Skip to content

fix(net): prevent hello message replay - #24

Closed
xxo1shine wants to merge 1 commit into
base-codefrom
fix/net-hello-message-replay
Closed

xxo1shine wants to merge 1 commit into
base-codefrom
fix/net-hello-message-replay

Conversation

@xxo1shine

Copy link
Copy Markdown
Owner

Hello messages were accepted without checking timestamp freshness, allowing a previously signed witness message to be replayed indefinitely.

Add a configurable freshness threshold and track the latest verified timestamp per witness so stale or repeated messages are rejected before trust is granted. Adapt the setting to the current NodeConfig-based configuration model while retaining signature-length validation.

What does this PR do?

Why are these changes required?

This PR has been tested by:

  • Unit Tests
  • Manual Testing

Follow up

Extra details

Hello messages were accepted without checking timestamp freshness, allowing a previously signed witness message to be replayed indefinitely.

Add a configurable freshness threshold and track the latest verified timestamp per witness so stale or repeated messages are rejected before trust is granted. Adapt the setting to the current NodeConfig-based configuration model while retaining signature-length validation.
@xxo1shine xxo1shine closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant