View Issue Details

IDProjectCategoryView StatusLast Update
0011445Talerlibeufin-bankpublic2026-05-28 18:41
ReporterFlorian Dold Assigned ToAntoine A  
PrioritynormalSeverityminorReproducibilityhave not tried
Status assignedResolutionopen 
Target Version1.7 
Summary0011445: prepared wire transfer API does not use the standard signature header and does not sign over full request
DescriptionFor all signatures in Taler, we use a standard header with a signature purpose and payload length field.

Additionally, the signature on /registration does not sign over fields like the amount, recurrent, etc.

Thus the same signature can easily be used to replay requests with different parameters, which defeats the purpose of having a signature in the first place.
TagsNo tags attached.

Relationships

related to 0011354 assignedAntoine A libeufin rewrite in Rust [2w] 

Activities

Antoine A

2026-05-28 18:41

developer   ~0028722

I would prefer to wait for the rust rewrite to be finished first

Issue History

Date Modified Username Field Change
2026-05-26 13:04 Florian Dold New Issue
2026-05-26 13:04 Florian Dold Status new => assigned
2026-05-26 13:04 Florian Dold Assigned To => Antoine A
2026-05-28 18:41 Antoine A Target Version 1.6 => 1.7
2026-05-28 18:41 Antoine A Relationship added related to 0011354
2026-05-28 18:41 Antoine A Note Added: 0028722