The Wayback Machine - https://web.archive.org/web/20200714064218/https://github.com/vector-im/riot-web/issues/12586
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Session verification confusing and not working with cross-signing #12586

Closed
jryans opened this issue Mar 2, 2020 · 7 comments
Closed

Session verification confusing and not working with cross-signing #12586

jryans opened this issue Mar 2, 2020 · 7 comments

Comments

@jryans
Copy link
Member

@jryans jryans commented Mar 2, 2020 •

With cross-signing at the moment, if you go to an encrypted room and expand someone's session list and click an unverified session, you get a dialog like:

2020-03-02 at 11 08

Clicking "manually verify" seems to send a verification request for that specific session which the other side never receives, so there's a bug there at least... but also, does that actually match the meaning of "manual"...?

@jryans jryans changed the title Device verification confusing and not working with cross-signing Session verification confusing and not working with cross-signing Mar 2, 2020
@bwindels bwindels self-assigned this Mar 4, 2020
@bwindels bwindels added this to In Progress in Workflow Mar 4, 2020
@bwindels
Copy link
Member

@bwindels bwindels commented Mar 4, 2020 •

just tested, and the request gets sent correctly, and seems to be received (as I get the line below in the logs of the target device) but for some reason no toast is shown.

Verification request xSgckKz7STKVQwU4bPJlbeegjsaJ8cX7: m.key.verification.request event with id:undefined, content:{"methods":["m.sas.v1","m.qr_code.show.v1","m.reciprocate.v1"],"transaction_id":"xSgckKz7STKVQwU4bPJlbeegjsaJ8cX7","from_device":"JPSZBGMWUS","timestamp":1583339691414} deviceId:JPSZBGMWUS, sender:@bruno-cs3:localhost, isSentByUs:false, isLiveEvent:true, isRemoteEcho:false, phase:1=>2, observeOnly:false=>false
@bwindels
Copy link
Member

@bwindels bwindels commented Mar 5, 2020

Created #12621 for UX confusion mentioned here, and lack of comparing public keys. This ticket is just about the device verification not working.

@bwindels
Copy link
Member

@bwindels bwindels commented Mar 5, 2020

Very weird, I can't repro this anymore. Have tried locally and on /develop and I always get a toast now...

@bwindels
Copy link
Member

@bwindels bwindels commented Mar 5, 2020

@jryans can you still repro this? I've tried with multiple accounts on /develop and local dev after having pulled, can't repro at all anymore.

@bwindels
Copy link
Member

@bwindels bwindels commented Mar 5, 2020 •

test with an account with xsigning turned off (no uploaded keys, no flag), dave hit this and rageshaked

@jryans
Copy link
Member Author

@jryans jryans commented Mar 5, 2020

Yes, I am still able to reproduce when the target user does not have keys or the flag enabled.

The request appears when the target user enables the flag even without uploading keys. I did notice in MatrixChat that we only bind the crypto.verification.request listener when cross-signing is enabled, but making that unconditional did not seem to be enough for the toast to appear, so there must be another lurking check as well...

@bwindels
Copy link
Member

@bwindels bwindels commented Mar 6, 2020 •

With the xsign flag off on the receiving side, I indeed don't see a toast

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Workflow
In Test
Linked pull requests

Successfully merging a pull request may close this issue.

2 participants
You can’t perform that action at this time.