authenticator-rs icon indicating copy to clipboard operation
authenticator-rs copied to clipboard

Audit for use of CTAP2 canonical CBOR encoding

Open jschanck opened this issue 2 years ago • 0 comments

We need to review our serialization routines to ensure that we use CTAP2 canonical CBOR encoding form. Martin Kreichgauer noticed that the keys in our AttestationObjects maps are in the order (authData, fmt, attStmt) instead of the correct (fmt, attStmt, authData). I'll fix that issue, but we should do an audit and add tests as well.

jschanck avatar Feb 17 '23 00:02 jschanck