servant-server's current implementation of basic authentication is not immune to certain kinds of timing attacks. Decoding payloads does not take a fixed amount of time.
The result of authentication/authorization
Constructors
Instances6Functor, Eq, Read, Show, Generic, Rep
Functor BasicAuthResultDefined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuthEq usr => Eq (BasicAuthResult usr)Defined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuthRead usr => Read (BasicAuthResult usr)Defined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuthShow usr => Show (BasicAuthResult usr)Defined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuthGeneric (BasicAuthResult usr)Defined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuthtype Rep (BasicAuthResult usr) = D1 ('MetaDataDefined in servant-server-0.20.2 · Servant.Server.Internal.BasicAuth"BasicAuthResult"
"Servant.Server.Internal.BasicAuth"
"servant-server-0.20.2-DEGy5HWu5CN9qp6ok675uv"
'False) ((C1 ('MetaCons"Unauthorized"
'PrefixI 'False) U1 :+: C1 ('MetaCons"BadPassword"
'PrefixI 'False) U1) :+: (C1 ('MetaCons"NoSuchUser"
'PrefixI 'False) U1 :+: C1 ('MetaCons"Authorized"
'PrefixI 'False) (S1 ('MetaSel 'Nothing 'NoSourceUnpackedness 'NoSourceStrictness 'DecidedStrict) (Rec0 usr))))