Repository navigation
Changes:
- fix:
verifySolutionrejects every challenge withinvalidSignaturewhen nohmacSignatureSecretis configured (nullor''). Previously the signature check was skipped, so unsigned or tampered challenges (e.g. with a client-chosenkeyPrefixorcost) verified.''now also counts as unset when creating challenges. - fix:
expiresAthandling matchesaltcha-lib(JS):0means no expiry, fractional timestamps (e.g.Date.now() / 1000 + 600) are accepted and signed as-is, and expiry is checked to the sub-second (no more up to 1 s of grace). - fix: canonical JSON used for challenge signatures matches
altcha-lib(JS) byte-for-byte, so challenges signed by one library verify in the other (JS number formatting, JS key order, empty or list-shapeddataencoded as an object, U+2028/U+2029 left unescaped).
BREAKING:
verifySolutionwithout a signature secret now always fails. PasshmacSignatureSecrettonew Altcha(...)on every server that verifies solutions.ChallengeParameters::$expiresAtandCreateChallengeOptions::$expiresAtareint|float|null(were?int).ChallengeParameters::toArray()['data']is astdClasswhendatais empty or list-shaped.createChallenge()andChallengeParameters::toCanonicalJson()throwJsonExceptionon invalid UTF-8 indata(previously an empty string was signed).- Challenges whose
datacontains floats that PHP formatted differently from JS are signed differently; such challenges issued before upgrading fail verification.
Full changelog: CHANGELOG.md · v2.2.0...v2.3.0