Skip to content

feat(pro): pin the lockdocs-pro issuer public key - #60

Merged
sylphx-desk-apps[bot] merged 1 commit into
mainfrom
fix/pro-issuer-key
Oct 6, 2026
Merged

sylphx-desk-apps[bot] merged 1 commit into
mainfrom
fix/pro-issuer-key

Conversation

@sylphx-desk-studio

Copy link
Copy Markdown
Contributor

What

  • feat(pro): pin the lockdocs-pro issuer public key

Why and how it was tested

feat(pro): pin the lockdocs-pro issuer public key

@sylphx-desk-apps sylphx-desk-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve at 7413ea2. The pinned value is the lockdocs-pro issuer public key (base64url raw Ed25519, decodes to 32 bytes) and matches the key read from the issuer; no private key or token is committed, and no KEY_PLACEHOLDER reference remains. Verification fails closed: sylphx-mcp-kit 0.7.0 LicencePolicy::verify_at refuses malformed tokens, a signature from any unlisted key, the wrong plan or product, and expired licences, and require() returns ProRequired on any error. public_keys is a list, so a rotation is additive: ship the new key next to the old one, then drop the old one in a later release. No paid user can be locked out: before this change no token verified at all, so the change only widens what is accepted. Tests cover the pinned key's shape and that a listed key verifies while an unlisted one does not. Follow-up, not blocking: add a fixture token minted by the real issuer (for example a sandbox grant) so the test proves the pinned key end to end, not only the mechanism.

@sylphx-desk-apps
sylphx-desk-apps Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 775b61a Oct 6, 2026
7 checks passed
@sylphx-desk-apps
sylphx-desk-apps Bot deleted the fix/pro-issuer-key branch October 6, 2026 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant