Skip to content

Patched timestamp login bypass and fixed formatting#4

Merged
Its-Networking merged 5 commits intoKeyAuth:mainfrom
ELF-Nigel:main
Mar 2, 2026
Merged

Patched timestamp login bypass and fixed formatting#4
Its-Networking merged 5 commits intoKeyAuth:mainfrom
ELF-Nigel:main

Conversation

@ELF-Nigel
Copy link
Contributor

  • Added a server-time–anchored expiry check that cannot be bypassed by changing the client clock (forward or
    backward). It uses the server’s signed timestamp header and a monotonic delta so local time changes after login
    won’t affect expiry enforcement.
  • Calls the new check after successful Login, Register, Forgot, and License flows.

@Its-Networking Its-Networking merged commit 57e2d41 into KeyAuth:main Mar 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants