Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 8 additions & 5 deletions crates/web-bot-auth/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -310,6 +310,8 @@ impl WebBotAuthVerifier {
#[cfg(test)]
mod tests {

use std::time::Duration;

use components::DerivedComponent;
use indexmap::IndexMap;

Expand Down Expand Up @@ -363,8 +365,9 @@ mod tests {
assert!(advisory.is_expired.unwrap_or(true));
assert!(!advisory.nonce_is_invalid.unwrap_or(true));
let timing = verifier.verify(&keyring, None).unwrap();
assert!(timing.generation.whole_nanoseconds() > 0);
assert!(timing.verification.whole_nanoseconds() > 0);

assert!(timing.generation.as_nanos() > 0);
assert!(timing.verification.as_nanos() > 0);
}

#[test]
Expand Down Expand Up @@ -446,7 +449,7 @@ mod tests {
signer
.generate_signature_headers_content(
&mut mytest,
time::Duration::seconds(10),
Duration::from_secs(10),
Algorithm::Ed25519,
&private_key,
)
Expand All @@ -463,8 +466,8 @@ mod tests {
assert!(!advisory.nonce_is_invalid.unwrap_or(true));

let timing = verifier.verify(&keyring, None).unwrap();
assert!(timing.generation.whole_nanoseconds() > 0);
assert!(timing.verification.whole_nanoseconds() > 0);
assert!(timing.generation.as_nanos() > 0);
assert!(timing.verification.as_nanos() > 0);
}

#[test]
Expand Down
14 changes: 8 additions & 6 deletions crates/web-bot-auth/src/message_signatures.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@ use regex::bytes::Regex;
use sfv::SerializeValue;
use std::fmt::Write as _;
use std::sync::LazyLock;
use time::{Duration, UtcDateTime};
use std::time::Duration;
use time::UtcDateTime;
static OBSOLETE_LINE_FOLDING: LazyLock<Regex> =
LazyLock::new(|| Regex::new(r"\s*\r\n\s+").unwrap());

Expand Down Expand Up @@ -575,7 +576,8 @@ impl MessageVerifier {
.ok_or(ImplementationError::NoSuchKey)?;
let generation = UtcDateTime::now();
let (base_representation, _) = self.parsed.base.into_ascii()?;
let generation = UtcDateTime::now() - generation;
let generation = (UtcDateTime::now() - generation).unsigned_abs();

match &keying_material.0 {
Algorithm::Ed25519 => {
use ed25519_dalek::{Signature, Verifier, VerifyingKey};
Expand All @@ -591,7 +593,7 @@ impl MessageVerifier {
.map_err(ImplementationError::FailedToVerify)
.map(|()| SignatureTiming {
generation,
verification: UtcDateTime::now() - verification,
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As in https://github.com/cloudflare/web-bot-auth/pull/79/changes#r3118154134, you could just do

Suggested change
verification: UtcDateTime::now() - verification,
verification: (UtcDateTime::now() - verification).unsighed_abs(),

and call it a day.

verification: (UtcDateTime::now() - verification).unsigned_abs(),
})
}
other => Err(ImplementationError::UnsupportedAlgorithm(other.clone())),
Expand Down Expand Up @@ -659,8 +661,8 @@ mod tests {
);
let verifier = MessageVerifier::parse(&test, |(_, _)| true).unwrap();
let timing = verifier.verify(&keyring, None).unwrap();
assert!(timing.generation.whole_nanoseconds() > 0);
assert!(timing.verification.whole_nanoseconds() > 0);
assert!(timing.generation.as_nanos() > 0);
assert!(timing.verification.as_nanos() > 0);
}

#[test]
Expand Down Expand Up @@ -713,7 +715,7 @@ mod tests {
signer
.generate_signature_headers_content(
&mut test,
Duration::seconds(10),
Duration::from_secs(10),
Algorithm::Ed25519,
&private_key
)
Expand Down
4 changes: 2 additions & 2 deletions examples/rust/signing.rs
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
// limitations under the License.

use indexmap::IndexMap;
use time::Duration;
use std::time::Duration;
use web_bot_auth::{
components::{
CoveredComponent, DerivedComponent, HTTPField, HTTPFieldParameters, HTTPFieldParametersSet,
Expand Down Expand Up @@ -71,7 +71,7 @@ fn main() {
signer
.generate_signature_headers_content(
&mut headers,
Duration::seconds(10),
Duration::from_secs(10),
Algorithm::Ed25519,
&private_key,
)
Expand Down
4 changes: 2 additions & 2 deletions examples/signature-agent-card-and-registry/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ use indexmap::map::IndexMap;
use rand::RngCore;
use serde::{Deserialize, Serialize};
use sha2::{Digest, Sha256};
use time::Duration;
use std::time::Duration;
use web_bot_auth::{
components::{CoveredComponent, DerivedComponent, HTTPField, HTTPFieldParametersSet},
keyring::{Algorithm, Thumbprintable},
Expand Down Expand Up @@ -167,7 +167,7 @@ async fn fetch(req: HttpRequest, env: Env, _ctx: Context) -> Result<Response> {
signer
.generate_signature_headers_content(
&mut generator,
Duration::seconds(10),
Duration::from_secs(10),
Algorithm::Ed25519,
signing_key.as_bytes(),
)
Expand Down
Loading