Skip to content

Trusted entitlements: Add IntermediateSignatureHelper to handle intermediate signature verification process#1110

Merged
tonidero merged 1 commit into
mainfrom
toniricodiez/sdk-3200-verify-intermediate-signature-android-2
Jun 30, 2023
Merged

Trusted entitlements: Add IntermediateSignatureHelper to handle intermediate signature verification process#1110
tonidero merged 1 commit into
mainfrom
toniricodiez/sdk-3200-verify-intermediate-signature-android-2

Conversation

@tonidero

Copy link
Copy Markdown
Contributor

Description

Second PR to implement SDK-3200

This PR creates the new IntermediateSignatureHelper class to handle the logic related to verifying intermediate keys. This is not currently used and will be used in future PRs

@tonidero tonidero changed the title Add IntermediateSignatureHelper to handle intermediate signature verification process Trusted entitlements: Add IntermediateSignatureHelper to handle intermediate signature verification process Jun 29, 2023
@codecov

codecov Bot commented Jun 29, 2023

Copy link
Copy Markdown

Codecov Report

Merging #1110 (e2cd630) into main (6423df7) will decrease coverage by 0.10%.
The diff coverage is 76.19%.

❗ Current head e2cd630 differs from pull request most recent head 01e5594. Consider uploading reports for the commit 01e5594 to get more accurate results

@@            Coverage Diff             @@
##             main    #1110      +/-   ##
==========================================
- Coverage   85.12%   85.03%   -0.10%     
==========================================
  Files         183      186       +3     
  Lines        6493     6554      +61     
  Branches      917      929      +12     
==========================================
+ Hits         5527     5573      +46     
- Misses        601      616      +15     
  Partials      365      365              
Impacted Files Coverage Δ
...enuecat/purchases/common/verification/Signature.kt 66.66% <66.66%> (ø)
...a/com/revenuecat/purchases/common/IntExtensions.kt 100.00% <100.00%> (ø)
...common/verification/IntermediateSignatureHelper.kt 100.00% <100.00%> (ø)
...purchases/common/verification/SignatureVerifier.kt 100.00% <100.00%> (ø)

@tonidero tonidero marked this pull request as ready for review June 29, 2023 11:19
@tonidero tonidero requested a review from a team June 29, 2023 11:19

@NachoSoto NachoSoto left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wish Foundation had this hehe. We should add it honestly.

Base automatically changed from toniricodiez/sdk-3200-verify-intermediate-signature-android to main June 30, 2023 07:11
@tonidero tonidero force-pushed the toniricodiez/sdk-3200-verify-intermediate-signature-android-2 branch from e2cd630 to 01e5594 Compare June 30, 2023 07:12
@tonidero tonidero enabled auto-merge (squash) June 30, 2023 07:15
@tonidero tonidero merged commit e6e498c into main Jun 30, 2023
@tonidero tonidero deleted the toniricodiez/sdk-3200-verify-intermediate-signature-android-2 branch June 30, 2023 07:21
tonidero added a commit that referenced this pull request Jul 3, 2023
### Description
Third PR for SDK-3200

- Adds support to the new signature format (salt + nonce + TS + etag +
content)
- Adds support for intermediate signatures verification
- Makes nonce optional in preparation of static endpoint signing.

Based on #1109 and #1110.
tonidero added a commit that referenced this pull request Jul 7, 2023
### Description
Third PR for SDK-3200

- Adds support to the new signature format (salt + nonce + TS + etag +
content)
- Adds support for intermediate signatures verification
- Makes nonce optional in preparation of static endpoint signing.

Based on #1109 and #1110.
tonidero added a commit that referenced this pull request Jul 12, 2023
**This is an automatic release.**

### New Features
* `Trusted Entitlements`: made API stable (#1105) via NachoSoto
(@NachoSoto)

This new feature prevents MitM attacks between the SDK and the
RevenueCat server.
With verification enabled, the SDK ensures that the response created by
the server was not modified by a third-party, and the entitlements
received are exactly what was sent.
This is 100% opt-in. `EntitlementInfos` have a new `VerificationResult`
property, which will indicate the validity of the responses when this
feature is enabled.

```kotlin
fun configureRevenueCat() {
    val configuration = PurchasesConfiguration.Builder(context, apiKey)
        .entitlementVerificationMode(EntitlementVerificationMode.INFORMATIONAL)
        .build()
    Purchases.configure(configuration)
}
```
### Experimental features
* Add await offerings (#1096) via Cesar de la Vega (@vegaro)
### Bugfixes
* Fix issue updating customer info on app open (#1128) via Toni Rico
(@tonidero)
### Dependency Updates
* Bump fastlane-plugin-revenuecat_internal from `13773d2` to `b2108fb`
(#1095) via dependabot[bot] (@dependabot[bot])
### Other Changes
* [PurchaseTester] Add option to purchase an arbitrary product id
(#1099) via Mark Villacampa (@MarkVillacampa)
* Fix release path after module refactor (#1129) via Toni Rico
(@tonidero)
* Fix load shedder integration tests (#1125) via Toni Rico (@tonidero)
* Trusted entitlements: New trusted entitlements signature format
(#1117) via Toni Rico (@tonidero)
* Fix integration tests and change to a different project (#1123) via
Toni Rico (@tonidero)
* Move files into src/main/kotlin (#1122) via Cesar de la Vega (@vegaro)
* Remove public module (#1113) via Cesar de la Vega (@vegaro)
* Remove common module (#1106) via Cesar de la Vega (@vegaro)
* Fix flaky integration tests: Wait for coroutines to finish before
continuing (#1120) via Toni Rico (@tonidero)
* Move amazon module into purchases (#1112) via Cesar de la Vega
(@vegaro)
* Trusted entitlements: Add IntermediateSignatureHelper to handle
intermediate signature verification process (#1110) via Toni Rico
(@tonidero)
* Trusted entitlements: Add Signature type to process new signature
response format (#1109) via Toni Rico (@tonidero)
* [EXTERNAL] Add `awaitCustomerInfo` / coroutines tests to
`TrustedEntitlementsInformationalModeIntegrationTest` (#1077) via
@pablo-guardiola (#1107) via Toni Rico (@tonidero)
* Remove feature:google module (#1104) via Cesar de la Vega (@vegaro)
* Remove identity module (#1103) via Cesar de la Vega (@vegaro)
* Remove subscriber attributes module (#1102) via Cesar de la Vega
(@vegaro)
* Delete utils module (#1098) via Cesar de la Vega (@vegaro)
* Remove strings module (#1097) via Cesar de la Vega (@vegaro)
* Update CHANGELOG.md to include external contribution (#1100) via Cesar
de la Vega (@vegaro)
* [EXTERNAL] Add missing `fetchPolicy` parameter to `awaitCustomerInfo`
API (#1086) via @pablo-guardiola (#1090) via Toni Rico (@tonidero)

---------

Co-authored-by: revenuecat-ops <ops@revenuecat.com>
Co-authored-by: Toni Rico <antonio.rico.diez@revenuecat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants