Skip to content

feat: bind OTP login token usage strictly - #153

Closed
grant-turnkey wants to merge 1 commit into
mainfrom
grant/cor-94-tob-26q2-20-otp-login-and-signup-intents-include-attacker/strict-csk-binding
Closed

grant-turnkey wants to merge 1 commit into
mainfrom
grant/cor-94-tob-26q2-20-otp-login-and-signup-intents-include-attacker/strict-csk-binding

Conversation

@grant-turnkey

Copy link
Copy Markdown

Summary & Motivation

  • Add LoginUsageV2 and SignupUsageV3. These updated requests sign more fields, prevent manipulation of newly created sub-organizations and login sessions.

How I Tested These Changes

Tested locally with a modified examples/otp/main.go

Did you add a changeset?

yes

@grant-turnkey
grant-turnkey force-pushed the grant/cor-94-tob-26q2-20-otp-login-and-signup-intents-include-attacker/strict-csk-binding branch from f58fae9 to ee65057 Compare October 6, 2026 21:11
- Add `LoginUsageV2` and `SignupUsageV3`. These updated requests sign more fields, protecting your data from manipulation in transit.
@grant-turnkey
grant-turnkey force-pushed the grant/cor-94-tob-26q2-20-otp-login-and-signup-intents-include-attacker/strict-csk-binding branch from ee65057 to c4ac93a Compare October 6, 2026 21:26
@grant-turnkey
grant-turnkey marked this pull request as draft October 7, 2026 16:09
@grant-turnkey
grant-turnkey deleted the grant/cor-94-tob-26q2-20-otp-login-and-signup-intents-include-attacker/strict-csk-binding branch October 9, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant