Skip to content

attest: verifier reports fully_verified for any self-signed attestation #508

Description

@PierrunoYT

gitlawb-attest's verifier (crates/gitlawb-attest/src/verifier.rs:119-145) never anchors the signer: it returns fully_verified: true for any self-consistent attestation. The docstring defers the allowlist check to callers, but no caller does it yet. Because identities are permissionless, anyone can mint a keypair, name it in the attestation, self-sign, and be told it is verified.

Fix: make the trusted-signer set a required input to the verifier (a pinned or configured allowlist), and fail the result on a mismatch rather than logging. Add a positive test with a trusted artifact and a rejection test for a well-formed forged one, per AGENTS.md. Related: #359, #360.

Found in the Oct 2 2026 audit (A19) at bfc44f9.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:attestgitlawb-attest — attestation and verificationkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:attestationCertificates, anchoring, per-ref attestationsubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions