Repository navigation
Conversation
…hm in Rust verify RFC 9421 Section 3.2 step 6 requires a verifier to fail when the alg parameter names an algorithm outside the allowable set (6.1, 6.4) or disagreeing with the algorithm the key material resolves to (6.5). MessageVerifier::verify took the algorithm from the key ring entry only and ignored the signed alg, so a signature over an Ed25519 key carrying alg="rsa-pss-sha512" (or alg="foo") verified. The TypeScript verifier already rejects both with AlgorithmMismatch. Add ImplementationError::AlgorithmMismatch and tests for mismatching, unregistered, matching and absent alg. Keys whose algorithm this crate cannot verify keep reporting UnsupportedAlgorithm. Fixes cloudflare#153. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #153.
MessageVerifier::verifyresolves the algorithm from the key ring entry and never compares it with the signedalgparameter. A signature over an Ed25519 key carryingalg="rsa-pss-sha512"verifies, and so does one carryingalg="foo". RFC 9421 §3.2 step 6 requires verification to fail in both cases: 6.1/6.4, the algorithm named in the parameters must be in the verifier's allowable set; 6.5, when the algorithm is known from more than one place the resolved algorithms must agree. The TypeScripthttp-message-sigverifier already rejects both withAlgorithmMismatch; this brings the Rust crate in line, in the same spirit as #125 and #127.Reproduced #153 independently at
c07ecb6with the request as filed and with a fresh signature under the RFC 9421 B.1.4 test key.Change:
ImplementationError::AlgorithmMismatch { signed, resolved }, returned fromMessageVerifier::verify(and thereforeWebBotAuthVerifier::verify) whenalgis present and is either unregistered or different from the resolved key's algorithm.algabsent keeps verifying; the algorithm then comes from the key material (step 6.3).UnsupportedAlgorithm, so the existingtest_verifying_unsupported_algorithmis unchanged.("@authority")under the test key: mismatching, unregistered, matching and absentalg.Not a practical bypass at this commit: the verifying algorithm is bound to the key ring entry, only Ed25519 is verified, and
algis inside the signed base. The change is about following the MUST and matching the TypeScript verifier.Checks:
cargo test --workspace --all-features --all-targets,cargo fmt --all -- --check,cargo clippy -p web-bot-auth --all-features --all-targets -- -D warnings.Adding an enum variant to the public
ImplementationErroris a semver-minor change for exhaustive matchers; happy to adjust if you would rather fold this into an existing variant.🤖 Generated with Claude Code