Skip to content

v2.3.0

Latest

Choose a tag to compare

@ovx ovx released this 04 Oct 08:30

Changes:

  • fix: verifySolution rejects every challenge with invalidSignature when no hmacSignatureSecret is configured (null or ''). Previously the signature check was skipped, so unsigned or tampered challenges (e.g. with a client-chosen keyPrefix or cost) verified. '' now also counts as unset when creating challenges.
  • fix: expiresAt handling matches altcha-lib (JS): 0 means no expiry, fractional timestamps (e.g. Date.now() / 1000 + 600) are accepted and signed as-is, and expiry is checked to the sub-second (no more up to 1 s of grace).
  • fix: canonical JSON used for challenge signatures matches altcha-lib (JS) byte-for-byte, so challenges signed by one library verify in the other (JS number formatting, JS key order, empty or list-shaped data encoded as an object, U+2028/U+2029 left unescaped).

BREAKING:

  • verifySolution without a signature secret now always fails. Pass hmacSignatureSecret to new Altcha(...) on every server that verifies solutions.
  • ChallengeParameters::$expiresAt and CreateChallengeOptions::$expiresAt are int|float|null (were ?int).
  • ChallengeParameters::toArray()['data'] is a stdClass when data is empty or list-shaped.
  • createChallenge() and ChallengeParameters::toCanonicalJson() throw JsonException on invalid UTF-8 in data (previously an empty string was signed).
  • Challenges whose data contains floats that PHP formatted differently from JS are signed differently; such challenges issued before upgrading fail verification.

Full changelog: CHANGELOG.md · v2.2.0...v2.3.0