fix(siwe): reject unparseable expirationTime and notBefore - #4990
Open
SashaMIT wants to merge 1 commit into
Open
fix(siwe): reject unparseable expirationTime and notBefore#4990SashaMIT wants to merge 1 commit into
SashaMIT wants to merge 1 commit into
Conversation
Invalid Date values from parseSiweMessage (e.g. Expiration Time: never) are truthy, so comparisons like `time >= expirationTime` are always false and lifetime / nbf checks were skipped. Fail closed when either field is present but not a real date (sibling of thirdweb-dev/js#8875 / supabase/auth#2688).
|
|
@SashaMIT is attempting to deploy a commit to the Wevm Team on Vercel. A member of the Team first needs to authorize it. |
Member
|
Two remaining cases:
See the ERC-4361 validation requirements. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
parseSiweMessageturns fields likeExpiration Time: neverinto a truthyInvalid Date. InvalidateSiweMessage, the lifetime checks were:Comparisons against
Invalid Dateare alwaysfalse, so both gates no-op and a signed SIWE message with garbage expiration / not-before still validates. This rejects unparseable dates when those fields are present (same class as thirdweb-dev/js#8875 and supabase/auth#2688).Test plan
pnpm exec vitest run -c ./test/vitest.config.ts src/utils/siwe/validateSiweMessage.test.ts→ 12/12Expiration Time: never/ garbageNot BeforeMade with Cursor