Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.
Sign upSecret requests on login appear to be unreliable #13229
Comments
|
It looks like js-sdk is processing the encrypted to-device events in parallel. For each event, it performs the following steps:
The problem here is that once the first event causes the one-time key to be removed, the other events will fail to create the inbound session, because it doesn't have the key any more. So to fix this, we need to change |
If they overlap, they can both try to create new sessions, but this removes the OTK so it will only work once. Fixes vector-im/riot-web#13229
If they overlap, they can both try to create new sessions, but this removes the OTK so it will only work once. Fixes vector-im/riot-web#13229


Works on my local dev server but looks to be reliably reproducible on michael's server. When logging in by verifying, SSK gets transferred but USK & backup key fail to be decrypted with BAD_MESSAGE_KEY_ID