fix: Sign browser passkey assertions consistently (v2.15.10) When Android supplies the browser-owned client-data hash, omit Peach's independently assembled clientDataJSON so the relying party verifies the same bytes Peach signed. Add a cryptographic regression test covering the framework-hash response shape. Verified with the focused passkey assertion suite and the full JDK 17 unit-test, lintDebug, and signed assembleRelease gate.

dev · 2 days ago · 2026-09-06 · 7.1 MB

$ koh steal kepr.uk/peach-android@b22874a1827a
·
← 2d43b6458f09 206ddb2db8da →
⇓ download .face