View Issue Details

IDProjectCategoryView StatusLast Update
0011445Talerlibeufin-bankpublic2026-05-26 13:04
ReporterFlorian Dold Assigned ToAntoine A  
PrioritynormalSeverityminorReproducibilityhave not tried
Status assignedResolutionopen 
Target Version1.6 
Summary0011445: prepared wire transfer API does not use the standard signature header and does not sign over full request
DescriptionFor all signatures in Taler, we use a standard header with a signature purpose and payload length field.

Additionally, the signature on /registration does not sign over fields like the amount, recurrent, etc.

Thus the same signature can easily be used to replay requests with different parameters, which defeats the purpose of having a signature in the first place.
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-05-26 13:04 Florian Dold New Issue
2026-05-26 13:04 Florian Dold Status new => assigned
2026-05-26 13:04 Florian Dold Assigned To => Antoine A