Repository navigation
feat(pro): pin the lockdocs-pro issuer public key - #60
Conversation
There was a problem hiding this comment.
Approve at 7413ea2. The pinned value is the lockdocs-pro issuer public key (base64url raw Ed25519, decodes to 32 bytes) and matches the key read from the issuer; no private key or token is committed, and no KEY_PLACEHOLDER reference remains. Verification fails closed: sylphx-mcp-kit 0.7.0 LicencePolicy::verify_at refuses malformed tokens, a signature from any unlisted key, the wrong plan or product, and expired licences, and require() returns ProRequired on any error. public_keys is a list, so a rotation is additive: ship the new key next to the old one, then drop the old one in a later release. No paid user can be locked out: before this change no token verified at all, so the change only widens what is accepted. Tests cover the pinned key's shape and that a listed key verifies while an unlisted one does not. Follow-up, not blocking: add a fixture token minted by the real issuer (for example a sandbox grant) so the test proves the pinned key end to end, not only the mechanism.
What
Why and how it was tested
feat(pro): pin the lockdocs-pro issuer public key