From 6c34b383d779858674ecdec7afc39661c32a4f30 Mon Sep 17 00:00:00 2001 From: Derrick Hammer Date: Tue, 16 Jan 2024 15:37:08 -0500 Subject: [PATCH] fix: verify the response, not the challenge --- api/s5/http.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/api/s5/http.go b/api/s5/http.go index bc8c2b3..ef3d685 100644 --- a/api/s5/http.go +++ b/api/s5/http.go @@ -297,7 +297,7 @@ func (h *HttpHandler) AccountRegister(jc jape.Context) { return } - if !ed25519.Verify(decodedKey[1:], decodedChallenge, decodedSignature) { + if !ed25519.Verify(decodedKey[1:], decodedResponse, decodedSignature) { errored(errInvalidSignatureErr) return } @@ -470,7 +470,7 @@ func (h *HttpHandler) AccountLogin(jc jape.Context) { return } - if !ed25519.Verify(decodedKey[1:], decodedChallenge, decodedSignature) { + if !ed25519.Verify(decodedKey[1:], decodedResponse, decodedSignature) { errored(errInvalidSignatureErr) return }