When running a react app within a FIPS enabled environment, anything that relies on createFastHash (such as useActionState in certain cases) will cause an error. This is because it relies on using MD5 for its hashing algorithm which is explicitly disallowed in FIPS:
|
const hash = createHash('md5'); |
The request would be to move to something that is FIPS compliant instead (e.g. sha256). A prior ticket was raised about this (#31748) with implementation PR (#31910), though was closed at the time.
A potential alternative approach if it was desired to use MD5 in majority of cases could be to do something like:
import {createHash, getFips} from 'crypto';
export function createFastHash(input: string): string | number {
const hash = createHash(getFips() ? 'sha256' : 'md5');
hash.update(input);
return hash.digest('hex');
}
React version: 19.2.4
Steps To Reproduce
- On a FIPS enabled system, try to use
createFastHash (via a hook like useActionState), see error.
Link to code example:
app/actions.js
'use server';
export async function submit(previousState, formData) {
return `Hello, ${formData.get('name')}`;
}
app/page.js
'use client';
import { useActionState } from 'react';
import { submit } from './actions';
export default function Page() {
const [state, formAction] = useActionState(submit, '');
return (
<form action={formAction}>
<input name="name" defaultValue="World" />
<button type="submit">Submit</button>
<p>{state}</p>
</form>
);
}
If crypto.getFips() returns 1, then the above will fail.
The current behavior
Uncaught Error: error:0308010C:digital envelope routines::unsupported
at new Hash (node:internal/crypto/hash:112:19)
at createHash (node:crypto:146:10) {
opensslErrorStack: [
'error:03000086:digital envelope routines::initialization error',
'error:0308010C:digital envelope routines::unsupported'
],
library: 'digital envelope routines',
reason: 'unsupported',
code: 'ERR_OSSL_EVP_UNSUPPORTED'
}
The expected behavior
It doesn't error.
When running a react app within a FIPS enabled environment, anything that relies on
createFastHash(such asuseActionStatein certain cases) will cause an error. This is because it relies on using MD5 for its hashing algorithm which is explicitly disallowed in FIPS:react/packages/react-server/src/ReactServerStreamConfigNode.js
Line 240 in d083ec1
The request would be to move to something that is FIPS compliant instead (e.g.
sha256). A prior ticket was raised about this (#31748) with implementation PR (#31910), though was closed at the time.A potential alternative approach if it was desired to use MD5 in majority of cases could be to do something like:
React version: 19.2.4
Steps To Reproduce
createFastHash(via a hook likeuseActionState), see error.Link to code example:
app/actions.js
app/page.js
If
crypto.getFips()returns1, then the above will fail.The current behavior
The expected behavior
It doesn't error.