Skip to content

fix(web-bot-auth): enforce alg parameter against resolved key algorithm in Rust verify - #154

Open
hakimlabs wants to merge 1 commit into
cloudflare:mainfrom
hakimlabs:fieldwork/001-alg-check
Open

hakimlabs wants to merge 1 commit into
cloudflare:mainfrom
hakimlabs:fieldwork/001-alg-check

Conversation

@hakimlabs

Copy link
Copy Markdown

Fixes #153.

MessageVerifier::verify resolves the algorithm from the key ring entry and never compares it with the signed alg parameter. A signature over an Ed25519 key carrying alg="rsa-pss-sha512" verifies, and so does one carrying alg="foo". RFC 9421 §3.2 step 6 requires verification to fail in both cases: 6.1/6.4, the algorithm named in the parameters must be in the verifier's allowable set; 6.5, when the algorithm is known from more than one place the resolved algorithms must agree. The TypeScript http-message-sig verifier already rejects both with AlgorithmMismatch; this brings the Rust crate in line, in the same spirit as #125 and #127.

Reproduced #153 independently at c07ecb6 with the request as filed and with a fresh signature under the RFC 9421 B.1.4 test key.

Change:

  • New ImplementationError::AlgorithmMismatch { signed, resolved }, returned from MessageVerifier::verify (and therefore WebBotAuthVerifier::verify) when alg is present and is either unregistered or different from the resolved key's algorithm.
  • alg absent keeps verifying; the algorithm then comes from the key material (step 6.3).
  • Keys whose algorithm this crate cannot verify keep reporting UnsupportedAlgorithm, so the existing test_verifying_unsupported_algorithm is unchanged.
  • Four tests on a signature covering ("@authority") under the test key: mismatching, unregistered, matching and absent alg.

Not a practical bypass at this commit: the verifying algorithm is bound to the key ring entry, only Ed25519 is verified, and alg is inside the signed base. The change is about following the MUST and matching the TypeScript verifier.

Checks: cargo test --workspace --all-features --all-targets, cargo fmt --all -- --check, cargo clippy -p web-bot-auth --all-features --all-targets -- -D warnings.

Adding an enum variant to the public ImplementationError is a semver-minor change for exhaustive matchers; happy to adjust if you would rather fold this into an existing variant.

🤖 Generated with Claude Code

…hm in Rust verify

RFC 9421 Section 3.2 step 6 requires a verifier to fail when the alg
parameter names an algorithm outside the allowable set (6.1, 6.4) or
disagreeing with the algorithm the key material resolves to (6.5).
MessageVerifier::verify took the algorithm from the key ring entry only
and ignored the signed alg, so a signature over an Ed25519 key carrying
alg="rsa-pss-sha512" (or alg="foo") verified. The TypeScript verifier
already rejects both with AlgorithmMismatch.

Add ImplementationError::AlgorithmMismatch and tests for mismatching,
unregistered, matching and absent alg. Keys whose algorithm this crate
cannot verify keep reporting UnsupportedAlgorithm.

Fixes cloudflare#153.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rust WebBotAuthVerifier::verify accepts a signature whose alg parameter does not match the key's algorithm

1 participant