Skip to content

Patched timestamp login bypass and fixed formatting#4

Open
ELF-Nigel wants to merge 2 commits intoKeyAuth:mainfrom
ELF-Nigel:main
Open

Patched timestamp login bypass and fixed formatting#4
ELF-Nigel wants to merge 2 commits intoKeyAuth:mainfrom
ELF-Nigel:main

Conversation

@ELF-Nigel
Copy link

  • Added a server-time–anchored expiry check that cannot be bypassed by changing the client clock (forward or
    backward). It uses the server’s signed timestamp header and a monotonic delta so local time changes after login
    won’t affect expiry enforcement.
  • Calls the new check after successful Login, Register, Forgot, and License flows.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant