Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fix false attacks in authentication queries by rewriting primitives a…
…nd checking later for equivalence The commit bcefa45 was added to address some false attacks in https://lists.symbolic.software/pipermail/verifpal/2020/000299.html, but was reverted by the "Cleanup" commit 35e0a28. The necessary lines seem to be in verifyActiveMutatePrincipalState in cmd/vplogic/verifyactive.go. The code in the email fails after the cleanup commit was added, but doesn't fail before the cleanup commit. To test, use the code in https://verifhub.verifpal.com/45ae1e65ce5ea647a2985bb098dc35e4 and modify it so that bob uses the done message after it is received.
- Loading branch information