Skip to content

test(pro): pin the issuer public key by value - #61

Merged
sylphx-desk-studio[bot] merged 1 commit into
mainfrom
pin-pro-issuer-key
Oct 6, 2026
Merged

sylphx-desk-studio[bot] merged 1 commit into
mainfrom
pin-pro-issuer-key

Conversation

@sylphx-desk-services

Copy link
Copy Markdown
Contributor

What

The Pro issuer key test now checks the key by its literal value, so changing or dropping the key fails the test. Before, it compared the policy with the same constant, which passes after any key swap.

Why

Every sold Pro token is signed by this key. A key that is replaced instead of added next to the old one would stop every sold licence from verifying.

How it was tested

A one-line test change, formatted with rustfmt; cargo test --locked -p lockdocs is left to CI.

Every sold Pro token is signed by this key; the test now fails if the key is
changed or dropped instead of comparing the constant with itself.

@sylphx-desk-studio sylphx-desk-studio Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The test now pins the issuer key by its literal value (crates/lockdocs/src/pro.rs:67), which matches the shipped constant at pro.rs:10. Swapping or dropping the key now fails the test, so every sold token stays verifiable. CI is green on all three OS targets.

@sylphx-desk-studio
sylphx-desk-studio Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 3501132 Oct 6, 2026
7 checks passed
@sylphx-desk-studio
sylphx-desk-studio Bot deleted the pin-pro-issuer-key branch October 6, 2026 20:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant