Skip to content

Expiry of issuer's auth claim is not checked #96

@nedgar

Description

@nedgar

Looking through the query circuits, I see that they check the base claim's expiry, but not the auth claim's. Should they?

I know that in the example scenarios the auth claims are always self-issued, with no expiry. But is it possible for auth claims to be issued by another party, with an expiry?

https://github.com/search?q=repo%3Aiden3/circuits%20verifyExpirationTime&type=code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions