Skip to content

fix: validate DID JWT issuer binding - #20

Merged
NateRobinson merged 1 commit into
mainfrom
fix/verify-jwt-did-binding
May 9, 2026
Merged

NateRobinson merged 1 commit into
mainfrom
fix/verify-jwt-did-binding

Conversation

@NateRobinson

Copy link
Copy Markdown
Collaborator

Summary

  • Fix verifyJWTDID issuer/public key binding check
  • Normalize did:abt issuer values to addresses before comparison
  • Derive JWT signature type from issuer DID type instead of raw public key bytes
  • Add positive and mismatched issuer coverage for verifyJWTDID

Tests

  • ./gradlew --no-daemon :wallet-sdk:testDebugUnitTest

Ensure verifyJWTDID requires the issuer DID to match the provided public key, derives the signature type from the issuer DID, and covers matching/mismatched issuer cases.

Co-authored-by: Codex <codex@openai.com>
@github-actions

github-actions Bot commented May 9, 2026

Copy link
Copy Markdown

Code Coverage

There is no coverage information present for the Files changed

Total Project Coverage 79.26% 🍏

@NateRobinson
NateRobinson merged commit 21736e5 into main May 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants