Skip to content

ucan: verify_chain never anchors the chain root to the resource owner #501

Description

@PierrunoYT

verify_chain (crates/gitlawb-core/src/ucan.rs:252-292) proves only self-consistency. A presenter can self-issue a root token (iss=me, aud=me, att=[git/push on Alice's repo]) and delegate from it; every check passes because every key is the attacker's. The node's validate_ucan_chain (auth/mod.rs:269-309) adds only iss == HTTP signer and aud == node, both of which the attacker controls.

Status: latent. ucan.can() gates nothing in the node today and push is owner-only, but the doc comment reserves exactly the extension that would activate it.

Distinct from #425 (constraints are ignored) and #467 (verification budget): this is about the chain root not being anchored to the resource owner.

Fix: before any can()-gated route ships, require the chain root's issuer to be the server-recorded repo owner (or a node-issued bootstrap token). Also check the ucan version field on verify, which is never read, and cap proof-chain recursion.

Found in the Oct 2 2026 audit (A6) at bfc44f9.

Activity

  1. added
    kind:securityVulnerability fix or hardening
    sev:highMajor break or real security/trust risk, no easy workaround
    subsystem:identityDID/UCAN, http-sig auth, push authorization
    crate:coregitlawb-core — identity, certs, encrypt, DID/UCAN
    crate:nodegitlawb-node — the serving node and REST API
    sev:mediumDegraded but workaround exists
    and removed
    sev:highMajor break or real security/trust risk, no easy workaround
    on Oct 2, 2026
  2. beardthelion commented on Oct 2, 2026

    @beardthelion
    Collaborator

    Open PR #331 already implements the fix asked for here: it anchors the UCAN chain root to the repository owner on the push path, which is the route where can() first goes live. Linking so the two stay paired.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:coregitlawb-core — identity, certs, encrypt, DID/UCANcrate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions