fix: Sign browser passkey assertions consistently (v2.15.10) When Android supplies the browser-owned client-data hash, omit Peach's independently assembled clientDataJSON so the relying party verifies the same bytes Peach signed. Add a cryptographic regression test covering the framework-hash response shape. Verified with the focused passkey assertion suite and the full JDK 17 unit-test, lintDebug, and signed assembleRelease gate.
$ koh steal kepr.uk/peach-android@b22874a1827a
·
parent: 2d43b6458f09
discussion
log in to leave a comment.