Skip to content

security: derive the real signed payload in obli-pkg verify path #60

Description

@hyperpolymath

The package verify path is an explicit MVP stub: placeholder payload (mock_message = pkg_content) and zeroed test-signature fallbacks (left by #56 with a TODO(security)). A real scheme signs the package bytes excluding the embedded signature blocks. Source: ffi/zig/src/obli-pkg.zig:377.

https://claude.ai/code/session_01GJatEm2TVFSTBEkKXmserJ

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions