🟡 [P1] Reduce timestamp validation window (replay attack) #284
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
5-minute tolerance for message timestamps allows replay attacks.
Location
apps/api/src/federation/signature.service.ts:19-20Required Fix
Priority
HIGH (P1) - Replay attack window