New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improvements to signature verification #9667

Merged
merged 4 commits into from Jan 7, 2019

Conversation

Projects
None yet
2 participants
@ThibG
Copy link
Collaborator

ThibG commented Dec 30, 2018

  • Fix stored invalid keys preventing from updating account data
  • Always re-fetch keys if signature verification fails, albeit avoiding webfinger roundtrip and additional HTTP queries
  • Extend stoplight to account/key refresh too

This part of the code is a bit hairy, this should be thoroughly reviewed, and tests should probably be added.

@ThibG ThibG force-pushed the ThibG:fixes/refresh-key branch 6 times, most recently from 93e0949 to 48d1b7d Dec 30, 2018

@ThibG ThibG force-pushed the ThibG:fixes/refresh-key branch from 48d1b7d to 3cabf7d Dec 30, 2018

@ThibG ThibG force-pushed the ThibG:fixes/refresh-key branch from 3cabf7d to 9be1988 Jan 1, 2019

@ThibG ThibG requested a review from Gargron Jan 7, 2019

@Gargron

Gargron approved these changes Jan 7, 2019

@Gargron Gargron merged commit 28b4828 into tootsuite:master Jan 7, 2019

11 checks passed

ci/circleci: build Your tests passed on CircleCI!
Details
ci/circleci: check-i18n Your tests passed on CircleCI!
Details
ci/circleci: install Your tests passed on CircleCI!
Details
ci/circleci: install-ruby2.4 Your tests passed on CircleCI!
Details
ci/circleci: install-ruby2.5 Your tests passed on CircleCI!
Details
ci/circleci: install-ruby2.6 Your tests passed on CircleCI!
Details
ci/circleci: test-ruby2.4 Your tests passed on CircleCI!
Details
ci/circleci: test-ruby2.5 Your tests passed on CircleCI!
Details
ci/circleci: test-ruby2.6 Your tests passed on CircleCI!
Details
ci/circleci: test-webui Your tests passed on CircleCI!
Details
codeclimate All good!
Details
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment