Fix Remote Bolus OTP validation on Authy#19
Merged
Conversation
gestrich
commented
Apr 16, 2022
| @@ -70,7 +70,8 @@ public class OTPManager { | |||
|
|
|||
| private var secretStore: OTPSecretStore | |||
| private var nowDateSource: () -> Date | |||
Author
There was a problem hiding this comment.
The fix: Changing SHA512 -> SHA1
Also adding "Issuer" as a property for reuse.
gestrich
commented
Apr 16, 2022
| @@ -143,7 +144,7 @@ public class OTPManager { | |||
| } | |||
|
|
|||
| let generator = Generator(factor: .timer(period: TimeInterval(self.tokenPeriod)), secret: secretKeyData, algorithm: algorithm, digits: passwordDigitCount)! | |||
Author
There was a problem hiding this comment.
Use property and get rid of unnecessary string interpolation.
ddeb09f to
4bcc0a3
Compare
SquareTheBase
approved these changes
Apr 17, 2022
pbipin74
pushed a commit
to pbipin74/NightscoutService
that referenced
this pull request
Jul 1, 2026
Add APNS response feature with JWT management and secure messaging
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remote bolus OTP validation was failing on Authy and possibly some other OTP clients. I was specifying the SHA512 algorithm for generating a QR code. The Google Authenticator spec, which I think these OTP standards were derived from, allows either {sha1, sha256, sha512}. However, it seems that Authy only supports SHA1. Some more background is here. Apparently this issue has been around for a long time.