01:00
committed by GitHub
parent aebe477f90
commit 02975a0abd

View File

@@ -1,5 +1,8 @@
import { randomBytes } from 'crypto';
export const generateUserId = () => { export const generateUserId = () => {
const userId = 'user_' + Date.now() + '_' + Math.random().toString(36).substr(2, 9); const secureRandomString = randomBytes(8).toString('base36').substr(0, 9);
const userId = 'user_' + Date.now() + '_' + secureRandomString;
return userId; return userId;
}; };