Skip to content

fix(auth): use base64url encoding in session signature verification (fixes #64)#67

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
FuturMix:fix/session-verify-encoding
Jun 14, 2026
Merged

fix(auth): use base64url encoding in session signature verification (fixes #64)#67
ralyodio merged 1 commit into
profullstack:masterfrom
FuturMix:fix/session-verify-encoding

Conversation

@FuturMix

Copy link
Copy Markdown
Contributor

Changes Buffer.from(signature) and Buffer.from(expected) to use explicit "base64url" encoding, matching the .digest("base64url") used to generate the signature. The webhook verification already uses explicit encoding ("hex").

Fixes #64

@ralyodio ralyodio merged commit 5cfece3 into profullstack:master Jun 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Session signature verification uses wrong Buffer encoding

2 participants